WOODLANDS ADVISORY
AI ASSURANCE

AI agents can act. The question is who controls that.

We do not build agents so that you have one. We bring them into your organisation under control: with their own identity, their own permissions, executable rules, approval thresholds and evidence that runs alongside.

The shift

A chatbot answers. An agent acts.

An agent reads data, operates systems, prepares decisions, uses tools and triggers transactions. It is not an interface in front of a model. It is an actor inside your systems.

That changes who owns it. While AI answers, it is a productivity topic. Once AI acts, it becomes a question of access, permissions, logging and evidence. That is where we have always worked.

What we do not do

We do not replace your IT. We connect AI to it safely.

No platform change
Your systems stay where they are. We place a control and execution layer in front of them, rather than a new enterprise platform beside them.
No data migration
Data stays in the systems that already hold it. The agent gets access to what the process actually touches, and to nothing beyond that.
No identity project
We connect your existing identity and access management instead of building a second one next to it.
No vendor switch
We do not recommend a model provider we earn from. Not indirectly either.
Identity

Three identities that must never become one.

The first question is always the same: do we need an account with the model provider for every agent? No. Treating that as an identity is precisely the mistake. Model access is a supplier account, not an identity inside your organisation.

The human
The principal. They remain the reason something happens, and they remain accountable.
The agent
The actor. Its own identity, its own permissions, a named owner, a risk class.
The service account
Technical access to the target system. Shared, impersonal, and therefore never the place where an action is attributed.
The ruleUser permissions are not agent permissions. The convenient shortcut says the agent may do whatever the user may do. It is also the fastest route into identity and privilege abuse, which the OWASP Top 10 for Agentic Applications 2026 list as a category of its own.
The control chain

Control before execution, not logging afterwards.

Seven stations between an agent's intent and the evidence about it. The sequence is the argument.

Why this matters commerciallyA portfolio under one set of controls instead of ten isolated solutions each with its own governance. The effort happens once, not per agent.
  1. Intent

    An agent wants to act. Nothing has happened yet.

  2. Identity

    It acts under its own identity. Not a person's, and not a shared service account.

  3. Permissions

    It holds its own permissions. User permissions are not agent permissions, and the shortcut is the fastest route into identity and privilege abuse.

  4. Rule

    The rule is executed, not looked up. A rule nobody can execute is a document.

  5. Risk

    The action is classified. Not everything should run on its own.

  6. Approval

    Above the threshold, a human decides. Approval thresholds are a feature, not a defect.

    A human decides here.
  7. Evidence

    Who wanted it, who did it, under which rule. The evidence runs alongside; it is not produced afterwards.

Human in the loop

Not everything should run on its own.

Autonomy is not a quality marker. An agent that decides everything alone is not more advanced, only less controlled. The question is not how much an agent may do, but where the line sits and who draws it.

You draw that line, not us and not the model. We make sure it is enforced technically, and that a rejection is logged exactly like an approval.

Below the threshold
The agent acts on its own. The evidence runs alongside.
Above the threshold
A named person decides before anything happens. Not afterwards.
Outside the rule
The action is rejected, and the rejection is an outcome, not a failure.
Models

The agent stays. The model is a supplier.

An agent welded to one provider can neither fall back nor differentiate. You need both: falling back when a provider fails or changes its terms, and differentiating because not every task deserves the same model.

Production
A capable model for everyday work.
Fallback
A second provider under the same rules, without anyone rebuilding anything.
Sensitive data
A private or self-hosted model where data must not leave your environment.
Cost-optimised
A smaller model for simple work. A classification does not need your most expensive one.
Vendor-neutralWe assess providers on security, data protection, data sovereignty and regulatory fit, not on vendor preference or partner commissions. Anthropic, OpenAI, Microsoft, Google, Mistral and on-premises open-source models sit side by side in that assessment, in no ranking.
Operations

An agent is a workload, not a feature.

Whatever a workload in a data centre carries, an agent needs too. Twelve attributes, all documented, all testable, all changeable without a rebuild:

When this starts to matterWith the first agent this looks like overhead. With the tenth it is the difference between a portfolio and a collection.
  • Identity
  • Owner
  • Environment
  • Permissions
  • Tools
  • Data access
  • Rules
  • Risk class
  • Model
  • Version
  • Approvers
  • Audit configuration
Process

From a business process to a controlled agent.

One department. One process. One agent. One connection.

  1. 01

    Assessment

    Capture the process including its exceptions. Connect existing identity and access management, define the agent identity and its owner.

  2. 02

    Configuration

    Set permissions, rules, approval thresholds, risk class and model routing. Connect only the systems the process actually touches.

  3. 03

    Sandbox

    A run in a separated environment, explicitly including the cases that must be rejected. A control that never rejects anything has not been proven.

  4. 04

    Go-live

    Supervised operation with evidence running alongside. Then the second process, under the same controls.

Operating models

Three models. One recommendation.

Managed
The default. The control layer runs as a managed service with a secured connection to your systems. Fastest route to a result, least effort on your side.
Dedicated
The control layer runs inside your own cloud environment. Removes tenancy concerns and reduces data exposure.
On premises
Runtime, governance, rules, audit and connectors inside your data centre. We supply software, updates, rule sets, templates and support.
And the responsibility that goes with itYou carry business decisions, data sovereignty and regulatory accountability. We carry the secure runtime, the enforcement of the rules and the operation. The line moves with the operating model, and it is written down beforehand rather than discovered afterwards.
Pricing logic

A fixed price per building block, defined before the engagement.

No open day rates. Scope is described before the engagement, and the price grows with scope rather than hours: more processes, more departments, more connections. Model costs from your chosen provider, licences for your own systems and hardware run through your existing contracts and stay transparent on your side.

We discuss terms in the initial consultation, once we have seen the first process.

Disclosure

What we do not claim.

  • We do not guarantee certification or audit success. Auditors and regulators determine both, not us.
  • We do not say AI can be deployed without risk. We make the risk visible, controllable and provable.
  • We do not recommend a provider we earn from. Not indirectly through partner commissions either.
  • We advise against a use case when it is not worth the control it would require. That happens.

Frequently asked questions

Do we need an account with the model provider for every agent?

No. Model access is a supplier account, not an identity inside your organisation. The agent receives its own identity in your identity and access management, independent of which model sits behind it at any given time.

Do we have to rebuild our IT landscape?

No. The control and execution layer sits in front of your existing systems. There is no platform change and no data migration. Only what the specific process actually touches gets connected.

What happens when an agent wants to do something it is not allowed to do?

The action is rejected before execution, and the rejection is logged exactly like an approval. A control that never rejects anything has not been proven, which is why the cases that must be rejected already run in the sandbox.

Are we locked into one AI provider?

No, and that is deliberate. The agent stays, the model is a supplier. A production model, a fallback, a model for sensitive data and a cost-optimised model for simple work can be assigned separately without anyone rebuilding the agent.

Does the EU AI Act already apply to us?

Partly. The transparency obligations under Article 50 and the enforcement powers have applied since 2 August 2026. Obligations for high-risk systems were postponed to 2 December 2027 and 2 August 2028. Immediate pressure therefore usually comes not from the AI Act but from ICT risk management, from customer questionnaires and from procurement.

What makes you different from an AI agency?

An AI agency builds use cases and has a commercial interest in seeing them go live. Security is a side condition there. We come from cybersecurity, governance and enterprise risk, we work vendor-neutral, and we advise against a use case when it is not worth the control it would require.

Growth needs security. Not someday – now.

Whether you face a transaction, need a certification or want to professionalise your security strategy – Woodlands delivers predictable results at boutique speed.

Schedule Initial Consultation →

20 minutes. Confidential. No obligation.