AI Agents
Agents That Only Do What You Authorised
An AI agent takes a judgement call inside a process and acts on a system, rather than only answering a question. Webcoda builds agents with hard limits on what they can touch, an approval step before anything consequential, and a full log of every action, so a wrong decision is caught and reversible rather than discovered later.
Who this is for
A decision queue with a person as the bottleneck
Automation that keeps hitting exceptions
A chatbot that people now expect to act
What we deliver
-
01
A defined scope of authority
Written down before anything is built: which systems the agent can read, which it can write to, and the value or risk threshold above which it must ask a person.
-
02
Approval steps where the stakes justify them
Human in the loop on the actions that are expensive or hard to unwind, and no approval theatre on the ones that are not.
-
03
A full action log
Every action recorded with the inputs and the reasoning behind it, in a form your auditors and your team can read.
-
04
Reversibility by design
An undo path for anything the agent can do. If an action cannot be reversed, it needs an approval step, not a confidence score.
-
05
Monitoring and a kill switch
Someone can see what it is doing and stop it, without a deployment. Named owner, not a shared inbox.
Acting versus answering
| An agent acts | A chatbot answers |
|---|---|
| Takes a judgement call inside a process and does something about it. | Retrieves and explains what your content already says. |
| A wrong action changes a record, and something has to be unwound. | A wrong answer means a bad experience and a correction. |
| Supervision is monitoring, permissions and an audit trail. | Supervision is content review. |
| Right when the volume is decisions. | Right when the volume is questions. |
| Costs more to build and much more to govern. | Cheaper on both, and the right answer more often. |
Most organisations that ask us for an agent need a chatbot or an automation, and we will say so. If your volume is questions rather than decisions, that is a cheaper build and a much lighter thing to supervise.
AI ChatbotsRules or judgement
If the process runs on a stable set of rules and the exceptions are rare, you want automation, not an agent. Automation is cheaper to build, cheaper to supervise and easier to explain to an auditor.
An agent earns its cost when the judgement is genuinely required, the exceptions are the work, and the decision would otherwise sit in a queue behind a person.
Looking for something that follows rules rather than exercising judgement? See AI Automation
Why the limits come before the agent
An agent with permission to act on your systems is a member of staff with no judgement about consequences and no instinct for when to stop. The governance is not paperwork around the build. It is the build.
We have spent years building the permission models these agents would run inside, including SharePoint intranets for NSW Health and Infrastructure NSW. That is the part most agent vendors treat as someone else's problem.
The practical order
Decide what it may touch. Decide what needs a human. Build the log. Then build the agent. Doing it the other way around produces a demo that cannot be put into production, which is most agent pilots.
What we have built
DA checklist automation for NSW councils
DA checking is manual, repetitive and easy to get wrong. This AI-powered checklist reads each submission and checks it against the applicable controls inside the council's existing workflow, with the rules held where planners can see and change them, so planners spend their time on the judgement calls.
NESA curriculum MCP server
The retrieval layer an agent needs to act on real curriculum data through real permissions, rather than on a guess.
How an engagement runs
-
Step 01
Assess
We map the decision, not the technology. What is actually being judged, on what evidence, by whom, and what happens today when it is judged wrongly.
-
Step 02
Prototype
The agent recommends, a person still decides. It runs beside your team with no authority to act, and we compare its calls to theirs until the difference is boring.
-
Step 03
Integrate
We grant authority narrowly, with the log and the approvals live first. Lowest-stakes actions only, then widened on evidence rather than on schedule.
-
Step 04
Scale
We widen scope where the record justifies it, and stop where it does not. Some agents should stay recommendation-only forever. That is a legitimate outcome, not a failed project.
Honest scoping
Starts with a decision audit
Then recommendation-only
Governance is a running cost
AI agents, answered
Talk to us about agents
Bring the decision that sits in a queue. If an agent is the wrong answer, that is a thirty-minute conversation well spent.