What we do
01  Advanced Infrastructure 02  Applied AI & Data 03  AI Cybersecurity 04  AI Assurance
Engagements
AI estate inventory Assurance review
Industries
Financial Services Government & Public Sector Energy & Utilities Telecommunications Healthcare & Life Sciences Transport & Logistics Industrial & Manufacturing Retail, Hospitality & Real Estate
Research
The Trust Maturity Model The GCC Assurance Index Readiness self-assessment Case studies Perspectives Sector briefings Technology evaluations
Company
About us Partners Events Careers Contact العربية Talk to our team
Applied AI & Data  ·  Agentic AI

The agent can act alone. Should it?

An agent is not a chatbot with tools. It is a system that takes actions with consequences — which makes the only useful question how far up the autonomy ladder it is standing, and whether the controls for that rung exist yet.

8–16 WEEKSA RUNNING SYSTEM AND ITS EVIDENCENAMED ACCOUNTABILITY AT EVERY GATE
The decisions underneath

Three questions decide the design.

Agentic systems are usually specified by what they can do. They should be specified by what happens when they are wrong.

01

What can it do without asking

Every action inside that boundary needs a limit somebody wrote, a log somebody reads, and a stop somebody has actually pulled.

02

What does being wrong cost

A wrong draft costs a minute. A wrong payment costs a relationship. The same architecture is not appropriate for both.

03

Can you undo it

Reversibility is a design property, not an incident-response hope. If an action cannot be reversed, the gate in front of it has to be real.

The ladder

How far up the ladder is this system standing?

An agent is not a chatbot with tools. It is a system that takes actions with consequences, and the only useful question is which rung it is on. Choose a rung.

AUTONOMY— OF 5 RUNGS EARNED
Select a rung

Five levels of autonomy. Each one is a different system with different consequences, and each one has a control that has to exist before you stand on it.

We will not build an agent on a rung whose controls do not yet exist. That is not caution for its own sake — it is that the rung below is almost always where the value actually was.

What you receive

A working system and the record behind it.

Four stages, every engagement. Hover a stage to see what happens in it.

DURATION
8–16 weeks
DELIVERABLE
Running system, controls, evidence pack
DELIVERED
Hybrid; in-country where residency requires
INDICATIVE FEE
[FEE BAND — pending sign-off]
The boundary

We build it. We do not grade our own work.

Three moves. Two of them are ours, and the one in the middle is deliberately somebody else’s.

MOVE 01 — OURS

We build and run it

Design, integration and operation of the system, with a named human accountable at every gate that matters. This is delivery work and we do not pretend otherwise.

MOVE 02 — NOT OURS

Somebody else forms the opinion

The assurance opinion on anything we built is not written by the team that built it, and where you need it to carry weight externally, not by Orvix at all. A firm that audits its own delivery is offering you a marketing document.

MOVE 03 — OURS

We remediate what the review found

We fix what the independent review says is wrong, and the fix is re-examined by the same reviewer rather than signed off by us.

This is the same independence test we apply to other people’s vendors. It would be difficult to argue for it and then exempt ourselves.
Applied AI & Data

The rest of this pillar.

Three engagements inside this pillar. Start with the question you can name, or take the whole estate at once.

Questions we are asked

Before you ask us.

What counts as an agent?
For our purposes, any system that takes an action in another system without a person performing that action. That definition catches a good deal of software nobody calls an agent, which is usually the point — the risk arrives with the action, not with the label.
Can you start at a lower rung and move up?
That is the recommended path, and it is not a delay tactic. In most processes the value turns out to sit on the rung below the one that was originally asked for, at a fraction of the control cost.
Who signs off that this is safe to run?
Not us. We build it, we produce the evidence pack, and the opinion is written by a reviewer who does not report to the build team — and, where it needs external weight, not by Orvix at all.
What happens when it gets something wrong?
That is a design input, not an exception. The stop, the reversal path and the notification are built at the same time as the capability, because retrofitting them means guessing what you wish you had logged.

Start with what it is allowed to do alone.

Thirty minutes. Describe the action you would least like to explain afterwards, and we will start there.

Book a 30-minute scoping call

ORVIX · INDEPENDENT AI & TECHNOLOGY ASSURANCE · WE DISCLOSE EVERY COMMERCIAL RELATIONSHIP ON THE PAGE FOR THE SERVICE IT BELONGS TO. WHERE LICENSING IS REQUIRED, DELIVERY IS PERFORMED BY NAMED PARTNERS UNDER THEIR OWN LICENCE.