AI Agents

Agents That Only Do What You Authorised

An agent takes a judgement call and acts on a real system. That is useful, and it is only safe when the limits, the approvals and the audit trail are designed before the agent is.
Talk to us about agents
In short

An AI agent takes a judgement call inside a process and acts on a system, rather than only answering a question. Webcoda builds agents with hard limits on what they can touch, an approval step before anything consequential, and a full log of every action, so a wrong decision is caught and reversible rather than discovered later.

Who this is for

Scenario 01
A decision queue with a person as the bottleneck
Requests that need a judgement call against known criteria, waiting on someone senior enough that the queue never fully clears.
Scenario 02
Automation that keeps hitting exceptions
A rules-based process already running, where the exceptions have become most of the work and someone triages them by hand.
Scenario 03
A chatbot that people now expect to act
Staff or customers ask an existing chatbot to action something, not just explain things – something it was never built for.

What we deliver

  1. 01

    A defined scope of authority

    Written down before anything is built: which systems the agent can read, which it can write to, and the value or risk threshold above which it must ask a person.

  2. 02

    Approval steps where the stakes justify them

    Human in the loop on the actions that are expensive or hard to unwind, and no approval theatre on the ones that are not.

  3. 03

    A full action log

    Every action recorded with the inputs and the reasoning behind it, in a form your auditors and your team can read.

  4. 04

    Reversibility by design

    An undo path for anything the agent can do. If an action cannot be reversed, it needs an approval step, not a confidence score.

  5. 05

    Monitoring and a kill switch

    Someone can see what it is doing and stop it, without a deployment. Named owner, not a shared inbox.

Acting versus answering

An agent acts A chatbot answers
Takes a judgement call inside a process and does something about it. Retrieves and explains what your content already says.
A wrong action changes a record, and something has to be unwound. A wrong answer means a bad experience and a correction.
Supervision is monitoring, permissions and an audit trail. Supervision is content review.
Right when the volume is decisions. Right when the volume is questions.
Costs more to build and much more to govern. Cheaper on both, and the right answer more often.

Most organisations that ask us for an agent need a chatbot or an automation, and we will say so. If your volume is questions rather than decisions, that is a cheaper build and a much lighter thing to supervise.

AI Chatbots

Rules or judgement

If the process runs on a stable set of rules and the exceptions are rare, you want automation, not an agent. Automation is cheaper to build, cheaper to supervise and easier to explain to an auditor.

An agent earns its cost when the judgement is genuinely required, the exceptions are the work, and the decision would otherwise sit in a queue behind a person.

Looking for something that follows rules rather than exercising judgement? See AI Automation

Why the limits come before the agent

An agent with permission to act on your systems is a member of staff with no judgement about consequences and no instinct for when to stop. The governance is not paperwork around the build. It is the build.

We have spent years building the permission models these agents would run inside, including SharePoint intranets for NSW Health and Infrastructure NSW. That is the part most agent vendors treat as someone else's problem.

The practical order

Decide what it may touch. Decide what needs a human. Build the log. Then build the agent. Doing it the other way around produces a demo that cannot be put into production, which is most agent pilots.

What we have built

da-checklist-case-study
Local Government

DA checklist automation for NSW councils

DA checking is manual, repetitive and easy to get wrong. This AI-powered checklist reads each submission and checks it against the applicable controls inside the council's existing workflow, with the rules held where planners can see and change them, so planners spend their time on the judgement calls.

nesa-ai-case-study-temp
Government · MCP

NESA curriculum MCP server

The retrieval layer an agent needs to act on real curriculum data through real permissions, rather than on a guess.

How an engagement runs

  1. Step 01

    Assess

    We map the decision, not the technology. What is actually being judged, on what evidence, by whom, and what happens today when it is judged wrongly.

  2. Step 02

    Prototype

    The agent recommends, a person still decides. It runs beside your team with no authority to act, and we compare its calls to theirs until the difference is boring.

  3. Step 03

    Integrate

    We grant authority narrowly, with the log and the approvals live first. Lowest-stakes actions only, then widened on evidence rather than on schedule.

  4. Step 04

    Scale

    We widen scope where the record justifies it, and stop where it does not. Some agents should stay recommendation-only forever. That is a legitimate outcome, not a failed project.

Honest scoping

Shape
Starts with a decision audit
A short, paid piece of work on one decision. It frequently concludes that automation or a chatbot is the right build instead.
Shape
Then recommendation-only
First build advises and does not act. Authority is granted after the comparison, not at kickoff.
Ongoing
Governance is a running cost
Monitoring, log review and a named owner. An agent nobody watches is the most expensive version of this.

AI agents, answered

Software that takes a judgement call inside a process and acts on a system, rather than only answering a question. The distinction that matters commercially is authority: an agent can change something, so it needs limits, approvals and a log.
Automation follows rules you have already decided. An agent decides. If your exceptions are rare and your rules are stable, automation is cheaper to build and far cheaper to supervise, and we will recommend it.
A written scope of authority, an approval step above a threshold you set, and an undo path for everything below it. Anything that cannot be reversed does not get automatic authority, regardless of how confident the model is.
Yes, and this is not optional. Every action is logged with its inputs and reasoning, in a form a person can read without a developer present.
The ones with an API and a permissions model worth respecting. Most commonly we work with HubSpot, Microsoft 365 and SharePoint, Umbraco and Xperience by Kentico, but we also support all other platforms.

Talk to us about agents

Bring the decision that sits in a queue. If an agent is the wrong answer, that is a thirty-minute conversation well spent.