Moving money
Transferring funds, releasing a payment, issuing a refund, paying an invoice.
The agent reconciles, drafts, and routes. A named person approves the transfer, and the agent that proposed it is refused as its own approver, a hard 403.
Use cases
Every high-consequence flow has the same shape. The agent clears the routine work and stops at the one action that cannot be undone: moving money, writing to a record, placing a trade, deleting data, filing a document. A named human owns that call, the agent that proposed it is refused as its own approver with a hard 403, and every step commits to a signed record your own auditor recomputes offline. The horizontal use cases come first, then worked examples across finance, life sciences, and other domains.
The horizontal use cases
Domain does not change the shape. These are the high-consequence actions an agent reaches across finance, operations, and any system of record. On each one the agent does the safe work, a named human owns the step that cannot be undone, and every action, block, and signature commits to an Ed25519-signed, SHA-256 hash-chained record your own auditor recomputes offline.
Moving money
Transferring funds, releasing a payment, issuing a refund, paying an invoice.
The agent reconciles, drafts, and routes. A named person approves the transfer, and the agent that proposed it is refused as its own approver, a hard 403.
Changing records
Writing to a system of record: a ledger, a case file, a chart, a customer account.
The agent proposes the change. Any write that alters a value waits for a named person, so a silent edit cannot slip through unowned.
Placing trades
Submitting an order, rebalancing a book, opening or closing a position.
The agent prepares the order and checks it against limits. A named person authorizes it before it reaches the venue.
Deleting data
Dropping a table, wiping a record, revoking access, purging a store.
The agent can quarantine and soft-delete on its own. Destroying anything is a one-way door reserved for a named person.
Filing documents
Submitting a report to a counterparty or an authority, sending a legal notice, filing a claim.
The agent drafts and cites its evidence. A named person signs the submission, because once it is filed it stands.
Worked examples
These are concrete flows in life sciences and patient access, the domains where the buyer is often the party under examination, so a record the auditor checks for themselves matters most. A finance desk runs the same shape: the agent reconciles and drafts, a named person approves the transfer or the trade, and the record verifies offline. We build and run the agent on whatever framework you use, and the proof is written as the rule is enforced.
For the manufacturer's compliance and legal function, and the hub or AI-access vendor's counsel.
The consequential action
The sensitive step is confirming funding eligibility, steering a federal-healthcare patient toward copay or an "independent" foundation, and authorizing the submission. The manufacturer carries the Anti-Kickback and False Claims Act risk. The agent that ran the investigation is blocked in code from doing any of those alone.
A real example
A patient is denied a $180k-a-year oncology therapy. The agent verifies benefits, finds the denial reason, drafts the medical-necessity appeal, and proposes a funding stack of copay card plus a charitable foundation (PAN, HealthWell, LLS). Then it stops. A named access specialist signs the eligibility and authorizes the submission, and only then is anything submitted. In a second case a Medicare patient is steered away from manufacturer copay support toward an eligible foundation, with the reason recorded word for word, and the specialist signs before any enrollment.
Why independence matters here
This is the lane where you are the party under examination, so a record you keep is just your own account of it. We make a record your auditor checks for themselves, offline, with no access to your systems. It proves a named human owned the decision, and if a single row were altered the chain would break when an investigator opens the record and recomputes it.
For the QPPV and the AI / agent team standing up a custom or outsourced PV agent.
The consequential action
A seriousness or expectedness call moves a case onto, or off, the 15-day expedited clock. The agent that processed the case is blocked in code from making that call.
A real example
P-4001, a non-serious, listed event confirmed against the label, is coded, narrated, and closed by the agent with a signed record, no expedited clock. P-4003, a serious and unexpected event, is drafted with cited evidence and then held: the safety physician signs "Serious, unexpected, expedited; causality assessed," and only then is the 15-day clock set and the case routed to submission.
Why independence matters here
The new exposure is keeping a hard-to-predict LLM agent inside fixed limits, and proving what an offshored CRO's agent actually did when the liable QPPV cannot take the CRO's word for it. We build and run the PV agent on whatever framework you use, and the proof is written as the rule is enforced.
For the regulatory-affairs lead and the AI / agent team building a complaint-handling agent.
The consequential action
Deciding a complaint is reportable starts the 30-day MDR clock; a "not reportable" call must trace to a qualified human in the event file. The agent triages and drafts, but never decides reportability. That call belongs to a named officer.
A real example
C-3004 (InsuFlow MX insulin pump), a reportable serious injury, and C-3008 (VentAssist 300 ventilator), a malfunction likely to recur, are both flagged against the 30-day MDR clock. The agent never decides reportability; the regulatory-affairs officer signs each disposition, and only then are the MDR skeletons drafted.
Why independence matters here
The new autonomous agents sit outside the eQMS log your inspector already accepts, so a clean record of who owned the "not reportable" call closes the gap. We build and run that agent on whatever framework you use, in your environment, and the proof is written as the rule is enforced.
For the QA and qualified-person lead and the AI / agent team automating disposition.
The consequential action
Releasing or destroying affected product is the one-way door. Quarantine is reversible, so the agent does it alone. Release or destroy belongs to a named QA person, and the agent that assessed the excursion is blocked from disposing of it.
A real example
An agent catches a temperature excursion live, pulls the approved stability limits, and quarantines the affected lots itself. Then it stops. The release-or-destroy call, six figures of product whichever way it goes, is signed by a named qualified person, with the reason recorded word for word, and the one who assessed it is not the one who approved it.
Why independence matters here
The rule that the assessor cannot also approve is enforced before the disposition runs, not caught in an after-the-fact review, and your auditor can check the signed record on their own. We build and run the disposition agent so the proof exists because the control held.
For the clinical-data-management lead and the AI / agent team at a CRO.
The consequential action
Resolving a query that changes a data value, or one that is more than a confirmation, is the consequential step. The agent closes the safe, confirmation-only classes; anything else routes to a named data manager who signs.
A real example
A trial throws tens of thousands of queries, most of them confirmation-only, a date format, a unit, an expected lab flag, that resolve to no data change. The agent closes those classes on its own, on the record. A discrepancy that touches a value is held for a named data manager, who signs the resolution, and the run exports as a file an inspector verifies on their own.
Why independence matters here
Trials are heavily outsourced, so a sponsor that cannot watch a CRO's agent in real time still gets a clean record of every resolution, with no silent data change, that an inspector checks on their own without trusting the CRO. We build and run the data-query agent on whatever framework you use.
For the CRO feasibility lead and the principal investigator.
The consequential action
Confirming a patient meets the inclusion and exclusion criteria is a physician call that cannot be delegated under ICH-GCP E6. The agent screens and proposes. It is blocked in code from marking a patient eligible on its own.
A real example
The agent screens an oncology population against a 2nd-line trial protocol, reading line of therapy, biomarker and mutation status, ECOG, prior treatments, washout, and disease progression out of unstructured notes and path reports. It proposes one fully-matched candidate and one borderline case (an ambiguous progression note), each with the matched and unmatched criteria and the supporting evidence cited. The principal investigator signs the eligibility determination on the matched candidate, and sends the borderline one back for chart review.
Why independence matters here
The eligibility call is the investigator's under GCP, so the agent reads the chart and proposes, and the human owns the determination. The record carries every matched and unmatched criterion with the evidence cited, on a file a monitor checks on their own.
Watch one of these run, live.
Block an agent from signing off its own work, then sign off as the named human, in your browser, no signup.
The pattern
Every flow on this page is the same shape. The agent runs free on the safe work: draft, reconcile, triage, quarantine, prepare. A named human owns the call that cannot be undone: move the money, place the trade, change the value, delete the record, file the document. The agent that did the work is refused as its own approver, a hard 403, limits fail closed, and the record is written in the same step as the action, so "acted but never logged it" cannot happen.
The edge is not the sign-off, which anyone can build. It is that your own auditor recomputes the record themselves, in their own browser, in any language, with no code from us and no access to your systems. We build and run the agent on whatever framework you use, and the proof is written as the rule is enforced. That is why the record matters most where you are the party under examination, so a record you control proves nothing on its own. And it is why agent control planes are complementary: they watch the fleet, we are the proof your auditor checks.
Keep reading
See it for yourself
One command starts the demo: an agent stopped from signing off its own work, and the signed evidence file an inspector can check for themselves.
Designed against the rules your auditors already enforce.