Agentic AI

AI is moving from answering questions to completing work.

Modern AI agents can retrieve information, select tools, call software, maintain task state, delegate to other agents and work through multi-step goals. That creates enormous operational potential. It also creates a new control problem.

TEMRIK is designed to sit around agentic systems as the business control layer—connecting company context, permissions, playbooks, tools, approvals and evidence around the AI doing the work.

Models · tools · memory · MCP · A2A · permissions · orchestration · human authority

Controlled agent loop

Stage 1

Business event

Stage 2

Goal

Stage 3

TEMRIK control plane

Plan
Tool call
Result
Next step

Operational events are observable. Private chain-of-thought is not required or exposed.

Policy check

Human authority where required

Action + audit record

First principle

Agentic AI is not simply “AI that works on its own.”

A useful working definition is an AI system in which a model can participate in deciding what steps to take, what tools to use, what information to retrieve, whether to delegate work and how to pursue a goal over multiple interactions.

Planning
Tool selection
Information retrieval
Task decomposition
Delegation
System interaction
State management
Error recovery
Action

From response to action

Chatbot

A chatbot answers.

User asks
Model generates response
Conversation ends

Reactive · primarily text generation · user directs most steps.

Agentic system

An agent can pursue a goal.

Goal supplied
Evaluate next step
Retrieve context
Select tool
Observe result
Choose next step
Continue
Complete / escalate / stop

Multi-step · tool-using · stateful · adaptive · capable of bounded action and delegation.

The difference is not simply intelligence. The difference is agency.

Workflow vs agent

Not every AI workflow needs an autonomous agent.

Workflow

The path is mainly determined by software.

Receive invoice → extract fields → validate supplier → compare PO → route exception → human approval. AI participates in defined stages.

Workflows provide predictability.

Agent

The system has discretion over how to pursue the objective.

“Investigate why this project is forecasting a six-week delay.” The agent may inspect programme data, search meeting records, retrieve RFIs, review drawing revisions, consult a specialist agent and assemble the evidence. The precise path may not be known in advance.

Agents provide adaptability.

Use the least autonomy necessary to complete the work well.

How agents actually work

Most agents are loops, not magic.

01

Receive goal

What needs to be achieved?

02

Assemble context

What information is relevant?

03

Select next step

What should happen next?

04

Use tool

Search, API, code, browser or specialist.

05

Observe result

What actually happened?

06

Update state

What do we now know?

07

Continue or stop

Complete, escalate, pause or fail safely.

The loop is why agents can handle open-ended work. It is also why one bad instruction, poisoned context or over-broad tool call can compound if the surrounding system has weak boundaries.

The augmented model

The model is only one component.

Model

Reasoning and language capability.

Instructions

Role, objective and operating guidance.

Tools

Functions that interact with external systems.

Context

Information supplied for the immediate task.

Memory / state

Temporary or persistent working state.

Identity

Which machine or human actor is operating.

Policy

What the actor may access or do.

Orchestration

How tasks, agents and systems coordinate.

Observability

How the organisation knows what happened.

Authority

Who ultimately permits consequential action.

From thinking to doing

An agent becomes operational when it can use tools.

Read

Search documents · query CRM · inspect project files · retrieve records

Calculate

Run code · compare data · forecast · validate

Communicate

Draft email · prepare notice · create message · report

Act

Update CRM · create task · schedule · publish · trigger workflow

High consequence

Release payment · change pricing · issue legal material · alter permissions

The tool definition is part of the security boundary.

An AI that can calculate an invoice does not automatically need authority to pay one. An AI that can draft a contractual notice does not automatically need authority to issue it.

Model Context Protocol

MCP

MCP is becoming a standard connection layer between AI and tools.

Model Context Protocol standardises how AI applications interact with server-exposed capabilities such as tools, resources and prompts. The current 2026-07-28 specification also strengthens authorization and introduces extensions for capabilities including longer-running Tasks.

Read the current MCP specification notes
Agent / AI application
MCP client / host
MCP server
Tools · resources · applications

MCP makes connection easier. It does not remove the need for identity, scope, allowlists, read/write separation, rate limits, approval and audit.

Connectivity is not authority

MCP is not the control plane.

MCP can answer “how can this AI application communicate with a capability?” TEMRIK must answer a different question: should this agent be allowed to use this capability for this user, tenant, workflow and data, right now?

MCPConnection
TEMRIKPolicy
ToolAuthority

Agent-to-agent

A2A

Agents are beginning to talk to other agents.

Agent2Agent is an open protocol, originally developed by Google and now hosted by the Linux Foundation, for interoperable communication between independent agent systems. The current 1.0 specification uses concepts including Agent Cards, stateful Tasks, Messages and Artifacts.

Read the A2A 1.0 documentation

Discover

Read an Agent Card and declared capabilities.

Select

Determine whether the remote agent fits the task.

Delegate

Create a stateful task with scoped context.

Receive

Track status and consume messages or artifacts.

When one agent asks another to do something—who authorised the delegation?

MCP vs A2A

Two connectivity layers. One business policy problem.

MCP

Agent → tools and resources

“What capability or data can I use?”

A2A

Agent → agent

“Can another agent participate in this task?”

TEMRIK

Company policy → both

“Is this interaction permitted under company policy?”

One agent will not do everything

Complex work is increasingly being divided between specialist agents.

Manager + specialists

A manager interprets the goal, delegates to specialists and synthesises results.

Sequential

Agents execute in a defined order.

Parallel

Several agents investigate at the same time.

Handoff

Responsibility transfers to another specialist.

Evaluator / critic

One agent generates and another tests or critiques.

Orchestrator-worker

A manager creates subtasks dynamically.

Group collaboration

Specialists contribute to a shared problem.

Human review

A person can pause, review, approve or redirect.

Multi-agent does not automatically mean better. It can add latency, token cost, duplicated work, coordination failure, context leakage, accountability ambiguity and cascading errors.

Who is acting?

Every serious agent needs an identity.

Businesses already govern user identities. Agentic systems add machine actors. The organisation needs to know who owns the agent, which tenant it belongs to, what role it has, which tools and credentials it may use, whether it can delegate, and when its authority expires.

Agent Passport · architecture concept

Agent ID
Owner
Tenant
Purpose
Model
Allowed tools
Allowed data classes
Delegation rights
Action ceiling
Human approver
Runtime status
Audit history

Memory changes the risk

An agent that remembers is different from an agent that only responds.

Working memory

Immediate task context.

Session memory

State retained across one working session.

Long-term memory

State or learned information retained across sessions.

Business memory

Authoritative company records and knowledge outside the model.

Company record ≠ model context ≠ agent memory ≠ audit record.

Context engineering

Agents do not need everything. They need the right context at the right moment.

Trusted control context

Company policy · permissions · agent identity · tool rules

Trusted business data

Approved internal records and authoritative sources

Untrusted content

Email · websites · uploads · external messages · generated text

Content must not be allowed to redefine authority.

Goal to plan

Planning is useful. Plans are not authority.

An agent may decide to inspect programme data, retrieve instructions, search unresolved RFIs, analyse a notice requirement and compile evidence. TEMRIK’s job is to separately govern whether each tool call, data access, delegation and external action is permitted.

1Inspect programme
2Identify critical-path movement
3Retrieve instructions
4Inspect unresolved RFIs
5Analyse notice requirements
6Compile evidence
7Propose escalation

An agent can decide what it wants to do next. The control plane decides whether it is allowed to do it.

Autonomy is a dial

How much agency does this workflow actually require?

Level 0

Assist

AI answers or retrieves. No external action.

Level 1

Prepare

AI prepares work. A person performs the consequential action.

Level 2

Recommend

AI proposes the next step. Human approval remains explicit.

Level 3

Act within boundary

Low-consequence, pre-authorised actions may execute. Exceptions escalate.

Level 4

Bounded autonomous workflow

Agent plans and acts over multiple steps inside a tightly defined scope.

Level 5

Open-ended agency

Broad goal, dynamic tools and delegation. Highest governance requirement.

Consequence-based autonomy

Low sensitivity / low consequence

Public research summarisation. Higher autonomy may be reasonable.

High sensitivity / low consequence

Restrict context and provider boundary even if the action is low impact.

Low sensitivity / high consequence

Sending customer pricing may require explicit approval even if the source data is ordinary.

High sensitivity / high consequence

Payments, contractual releases or privileged material require the strongest data and authority boundary.

Human control

Human control is more than one approval checkbox.

Human In the loop

Human approves during execution.

Human On the loop

Human supervises and can intervene.

Human Above the loop

Human defines policy, authority and escalation boundaries.

Human After the loop

Human reviews outcomes retrospectively.

Human control should not mean watching every tool call. It should mean humans define and retain the important decision rights.

The Dispatcher Gate

The model cannot prompt itself into having more authority.

A Dispatcher Gate sits outside the probabilistic agent and evaluates tenant, identity, role, workflow, tool, data sensitivity, action consequence, approval requirement and risk threshold.

Proposed action

Tenant
Agent identity
Role
Workflow
Tool
Data sensitivity
Action consequence
Approval requirement
Allow
Deny
Escalate
Request info

More capability creates more attack surface

An agent can fail through reasoning, identity, memory, tools or delegation.

Goal hijacking

External content diverts the agent from the authorised objective.

Tool misuse

A legitimate tool is called in an unintended or over-broad way.

Identity & privilege abuse

An agent operates with excessive credentials or authority.

Agentic supply chain

A compromised MCP server, skill, plugin, package, tool or remote agent changes the trust boundary.

Memory poisoning

False or malicious state persists and influences later work.

Insecure delegation

One agent trusts another without an appropriate identity or policy check.

Cascading failure

One incorrect action causes other systems or agents to react.

Human trust exploitation

Confident output persuades a person to approve unsafe work.

The risk is no longer only “could the model say something wrong?” Could the system do something wrong?

The control layer is becoming a standard

OWASP is standardising runtime agent control.

OWASP’s Agent Control Standard, published 1 September 2026, says enterprise agents should be inspectable, traceable, instrumentable and controllable at runtime, with policy enforced through external control hooks. TEMRIK does not claim certification against ACS; the significance is architectural alignment.

Read the OWASP Agent Control Standard
Agent framework
Control hook
Policy layer
Allow / block / modify / escalate
Tool or action

Security is catching up with agency

Traditional cybersecurity now has machine decision-makers to secure.

NIST’s May 2026 analysis of industry responses found widespread agreement that AI agents introduce novel security threats. Conventional cybersecurity principles remain relevant, but require adaptation for agentic systems.

Read the NIST analysis

Traditional security

Users · applications · infrastructure

Agentic security adds

Machine actors · delegated authority · dynamic tools · machine-to-machine decisions

Agents need observability

If you cannot reconstruct the run, you cannot govern the agent.

Agent ID
Initiator
Tenant
Goal
Model
Context sources
Tools called
Tool results
Delegations
Policy decisions
Human approvals
Exceptions
Timestamps
Final outcome

Observability does not require exposing a model’s private reasoning. It requires recording the operational evidence around what the system saw, called, delegated, proposed, approved and did.

Test the system, not just the model

A good model does not guarantee a good agent.

Task completion

Did the system achieve the goal?

Tool selection

Did it choose the right capability?

Tool parameters

Were the inputs appropriately scoped?

Context selection

Did it retrieve only relevant evidence?

Policy compliance

Did it remain inside permissions?

Escalation

Did it stop when it should?

Error recovery

Did it recover safely?

Security

Could malicious input alter authority or behaviour?

Cost + latency

Was the workflow economical enough to justify the complexity?

Auditability

Can the operational run be reconstructed?

Stop conditions

A controlled agent needs a reason to stop.

Task complete
No authority
Insufficient evidence
Low confidence
Tool failure
Policy block
High consequence
Human input required
Iteration limit
Time limit
Cost limit
Security event

Autonomy without stop conditions is not an enterprise architecture.

Economics

Measure cost per completed workflow—not merely cost per token.

Agentic systems can consume multiple model calls, tools, retrieval operations, agents and iterations. More autonomy can buy flexibility and task completion, but it can also add latency, compute and failure modes.

Planner
Search
Retrieval
Specialist
Critic
Tool
Final synthesis
Audit + approval

Agentic workflows for SMEs

Agentic AI becomes useful when it is attached to a real operating problem.

Construction

Revised drawing → affected packages → contract obligations → programme impact → evidence → draft notice → authorised approval.

Accounting

Records → missing documentation → policy check → reconciliation tasks → exception summary → irregular payment escalation.

Property

Enquiry → listing data → qualification → response → authorised inspection booking → negotiation escalation.

Professional services

Client request → engagement scope → precedent → research → draft advice → professional sign-off.

R&D

Evidence → experiment mapping → gaps → information request → technical chronology → human validation.

TEMRIK agentic architecture

Agents inside a business operating system.

Layer 9

Audit

Evidence · action · outcome

Layer 8

Human authority

Decision owner · approval · escalation

Layer 7

Dispatcher Gate

Allow · deny · escalate · request information

Layer 6

Specialist agents + tools

Research · analysis · systems · external services

Layer 5

Agentic orchestration

Agent · workflow · MCP · A2A · model router

Layer 4

TEMRIK policy

Data class · tool rights · delegation rights · action limits

Layer 3

Identity + access

Tenant · user · agent · role

Layer 2

Company data

Records · knowledge · evidence

Layer 1

Business systems

CRM · documents · finance · projects · communications

The agent can choose the next step. The company still chooses the boundary.

Agent portability

The agent architecture should not belong to one model vendor.

Company policies, tools, knowledge, identities, playbooks, permissions, memory and audit should remain part of the company architecture. TEMRIK’s strategic direction is to orchestrate across multiple agent runtimes and models rather than make the business depend on one provider.

Architecture direction

OpenAI agent
Anthropic agent
Google agent
Microsoft agent
Custom agent
Specialist third-party agent

Universal interoperability is not claimed as a current production feature.

The model may change. The agent framework may change. The company’s operating rules should not have to.

Digital workforce

Human employee

Identity
Job description
System access
Delegation limit
Manager
Approval authority
Audit

AI agent

Agent ID
Instructions
Tool access
Action ceiling
Orchestrator
Human owner
Runtime log

Digital workers only become credible when their authority is defined.

What not to do

Ten ways to lose control of agentic AI.

01

Give one general agent every company tool.

02

Put passwords or API credentials into prompts.

03

Let external documents redefine system authority.

04

Give write permission when read is enough.

05

Allow unrestricted agent-to-agent delegation.

06

Use one shared service account for every agent.

07

Persist every interaction indefinitely as memory.

08

Allow the model to approve its own high-consequence action.

09

Deploy multi-agent complexity where deterministic workflow would work.

10

Run agents without observable logs and stop conditions.

Agentic maturity model

01

Assistants

Generate, retrieve and answer.

02

Controlled workflows

AI participates inside deterministic business processes.

03

Tool-using agents

The agent dynamically chooses tools inside defined scope.

04

Multi-agent operations

Agents delegate and collaborate under explicit policy.

05

Agentic operating system

Machine actors operate broadly while identity, policy, authority and audit remain centrally controlled.

Do not jump from Stage 1 to Stage 5. Earn autonomy.

Earned autonomy

Give an agent more authority because the evidence supports it—not because the demo looked impressive.

Prepare only

Establish baseline quality and safe context use.

Approved recommendation

Test judgement and escalation under review.

Limited action

Allow defined low-consequence actions with exceptions.

Bounded autonomy

Expand only after repeated evidence of safe performance.

Evidence should cover accuracy, policy compliance, safe escalation, reliable tool use, appropriate context selection and exception rates.

The agentic company

The future company may have more machine actors than human users.

Companies may eventually operate large numbers of agents, workflows, scheduled automations, MCP connections, tool identities and agent-to-agent relationships. The scaling problem becomes governance.

Who can see what?
Who can call what?
Who can ask whom?
Who can act?
Who can approve?
Who can revoke?
Who can explain what happened?
Who owns the machine actor?

TEMRIK positioning

You can build an agent almost anywhere. The harder question is how you let it into the company.

Agent frameworks help developers create and run agents. TEMRIK’s strategic position is the enterprise layer around them: business orchestration, company policy, agent identity, playbooks, context control, tool authority, human approval, model independence, auditability and multi-agent governance.

Business orchestration
Company policy
Agent identity
Playbooks
Context control
Tool authority
Human approval
Model independence
Auditability
Multi-agent governance

Agents need playbooks

Free field guide · 27 Rules of Peace

The more autonomy a system receives, the more important explicit operating rules become.

Download TEMRIK’s free construction AI field guide on decision rights, evidence, escalation, playbooks and keeping people in authority.

Start with one agentic workflow

Before you give an AI agent more authority, define exactly where that authority ends.

TEMRIK can help map a real workflow into its goal, data, agent, tools, permissions, delegations, exceptions, human authority and audit evidence.

AI agents can do more of the work without quietly taking over the organisation’s decision rights.

TEMRIK does not claim universal agent-framework support, guaranteed prevention of rogue-agent behaviour or automatic safety. Production controls depend on the selected architecture, providers and implementation scope.