Agentic work needs three layers, not one product.
Nagent builds the infrastructure that governs agents, the agent teams that do the commercial work, and the operating crew that makes the outcome land. This document sets out why the model has to be built in that order, and what two years of client work proved about each layer.
Screen capture with founder voiceover. Suggested run: Live Ops at rest, one approval queued and cleared, a workflow run overlay, then the team workspace thread where a human and an agent settle a decision. No music bed under the first fifteen seconds.
Agents do not fail at generating work. They fail at being accountable for it.Everything below follows from that sentence.
Nagent started where most of the market started, by making models produce commercial output. Campaign copy, outbound sequences, research briefs, video. That problem closed faster than anyone expected. By the middle of 2025 the quality of a single generated artefact was no longer what separated a working system from a demo.
What separated them was everything around the artefact. Who authorised it. What it was allowed to touch. Which version of the brand rules it read. Whether the same decision would be made the same way next Tuesday when nobody was watching. Whether a mistake would be caught in the hour or in the quarter. Whether the person accountable for the number could see enough to stay accountable.
Those are not model problems. They are organisational problems, and they are solved with infrastructure, not with better instructions. That is the first claim of this thesis.
The second claim is that infrastructure alone does not sell and does not deliver. A marketing head does not want a control plane. That person wants organic visibility to hold while paid spend efficiency improves, and wants to stop losing three days a week to coordination. So the infrastructure has to arrive wearing a job title. Nagent ships named agents with defined remits, reporting lines and a number each one owns, assembled into departments that map onto how commercial organisations are already structured.
The third claim is the one most platform companies resist. Software alone does not produce an outcome in an enterprise. Someone has to sit inside the client organisation, learn how work actually moves there, encode it, and then keep operating the system once it is live. Nagent provides forward deployed engineers for the first part and trained marketing and sales operators for the second. The delivery motion is not a support function bolted onto a product. It is a layer of the model, priced and staffed as such.
Infrastructure gives agents a place to be accountable. Applications give them a job. Operations make the outcome real. Remove any one layer and the other two stop compounding.
What follows sets out each layer in the detail an evaluator needs: the platform primitives and the control plane that governs them, the agent organisations that run on top, the operating model that puts humans in front of and behind the system, and the evidence base of client work and failed experiments that produced the design.
The bottleneck moved from making work to deciding on work.
The clearest version of this arrived during a summer 2026 campaign for Emami, on the Navratna brand. The brief called for a persona-led content programme at a volume no conventional studio would quote for. Eight AI personas were built, more than twenty films produced, and the campaign passed 24.5 million views in total, with a single film above 11 million.
(source: Emami campaign reporting shared with Nagent)
The production side was, by then, close to routine. What was not routine was the decision load around it. Every asset needed a call on brand fit. Every variant needed a call on whether it went live. Every performance signal needed a call on what to double down on and what to retire. The generation engine could produce a hundred options a day. The organisation around it could absorb perhaps a dozen decisions a day. The constraint had moved, and no amount of additional generation capacity would move it back.
This is the pattern that repeats in every serious deployment: capability outruns governance, and the gap shows up as unused output, quiet risk, or both.
Three failure modes follow from that gap, and each one has cost a real engagement.
Output nobody ships
An agent produces good work that sits in a queue because no one has the authority, the context or the time to approve it. Measured value is zero. The client concludes the agent does not work, when in fact the approval path was never designed.
Action nobody sanctioned
An agent with tool access does something irreversible: an email to the wrong segment, a bid change on a live campaign, a record overwritten in a system of record. One such event ends a pilot, whatever the aggregate quality of everything else.
Drift nobody noticed
An agent performs well for six weeks and then degrades as prompts, data or context shift. Without scored behaviour over time, degradation is discovered by a customer rather than by an operator.
Copilots do not address these, because a copilot suspends every decision until a human is present and therefore never accumulates leverage. Workflow builders do not address these, because a fixed graph handles the case it was drawn for and escalates everything else to a person who has to reconstruct the context from scratch. Agencies do not address these, because their unit of delivery is human hours, and their incentive is to keep the process opaque.
The answer Nagent arrived at is graduated autonomy with an evidence trail: an agent earns the right to act unsupervised by demonstrating, on the record, that its judgement holds. That mechanism cannot live in an application. It has to live in the layer beneath it.
Three layers, built bottom up, sold top down.Select a layer to see what it owns and why it cannot be collapsed into its neighbour.
This is the durable asset. It holds the client's knowledge, rules, data and tool access; it is where agents are built, governed, budgeted and scored; and it is the only place a full audit record of agent and human action exists. Four patents have been filed on the orchestration and memory management methods that sit here, three of which are published.
It is deliberately not a vertical product. The same primitives that run a performance marketing team run a sales development team, a customer experience function, or a financial operations workflow, because the thing being abstracted is governed agentic work, not marketing.
Each department has a chief of staff agent that owns a number and specialist agents that execute against it. MIRA leads marketing over DRIS, NIA, MOXA and CREA. SERA leads sales over NORA, DEXA and RIVA. Convexa spans the conversion surface between the two. Kinetiq produces the video.
The application layer is what a buyer actually evaluates, and it is where the commercial contract sits. It exists because infrastructure does not have a job description and a job description is what an operating budget is approved against.
Nagent AI Labs runs a discovery sprint inside the client organisation, maps the real decision paths, encodes knowledge and rules into the platform, provisions the agent team and sets the guardrails. That is the engineering half.
The operating half places Nagent marketing and sales people alongside the agents, sitting in the same workspace, taking the approvals, working the escalations and reporting against the number. The client buys an outcome; the composition of agents and humans behind it is Nagent's problem to optimise, and the mix shifts towards agents as trust scores rise.
Sales org — SERA NORA DEXA RIVA
Customer experience — CONVEXA
Agent tools — CRM · MESSAGES · RESEARCH
Teams workspace
Orchestration engine
Composable agents
Skills · Tools · Models · Smriti · Karmic
The platform primitives sit inside the control plane rather than beside it. Nothing in the application layer reaches a tool, a data source or an outbound channel except through a scope the control plane issued.
The platform is the asset. Everything else is an expression of it.Seven primitives, one control plane, one live view. Nothing in the layers above reaches a tool, a document or a customer except through them.
Nagent's platform is an agentic operating system for enterprises. That phrase earns its keep only if the platform does what an operating system does: hold shared state, arbitrate access to resources, schedule work, isolate tenants, and keep a record that survives any individual process. A prompt library does none of that. A workflow tool does some of it for a fixed set of paths.
The design conviction underneath is short. Autonomy is earned, not deployed. Every agent on the platform starts supervised and proposes actions for human approval. As it demonstrates reliable performance, it moves up a trust ladder, and at each grade it may do more without asking. At every grade, actions stay logged, attributable and reversible.
What follows walks the primitives in the order an organisation meets them.
Organisation. Knowledge, rules, assets, data, tools, people and roles, held once at the tenant boundary and scoped outward. Knowledge on Nagent is scoped, never pooled: nothing in one organisation's hub is visible to another, and an agent sees only what its team and level permit.
Agents are only as good as the organisation they can read.
The first thing a deployment does is make the organisation legible to software. Not a document dump into a vector index, which is where most agent projects begin and stall, but a structured account of what is true, what is permitted, what is owned, and who decides.
Knowledge sits at three levels
Enterprise knowledge is the organisation-wide layer: documents and data, plans, product and service detail, the logo and brand assets, brand guidelines, ideal customer profiles and competitor intelligence. It is owned by organisation administrators, and it is where the single source of truth lives. When an agent anywhere in the tenant describes a product or applies the brand, it draws from here.
Team knowledge is scoped to one AI team: the shared files, the working surface, the system of record that a team's humans and agents both work from. What one agent learns lands here, where teammates build on it rather than starting over.
Agent knowledge is the individual layer, and it is the agent's skills. Two agents on the same team can share every document and behave completely differently, because their procedures differ.
When an agent works, its effective knowledge is the stack of all three. Conflicts resolve towards the more specific level: a team's documented way of working beats a generic enterprise document, and a skill's explicit instruction beats both.
Retrieval is hybrid because knowledge is not one thing
Text-based knowledge is indexed into a vector store and retrieved semantically, so agents reason over the organisation's actual material rather than general knowledge. Vector storage runs on MongoDB, with Pinecone available as the vector layer for enterprise customers.
Media assets do not go through semantic search. Logos, product images, video and brand files are stored and served through a content delivery network and retrieved directly by reference. Semantic retrieval finds the right passage; direct retrieval guarantees the right file. Brand-critical assets arrive byte for byte as uploaded, which is the difference between a usable creative agent and one that quietly approximates a logo.

Show the three levels in the left navigation and at least one source in each indexing state. Anonymise document titles if the tenant shown is a live client.
Rules are captured as artefacts, not settings
Brand guidelines are converted by Brand Lock AI into a structured markdown file that agents check work against, so voice, tone, terminology and visual standards shape output rather than sitting in a PDF nobody reads. Ideal customer profiles are held as first-class records that marketing and sales agents both target against. Competitor profiles are held so that agents drafting positioning or handling objections cite a maintained file rather than improvising claims.
Tools are hands, and every finger is individually enabled
Integrations connect third-party systems and define exactly which actions agents may fire. Connecting a tool does not hand agents its capability. Every action is individually whitelisted, individually scoped, and governed by the trust ladder. On the Pro tier integrations run through Composio, giving a catalogue of more than 1,100 tools with managed authentication. On Enterprise, that is joined by custom integrations and native connections over Model Context Protocol and REST for internal systems.
The protocol works in both directions. Agents built elsewhere can be brought onto Nagent as integrations, placing them under the same governance, approvals and audit trail as native agents. An organisation that has already built with a coding agent does not have to discard that work to govern it.
Triggers let the outside world start agent work: a new message received, a record changed, a schedule reached. Work started by a trigger is governed exactly like work started by a person, so an event can never cause an agent to do something it could not otherwise have done.

The Gmail or HubSpot action list works best here: a long list of individually ticked actions makes the whitelisting argument visually, with destructive actions visibly unticked.
People and roles are modelled as peers of agents
The organisation holds its humans with the same weight as its agents: named members, workspace roles, team leads, approvers by email, and an explicit fallback to anyone holding the relevant permission. Approval authority is framed at the agent level as a plain question, which is who may override this agent's verdicts. That framing keeps accountability with a person rather than dispersing it into a policy engine.
Work happens in a shared room, and the room keeps the record.
On Nagent, work does not happen in isolated chat windows. It happens in an AI team: a persistent space where several humans and several agents operate side by side, run workflows together, and share one pool of context and decisions. The composer in that thread reads "talk is work, and it is on the record", which is the design claim in six words.
Two rules make the thread more than chat. Addressing has meaning: mentioning an agent asks it to answer, mentioning a person records it, and either way the mention is on the record. Instructions become tasks: when someone gives an instruction, the team lead agent proposes it as a captured instruction, a human confirms it, and it lands on the task board attributed to whoever raised it. Nothing scrolls away. An instruction either becomes a task or visibly does not.
Behind the thread sits a repository that holds the team's operating state as files rather than settings. That choice is load-bearing. Files can be quoted, cited and revised, and every member reads the same ones, so humans and agents share one picture of the team rather than two representations that drift.
| FILE | WHAT IT ANSWERS | WHY IT IS A FILE |
|---|---|---|
| charter.md | What this team exists to do, with real targets, thresholds, guardrails, response commitments and reporting cadence | Agents are held to it and cite the line they acted on. Editing the charter is editing the team's contract, and the edit itself is logged |
| roster.md | Every member, human and agent, with leads marked in both species | The list both species read when deciding who to hand work to |
| tasks.md | One board for both species, each task attributed to whoever raised it and linked to the run it produced | Connects instruction to outcome permanently |
| smriti.md | What the team has learned and carried forward | Memory that any member can read and correct, rather than an opaque store |
| decisions/pending.md | What is awaiting a call | The file is the queue, so pending decisions cannot hide in an inbox |
| decisions/log.md | What has been decided | Decisions are made once and cited thereafter, not re-litigated per agent |
| access.md | Who can open this team's thread, documents and decisions | Access stated as part of the record rather than buried in an admin panel |
| events.log | Every action by every actor, timestamped and attributed | Append-only at the point of write, so a correction is a new line and never an edit |
| runs/ | One file per executed run: steps taken, tools fired, approvals sought, output produced | The account of what an agent actually did with a task |
Each file answers a question every organisation eventually asks of an AI system. What was this team meant to do. Who was on it. What was it asked to do. What did it actually do. What did it decide. What did it learn.
The board contract
The task board runs on an explicit contract worth stating precisely, because it is where most agent platforms get vague. Confirming a captured instruction is the authorisation, and a task assigned to an agent is then picked up without a second press. Authorisation to start is not authorisation to act: what the agent chooses to do still faces its own approvals, per its trust level and the action whitelist. The board starts work; it never bypasses governance.
Membership is the access boundary
Being on a team is what opens it. Removing a member closes their access to that team's record and changes nothing about their access to the rest of the workspace. Agents join teams from the workspace register carrying their own governance with them: an agent at a given trust level holds that level on every team it serves, its side-effect actions still queue, and tool actions scoped away from it stay out of reach. Joining a team never widens what an agent may do.
The practical effect is that a new human member needs no handover meeting. The charter, the decision log and the last few runs are the handover.

The strongest single frame in the product. Capture a sequence showing a human instruction, an agent picking it up, a captured instruction awaiting confirmation, and a decision being recorded. Keep the repository panel visible on the right.
One unbroken take: type an instruction, confirm the captured task, watch the agent run, then open the run file it produced. This is the clearest demonstration of the record.
Orchestration is deterministic where it must be, and reasoned where it can be.
Two orchestration models are usually presented as opposites. A workflow engine gives repeatability and no judgement. A free-reasoning agent gives judgement and no repeatability. Neither survives contact with commercial work, where the same process needs to run identically two hundred times and then handle the case nobody drew.
Nagent runs a deterministic orchestration layer underneath reasoning agents. The sequence, the state transitions, the retries and the gates are deterministic and testable. The judgement inside each step is the agent's. A campaign state machine holds exactly one stage per account with logged, reversible transitions; the decision about what to say to that account is reasoned.
Workflows are versioned artefacts
A workflow is created from a one-line description and lands as a draft. It carries a version, and live examples in production run to v8 and v21, which is the ordinary shape of a process that has been corrected by real use. The builder offers a pipeline view and a graph view, with node types for agent, branch, parallel, join, loop and end, run inputs, and a live-run overlay that shows execution moving through the graph.
The builder assistant is called the Conductor. It will explain what a branch is, when an orchestrator earns its keep, and what the engine cannot do, and it states plainly that nothing goes live without an explicit accept. An assistant that names its own limits is a small thing that changes how much an operator trusts the rest.
Blast radius is reported at design time
The builder carries a blast radius panel that flags, before a workflow ever runs, what it can reach: whether it calls a third party, whether an action it uses is unscoped and therefore available to every agent in the tenant, and where side effects sit in the sequence. Most platforms surface this after an incident, in a log. Reporting it while the workflow is being drawn is the difference between a control and a post-mortem.
Only a team lead may start a workflow, and the workflows a team may start are listed per team. Starting one is a plain instruction in the thread rather than a separate console, which keeps the record in one place.

Pick a workflow with a branch, a parallel and a join so the node vocabulary is visible. Have the blast radius panel open with at least one flagged condition showing.
An agent is a governed digital worker, not a script.
Most platforms define an agent by what it can do. Nagent defines an agent equally by what it is allowed to do, and by how that allowance grows. In practical terms an agent here is a role rather than a prompt, skilled rather than general, remembering across sessions, and accountable through a logged record that feeds a trust score.
Building one takes under five minutes and three steps. Describe the role in a few lines and answer a short set of questions; Helix, the agent builder, assembles a definition in one to two minutes; then the definition is reviewed and edited before provisioning. What is reviewable at that third step is the full anatomy: key, name and description, skills, tools, models, capabilities, triggers, guardrails, autonomy, system prompt and risk level. Agents can also be built conversationally by addressing the builder agent inside a team thread.
Every new agent lands unprovisioned and starts at the bottom of the ladder regardless of how it was created. There is no path by which a well-written description produces an agent that can act unsupervised on day one.
The register is a workforce health check
The workbench lists every agent with the same columns: role, operational state, autonomy level, model, whether memory is on, whether the learning loop is active, how many whitelisted tool actions sit in its scope, and how many times in the last day it handed work to a human or another agent. That last column is the useful one. A rising handoff count is an early signal that an agent is out of its depth, visible before quality drops.
Operational states are deliberately few: active, observing (watching and learning without acting, which is how a new agent builds context or a read-only monitor operates by design), paused, and unprovisioned.
Agents group into clusters with distinct jobs. A super coordinator routes incoming work, one per workspace. Builders create agents, skills and workflows and are maintained by Nagent rather than edited by the tenant. Function specialists sit deep in one function. Custom agents are built by people in the organisation, each showing its author and visibility, and a mature workspace holds far more custom agents than prebuilt ones. Internal agents run schedulers, pipeline runners and optimisers behind the scenes.
Composition, hierarchy and handoff
Agents report to other agents. Each carries a reports-to key and a tier, and handoff targets are derived from the reporting line rather than stored separately, routing to parent, children, root, or sideways to a function specialist. Cluster tags group agents into pods. A team can designate an agent lead alongside its human lead, so leadership exists in both species, each leading its own.
NORA is the clearest worked example of composition. It is one product with one workflow, executed by an orchestrator and six specialised sub-agents: PLAN builds the knowledge base and campaign checklist, DISCOVER cuts a longlist to a shortlist, ENRICH researches each account and maps its buying committee, ENGAGE drafts and after approval sends across channels, ANALYST reports the funnel weekly, and ONBOARD activates customers who close and writes what it learns back into PLAN's knowledge base. Sub-agents never talk to the outside world directly. They return work to the orchestrator, and everything outbound passes the approval gate, which is architecture rather than a setting.


Choose a view where L1, L2, L3 and L4 agents appear together, since the argument is that trust attaches to the agent rather than the workspace. Include the 24-hour handoff column.
Three steps end to end: describe, wait through the build, then review and provision. The review screen is the important frame because it shows guardrails and autonomy being set before anything runs.
Skills, tools and trust are three separate controls over one behaviour.
Keeping these apart is what makes a large agent estate governable. A skill answers how the work is done and within what boundaries, and is set in the skills catalogue. A trust level answers how much of it the agent may do without approval, and is set in the workbench. A tool action scope answers which external actions the agent can physically reach at all, and is set in integrations. Widening any one never quietly widens the others, which is why the same skill can be shared between a junior and a senior agent safely: same procedure, different autonomy.
Skills are written procedures, not capabilities
A prompt describes an agent's disposition. A skill defines a unit of its work, with a trigger, a procedure and a boundary. "Handles paid search" is a role. "Every outbound post must pass a deterministic compliance gate before approval" is a skill. Agents built from skills behave predictably because every behaviour traces to a written procedure someone can read, question and revise.
Each skill carries a key, name, description, trigger conditions, a priority number that orders loading, an allowed-agent list, and a markdown body holding the procedure. Guardrails, escalation rules and rollback behaviour are written into the body as rules of the procedure, which keeps them versioned and readable in one place with the work they govern. A revision produces a new version, so what an agent did last month is explained by the skill as it stood then rather than as it reads today.
The prebuilt catalogue demonstrates a layering worth copying, visible in the priority bands. Contract skills load first and define how agents share state, so any run can be replayed, audited and continued by a different agent instance. Convention skills hold a team's vocabulary, schemas and hard rules, loaded before every action skill in their domain, so changing the convention once changes every skill downstream. Gate skills are deterministic checks work must pass before it proceeds, and the same input always passes or fails the same way, which is what makes them dependable as controls. Action skills do the work and rely on everything beneath.
This layering is why an agent with forty skills is not forty times harder to govern: contracts and gates police the boundaries for all of them.

Sort by priority so contract and convention skills appear above action skills, which makes the layering argument visible without narration.
Tools become available one action at a time
Nothing is enabled by default when a tool is connected. Each action is ticked individually, and each shows its name, technical identifier and a description of exactly what it does. Side-effect actions are labelled throughout, so it is always visible which actions carry consequences.
Whether a whitelisted action fires immediately or waits depends on two things: what kind of action it is, and the trust level of the agent calling it. Read-only actions fire automatically from L1 upward. Anything that creates, modifies, sends or deletes queues for approval below L3 and executes directly at L3 and above. The same whitelisted action is a proposal in the hands of a new agent and an execution in the hands of a proven one.
Scope controls reach. An unscoped action is available to every agent in the tenant, and that breadth is exactly what a workflow's blast radius report shows. Narrowing an action to the agents that need it means no other agent can reach it, whatever its own tool list says. The operating practice is to whitelist narrowly, scope tightly, and widen only when a real workflow needs it.
Models are an agent-level decision
Most agents run on the platform default, with Claude Sonnet autofilled, while individual agents are pinned where their work benefits: a heavyweight model for long-form writing, a different provider for a research variant, a small fast model for reply classification. More than 365 models are browsable, and image models are set separately from text models. Model choice is a per-agent setting, not a platform-wide constraint, which matters both for cost control and for the pace at which a tenant can adopt a new model without re-platforming.
Smriti is memory that a person can read
Agent Smriti holds what an agent has done, decided and learned, scoped to the tenant and inspectable by humans. It is layered: a creator layer carries operator-authored hard rules and brand voice, and a user layer carries the agent's own observed tendencies, recent successes and recent failures. At team scope it is a readable file that any member can correct.
Underneath sit the components that make replay possible: context snapshots, a cognitive graph, a cognition pyramid that rolls episodic memory up through daily, weekly and monthly horizons, long-term doctrines, temporal replay, structured memory and prompt history with comparison. Every agent turn persists its assembled context for inspection and replay, which is the mechanism that turns "the agent did something odd last Tuesday" into a question with an answer.
Karmic is the loop that moves trust in both directions
The karmic feedback loop converts outcomes and human feedback into trust adjustments, upward and downward. What humans change is what the system learns: approval edits, refusals and outcomes all feed it. Reformation rules govern what happens when an agent underperforms or oversteps, and an agent can be moved to a probation bench rather than switched off, which keeps it earning its way back on supervised work.
Learning mode is set per agent. Continuous adapts immediately and is the default. A training window queues every action for human approval for the duration, which is the setting to use when a process is being changed rather than run.
Trust scores drift and can auto-downgrade without any human acting. An agent that degrades loses autonomy on the evidence, not on someone noticing.

Show the assembled context for one turn with its sources, so the replay claim is evidenced. Redact any client content.
Autonomy is earned, not deployed.Five grades, scored continuously, reversible without a human in the path.
The trust ladder is the mechanism the rest of the platform hangs from. Every agent holds a position on it and a trust score out of 100. Each grade widens what the agent may do without approval. No grade removes the record.
Select a grade to see what changes.
L0 · Novice · locked
Every output requires a human to act on it. The agent proposes and nothing else. This is where every agent begins, prebuilt or custom, however it was created and whoever created it.
| READ-ONLY TOOL ACTIONS | Queue for approval |
| SIDE-EFFECT ACTIONS | Queue for approval |
| HUMAN POSITION | In the loop, on every item |
| TYPICAL USE | First two weeks of any new agent |
(L1 to L4 panels: copy to be supplied.)
L1 · Apprentice
L2 · Practitioner
L3 · Senior
L4 · Expert
Progression is earned against the record rather than granted in a settings panel. The karmic loop reads outcomes and human corrections, and the score moves in both directions. Downgrades happen automatically when performance slips, which is why the attention rail in Live Ops watches for trust drift and auto-downgrades as first-class events rather than footnotes.
Autonomy is individual, and that is the point most easily missed. Agents at four different grades sit side by side in the same workspace. A coordinator can hold a high grade while a newly built custom agent beside it holds a low one, and a long-serving research specialist holds the highest. An agent carries its earned grade to every team it serves, and joining a team never widens it.
Guardrails are per agent, added from a library, and enforced in three ways
Each guardrail carries a severity, a category and an enforcement action. Severity is advisory or blocking, and advisory means the agent is alerted while the action still runs. Categories cover content restriction, cost cap, time window, audience restriction, tool restriction and approval requirement. Enforcement is to warn, to queue for approval, or to block outright.
The template library reads like operator experience written down, because it is. External communications are named as the highest-risk surface for early-autonomy agents. Agent-to-agent handoff without approval is restricted to prevent runaway chains during early operation. Reasoning from supplied context is advisory rather than blocking, because some agents legitimately do it.
Cost caps that act
A daily cap auto-pauses the agent on breach until an operator resets it. Monthly caps sit alongside. Budgets are per agent with a fourteen-day spend trend, and the behaviour on exceeding a cap is to queue actions for approval rather than to stop the agent.
Claims and voice
Templates ban pricing in writing, require a source for every factual claim, restrict citations to published content, forbid medical and legal advice, and enforce brand voice down to a banned-phrase list.
When and to whom
Firing windows constrain agents to working hours in a named timezone. Audience restrictions gate outbound to qualified segments only. Personal data exposure and named customers in public output are blocked outright.
Policies are the hard runtime gates
Where guardrails shape behaviour, policies constrain execution. Approval policies name the actions that must route through the approval engine instead of executing, the approvers who receive the queue, and a service level for a decision, defaulting to 24 hours. Execution policies set maximum runs per hour, a daily cost cap and a per-action cap. These are runtime limits rather than instructions, so an agent cannot reason its way past them.
Access control covers both species
Role-based access control applies to humans and to agents through the same model. For humans it governs which surfaces, tenants and teams they can open, and which approvals they can give. For agents it governs which knowledge scopes they can retrieve from, which tool actions they can reach, which other agents they can hand work to, and which artefact types they may write. Team membership is the access boundary for both, and every addition and removal is a logged, attributed line.
Data access control runs at the tenant boundary first: nothing in one organisation's knowledge is retrievable by another, and enterprise deployments run in a private virtual private cloud with the tenant's own storage and content delivery endpoints. Inside the tenant, scope narrows by level, by team and by agent, and a retrieval that falls outside scope returns nothing rather than degrading to a general answer.
Blast radius is a first-class report
Blast radius answers a single question: if this goes wrong, how far does it reach. It is computed from the scopes an action carries and the reach of the workflow that calls it, reported at design time in the builder and monitored at run time. Narrowing scope shrinks it. The report is what makes "whitelist narrowly, scope tightly" an inspectable practice rather than advice.
Anomaly detection watches behaviour, not just errors
The governance surface is a per-agent scoring screen rather than a permissions table, and it sorts worst first. Each agent carries a composite score out of 100, banded critical, risk, watch or healthy, built from five sub-metrics covering trust, karma, error rate, block rate and autonomous action rate, with a recompute action available. Row copy names the weakest dimension in plain words, for example weakest is karmic stability, or weakest is trust trajectory.
Three header cards frame it. Predictive warnings flag agents heading towards trouble before they arrive. Cognitive drift bands agents severe, significant, modest or stable. Operator impact scores human decisions over a seven-day window, which is the unusual one: the system grades the quality of human approvals alongside agent behaviour, on the reasoning that an approval queue rubber-stamped by a tired operator is a governance failure whichever species caused it.
The audit log is append-only where it is written
Every event is a timestamped line attributed to its actor, and agent actions and human actions are recorded in the same format in the same log with no privileged species. Append-only is enforced at the point of write rather than in the view, so a correction is a new line and never an edit. That single property is what makes it an audit trail rather than a diary, and it is the property enterprise security reviews test first.

The most persuasive screen for an enterprise security reviewer. Capture with at least one agent in a risk band so the sorting behaviour is evident, and with the three header cards visible.
Two frames side by side. Left, the guardrail list with severities and categories visible. Right, approval and execution policies with caps set. Composite the pair before placing.
One live view, and both species in the same event stream.
Live Ops is the day-to-day home for operating agents. Its header carries four metrics: agents active, pending approvals, events in the last five minutes, and model spend. Those four answer what is running, what is waiting on a person, how busy the system is, and what it costs, which is close to the full set of questions an operator asks in a morning.
The actor filter is the design decision worth noting. Humans, agents, system and visitors are treated as peer actor types in one stream. There is no separate human activity view and agent activity view to reconcile, because reconciling them is precisely where accountability gets lost.
An attention rail carries pending approvals, escalations in the last 24 hours, and trust warnings in the last 24 hours, with a healthy state that reads as no drift beyond ten points and no auto-downgrades. Quick actions sit alongside for creating an agent, connecting a skill or adding a tool, so an operator who spots a gap can close it without leaving the screen. An orchestrator chat panel sits inside Live Ops and answers the question an operator actually has, which is what should be looked at first.

Capture during a period with genuine activity: several agent events, at least one human event, one pending approval. The four header metrics must be readable at the width this is placed.
Topology shows the shape of the estate
Topology renders the agent estate as a structure rather than a list: which agents report to which, which sit in which pods, what each can reach, and where the dense clusters of tool access are. A living view animates the same structure with current activity, so the estate can be watched rather than queried. For an organisation running dozens of agents across several departments, topology is what stops the estate becoming an unmapped surface.
Alongside Live Ops and topology sit integrity, governance, anomalies, missions, episodes, actions and model spend, with agent budget defaults and internal operations. Missions and episodes matter for the application layer: each agent has a mission control page showing the number it owns, a monthly plan with objectives, an at-risk status, and a funnel with targets. Mission control answers what the agent did today, what it spent, and what is waiting on a human.

The living view with activity in flight is stronger than the static one. If capture quality suffers from animation, take a short screen recording instead and place it as a looping muted clip.
Infrastructure does not have a job description. Agents do.Six prebuilt departments, each led by a chief of staff agent that owns a number, with specialists who execute against it.
The application layer exists because operating budgets are approved against outcomes, not against primitives. A marketing director evaluating Nagent is not choosing an orchestration engine. That person is deciding whether organic visibility will hold while paid efficiency improves, and whether the team stops losing three days a week to coordination.
So the platform ships as an organisation. Levels run from the organisation, to departments, to teams led by a team lead, to agents and their sentinels, alongside humans with roles. Six departments come prebuilt: brand and marketing, sales, content creation, customer experience, operations, and research. Each ships with its agents, their skills, their internal hierarchy including the team lead, and its standard workflows already wired together. A prebuilt team is a starting point rather than a fixed unit: after installation agents can be added or removed, skills adjusted, and workflows edited to match house practice.
Installing a team does not grant the team autonomy. Every agent in it holds its own position on the ladder and starts at the bottom, so a newly installed department runs supervised by default and earns its way into autonomy agent by agent.
Owns the marketing number and routes work across the department. Also the onboarding coordinator: MIRA walks a new organisation through initial configuration, and on Nagent's own deployment is the super coordinator that routes incoming work across every team.
Owns organic and answer-engine visibility across search and AI assistants, running as six coordinated roles: orchestrator, access prober, corpus mapper, extractability analyst, knowledge consistency auditor and report composer, against a weighted scoring rubric.
Owns spend. Covers the full campaign lifecycle on Google Ads: planning, creation, optimisation and running, under spend guardrails, rollback rules and containment policies set per campaign rather than per platform.
Owns the social surface: planning, production scheduling, publishing and community response across channels, with a deterministic compliance gate in front of every outbound post.
Produces the written and visual work the rest of the department needs, checked against brand guidelines held in the knowledge hub and against a claims gate that requires a source on file for every factual statement.
Brand video at volume, built on a deterministic rendering engine with an authoring layer on top: four-way editing, a full timeline, more than 130 templates, brand kit capture, speech, an agentic quality loop, a persistent render queue and exports to 4K in any ratio.
Reads across the department's channels and reconciles what happened with what was planned, so the chief of staff has one number to work from rather than four platform dashboards that disagree.
Owns the revenue number and the planning motion above the department, coordinating outbound, deal execution and revenue operations, and working alongside human account executive and sales head seats rather than in place of them.
Runs the outbound motion end to end: sourcing accounts against the profile with a verified reason to reach out now, researching each into a cited dossier, writing multi-touch sequences, qualifying replies through a state machine, and booking meetings onto a human calendar with the dossier attached to the invite.
Carries an opportunity from qualified through to close: preparation, follow-up discipline, document assembly, objection handling against maintained competitive files, and the handoffs that otherwise go missing between calls.
Keeps the record true: pipeline hygiene, stage integrity, attribution, forecast inputs and the reconciliation between what agents did and what the system of record says happened.
The conversational surface across chat, voice and video, spanning the join between marketing and sales. Convexa is deployed as a suite rather than a single agent, and is the first Nagent product several enterprise clients put into production.
An inbuilt customer record designed so agents can read and propose writes under the approval gate, which removes the need for a separate third-party licence. Agents can equally write into Salesforce, HubSpot or Zoho where a client already runs one, with writes queued as proposals until approved.
Warmed sending infrastructure with staggered sends, domain warm-up, caps and suppression built in. Tenants connect their own mailboxes for outreach rather than sending on shared infrastructure, which keeps deliverability and reputation with the client where it belongs.
A multi-agent research system that fans out across several model providers and the open web, then grades claims against a ledger so a dossier carries its sources with it. Deep research and web search ship as base tools inside every sub-agent on the platform.
A marketing department where the chief of staff is an agent.
The marketing organisation is the department with the most client mileage behind it, because it is where Nagent's own work started. Its structure follows the split that exists in most marketing teams already: someone owns the plan, someone owns organic, someone owns spend, someone owns social, someone owns content, and someone owns the numbers.
MIRA sits above as chief of staff. DRIS owns organic visibility across search and answer engines, which is a materially different discipline from classical search optimisation: the question has moved from where a page ranks to whether an assistant can access, extract and consistently represent what the organisation says about itself. DRIS runs an access prober, a corpus mapper, an extractability analyst and a knowledge consistency auditor precisely because those are the four ways an answer engine fails a brand. NIA owns spend across the paid lifecycle. MOXA owns social. CREA produces the content and creative, and Kinetiq produces the video.
The department was specified as a working programme rather than a diagram: twelve agents and sixty-seven skills across consumer goods and direct-to-consumer commerce, delivered in four waves with governance templates that tighten at each wave, covering spend guardrails, rollback, containment and data rights.

The monthly plan with objectives, at-risk status and the funnel with targets. This is the frame that shows an agent accountable for an outcome rather than a task.
Outbound rebuilt as a research problem with an approval gate.
The B2B sales organisation is four agents deep, with NORA live and leading. It is worth setting out in detail, because it is the clearest demonstration of what the platform underneath actually buys.
NORA is one product with one workflow, executed by an orchestrator and six specialised sub-agents. The orchestrator owns state and sequencing; each sub-agent owns one job. Sub-agents never talk to the outside world. Everything outbound, every email, every social message, every conversational touch, and every write to the system of record, passes through the approval gate. That gate is architecture, not a setting, and higher trust grades widen batch approvals without ever removing it.
How a campaign runs
PLAN reads the company's site, deck and documents, drafts three ideal customer profiles and the value narrative for human sign-off, and files pricing, sales material, templates and competitive intelligence onto knowledge shelves with source tags and refresh rules. Its governing rule is that an empty shelf produces a question to the operator, never an invention.
DISCOVER builds the longlist against those profiles and runs the first two cuts, scoring on a repeatable need-and-fit rubric, attaching a named trigger to each account from funding, hiring, leadership change or expansion signals, and removing existing customers, open opportunities and do-not-contact domains by reading the system of record. Every shortlisted company carries a written reason to be on the list.
ENRICH maps the buying committee for each shortlisted account and writes a cited dossier: fit reasoning, four pitch hooks each tied to a sourced signal, buying signals with links, and validated contact channels. It refuses to state what it cannot source, and research spend is metered and shown per account, at roughly a quarter of a US dollar per account in the current specification. The receipt trail is treated as a feature rather than overhead.
(source: NORA technical specification, 25 August 2026)
ENGAGE writes three touches per committee role per channel, grounded only in the knowledge base, opens with the account's own trigger rather than a template, classifies replies through a state machine on need, fit, authority, timing and intent, closes misfits politely, and books qualified meetings onto the human owner's calendar with the dossier attached. Any qualified handoff nobody acknowledges within 36 hours is escalated loudly.
ANALYST computes the funnel per profile and per channel deterministically from state, explains movements and anomalies, and ships a report every Friday whose numbers reconcile with the system of record. Its recommendations route back to PLAN as proposed checklist edits, so strategy changes face the same approval as sends.
ONBOARD activates a customer who closes on a day zero to day seven plan and writes what it learns back into PLAN's knowledge base, so the next campaign starts better informed than the last.
| STAGE | DEFAULT VOLUME | WHAT THE CUT TESTS |
|---|---|---|
| Longlist | 100 companies | Match against the three ideal customer profiles |
| Qualified | 80 companies | A named trigger is attached and the account is not already in the system of record |
| Shortlist | 15 companies | Deep research completed and a dossier written with sources |
| Contacts | approx. 75 people | Buying committee of five mapped per account and channels validated |
| Engagement | 3 touches per role | Every claim traceable to the knowledge base, every send approved |
Funnel defaults set in the campaign checklist and overridable per campaign (source: NORA technical specification v1.0, 25 August 2026).
The definition of done is stated in the same specification and is unusually blunt: meetings on a human calendar with the dossier attached, and no unapproved send, ever.
What the platform contributes to this is not the sequence, which any competent team could draw. It is that the sequence runs under one shared memory across all six sub-agents so no agent holds private state, a single approval queue for every outbound item and every record write regardless of which sub-agent produced it, a knowledge base that ENGAGE may only claim from, an audit log the customer can read, and a learning loop where the edits humans make to drafts are what the system learns from. Take those away and the same six sub-agents become an unaccountable sending machine.
The rest of the department
SERA sits above as chief of staff, owning planning and coordination. DEXA carries qualified opportunities through execution to close. RIVA holds revenue operations and the integrity of the record. NORA currently carries the department's coordination duties as team leader, handing qualified pipeline onward and escalating unacknowledged handoffs, and will brief the others as they come into production.
The department ships with eleven sentinel sub-agents and nineteen skills across a three-phase rollout, and buyers are typically revenue leadership, sales development leaders and founders at companies between fifty and five hundred people.

Left, mission control with the funnel and pipeline target. Right, the qualify kanban with per-account fit scores. If the re-scoring banner is showing, keep it: it is honest about a real limitation and reads well to technical buyers.
The conversational surface is where marketing and sales actually meet.
Convexa is the customer experience suite: the conversion and conversational agent covering chat, voice and video. It sits deliberately across the join between the two departments, because that join is where most commercial organisations lose people. A visitor who asks a question during evaluation is a marketing responsibility on Monday and a sales responsibility on Tuesday, and the handover between them is usually a form.
Convexa is governed the same way as everything else. It draws on the enterprise knowledge layer for what is true, on brand guidelines for how to say it, and on ideal customer profiles for who it is talking to. It cannot make a claim without a source on file. Its escalations to human agents are logged as handoffs and appear in the same event stream as everything else, and a rising handoff rate is treated as a signal about the agent rather than about the customer.
Convexa has been the entry product for several enterprise engagements, including a deployment integrated with a client's existing customer relationship system, with the data protection terms negotiated down to sub-processor schedules and a 48-hour breach notification commitment. That negotiation is itself informative: a conversational agent inside an enterprise is a data processing question long before it is a conversation quality question, which is why the compliance programme described later is not a footnote.

Show a real exchange with a citation to the knowledge base and a handoff to a human. Use a demo tenant rather than client data.
The tools agents operate ship with the agents.
An agent department that requires the client to buy four other licences before it can work is not a department. Nagent ships the operating tools inside the platform.
The agentic customer record is built so that agents read freely and propose writes under the gate, which removes the need for a separate licence for clients who do not already run one. Where a client does, agents write into it instead, with the same proposal-then-approval behaviour. Search and competitive data subscriptions are provided by Nagent rather than passed through as a client procurement item.
Messaging runs on warmed infrastructure with staggered sends, domain warm-up, caps and suppression, and tenants connect their own mailboxes so sending reputation stays with the client. Research runs as a multi-model system that fans out across providers and the open web and grades claims against a ledger, and is available as a base tool inside every agent rather than as a separate product.
Alongside these sit the studio tools: Brand Lock AI for converting brand guidelines into a machine-readable rule set, the agentic content studio, the visibility system that DRIS operates, and Kinetiq for video. Each is usable on its own and each is governed by the same control plane, which is the difference between a suite and a bundle.
Software does not produce an outcome in an enterprise. People do, with software.Forward deployed engineers stand the system up. Trained operators run it to a number.
This is the layer that platform companies avoid, usually on the argument that services do not scale and depress multiples. The argument is sound in the abstract and wrong for this category at this moment, for a reason worth stating plainly: the encoding work is where the value is, and the encoding work cannot yet be done by the buyer alone.
An organisation's real operating knowledge is not in its documents. It is in what an experienced person knows about which approvals are real and which are ceremonial, which data can be trusted, which customer segment is politically sensitive, and which process the written procedure describes incorrectly. Encoding that into charters, skills, guardrails and approval paths is a discovery job performed by someone sitting inside the organisation.
Forward deployed engineering
Nagent AI Labs is the enterprise offering. Forward deployed engineers run a discovery sprint inside the client organisation, then build and deploy custom agents on the platform. In practice the sequence runs: map the decision paths that actually exist, populate the knowledge hub at the three levels and confirm scope before agents draw on it, connect tools and whitelist actions narrowly, write the team charter as an operating agreement with real thresholds, provision agents starting with two or three rather than ten, put the actual supervisors in the workspace rather than the whole organisation, and let the first workflows run end to end under supervision before widening anything.
The platform documentation encodes this as expansion practice, and the reasoning is worth repeating because it is the opposite of how software is usually sold. Add supervisors before adding agents, because every agent below the execution grade generates approvals and someone has to be there to give them. Grow by one agent, not by five, because adding several at once multiplies the approval queue and dilutes the attention each agent's early work receives, and that early work is exactly what sets its trust trajectory.
Managed operations
Once the system is standing, Nagent places marketing and sales people alongside the agents. They sit in the same workspace, take the approvals, work the escalations, correct the drafts and report against the number. The client contracts for an outcome. The mix of agents and humans behind that outcome is Nagent's problem to optimise.
That mix is not static, and the direction of travel is the commercial argument for the whole model. An agent at the bottom of the ladder generates an approval for nearly everything it does, so early operation is human-heavy by design. As trust scores rise and guardrails prove themselves, the same volume of work needs materially fewer human decisions. Nagent carries the cost of that transition rather than the client, and captures the margin as it completes.
The operation layer is not a services business attached to a product. It is the mechanism by which the product learns what an enterprise actually does, and the reason each deployment makes the next one cheaper.
Shot in a client-like setting rather than an office backdrop. The strongest content is the specific: one process that was documented wrongly, and what changed once it was encoded correctly.
What the client sees
A named engineer through onboarding, a named operator through delivery, a workspace they can open at any time to see exactly what has been done and what is waiting, and a weekly report whose numbers reconcile with their own systems. The system of record for the engagement is the same workspace the agents work in, so there is no separate status document that can quietly diverge from reality.

Show the four-stage path in one frame if the product allows it. If not, composite three frames: knowledge review, agent provisioning, first supervised run.
The model was not designed. It was arrived at.Seventeen client engagements, more than fifty proofs of concept, and two years of correcting what did not survive contact with an enterprise.
Nothing in the three layers was obvious in advance. Each part of the architecture exists because something failed without it, usually in front of a client. The sequence below is the honest version of how the company got here.
A prompt-driven workflow repository. The insight that stuck was that people wanted repeatable procedures rather than clever phrasing. The insight that did not survive was that a repository is enough.
Chinmoy Nanda joins as co-founder and chief product and technology officer, bringing platform architecture experience from Palo Alto Networks, Dell and HPE, which shaped the decision to build a control plane rather than a set of features.
A social posting agent and a competitive deep research agent. Both worked. Both immediately raised the question that became the company: who decides whether this goes out.
The first attempt at letting non-engineers assemble agents. Useful, and insufficient on its own, because an agent that anyone can build is an agent nobody can govern.
Building agents becomes routine. The constraint moves entirely to operating them.
Complex multimodal agents assembled from a single description, which is what makes the five-minute agent creation flow possible today.
Eight personas, more than twenty films, 24.5 million views in total. The moment generation was demonstrably solved and decision-making was demonstrably the constraint.
The whole platform ships as one release rather than a single named feature: the trust ladder, guardrails, policies, budgets, blast radius, governance scoring, Live Ops and topology.
The client work behind it
The engagements below span consumer goods, commerce, procurement, professional services, education technology, logistics technology, legal technology, recruitment and healthcare. They differ in almost every respect except one: each of them tested a different part of the model, and several broke it.
Logo slots L-01 to L-17. Supply as SVG or transparent PNG at 2× the placement height. Confirm written permission per logo before publication, and confirm whether each engagement may be named at all.
Fifty proofs of concept. Some failed. All of them changed the platform.
The enterprise pilots below are described by sector and scale rather than by name. Each entry states what did not work, because that is the part that produced the architecture.
Persona-led content production across multiple markets from one brand system, on the assumption that a strong brand rule set plus a strong generation engine would hold consistency at volume.
Brand rules held inside a single market and drifted across them. Guidelines held as documents were interpreted differently by different agents, and there was no mechanism to make a rule binding rather than advisory.
Brand guidelines became a machine-readable rule set rather than a retrieved document, and enterprise knowledge gained explicit precedence over team knowledge, so a market cannot quietly override a brand-level constraint.
Compliance-safe marketing production, where every outbound asset had to clear regulatory constraints before a human reviewer ever saw it.
Compliance treated as a prompt instruction is not compliance. Instructions were followed most of the time, and most of the time is the wrong standard in a regulated communication.
Deterministic gate skills entered the platform as a distinct class: checks that pass or fail identically on identical input, placed in front of any step that crosses into publication, spend or personal data. Guardrail severity became explicit, with blocking separated from advisory.
A multi-agent marketing team assembled quickly to demonstrate breadth: many agents, many skills, live within days.
The approval queue overwhelmed the client team within a fortnight. Every agent below the execution grade generates approvals, and provisioning ten at once multiplied the queue while diluting the attention each agent's early work received, which is exactly the work that sets its trust trajectory.
Expansion practice became part of the product rather than advice: add supervisors before agents, grow by one agent rather than five, and reuse a proven agent across teams instead of creating a fresh one at the bottom of the ladder.
A proposal into a formal corporate innovation programme, evaluated by a procurement and security function rather than by a marketing buyer.
The product answered every question about capability and almost none about deployment topology, data residency, sub-processors or exit. Capability was never the blocker.
Private virtual private cloud deployment became a first-class enterprise option, and the certification programme described below moved from a roadmap item to a funded workstream.
Agents operating against internal systems that predate every modern integration catalogue, in a business where the field organisation, not headquarters, holds the operating knowledge.
The integration catalogue covered none of what mattered, and the documented process differed from the real one in ways nobody at headquarters could see.
Native integration over Model Context Protocol and REST for internal systems, and the forward deployed engineering motion itself. The discovery sprint exists because this engagement proved that remote configuration cannot find what only a field operator knows.
An agent network operating across member institutions, where the same customer record is governed by several consent regimes at once.
A single tenant boundary was too coarse. Scoping knowledge by team and agent did not express the case where the same data is permitted for one purpose and forbidden for another.
A layered consent design for sovereign deployments, and the strengthening of data access control as a control distinct from role-based access, so purpose limitation is enforced at retrieval rather than assumed at configuration.
Brand governance across a portfolio of franchises, each with its own rules, licensors and tone, produced by one regional team.
A single knowledge scope per organisation could not represent a portfolio where the binding rules differ per franchise and a mistake carries licensing consequences.
Team-scoped knowledge with explicit precedence, and the shared-item model that makes cross-team visibility an enumerated exception rather than a default.
Pilots did not fail on output quality. They failed on the surrounding conditions: an approval path nobody owned, a knowledge base that was never populated properly, a tool the agent could technically reach but should not have been able to, or a schedule that fired work when no reviewer was available.
A run of internal corrections followed, including a hardening programme on the trigger system after an audit found scheduled work was being driven by polling rather than a real event bus, limits on knowledge retrieval depth that had to be raised, and a rebuild of the onboarding path from knowledge review through to agent provisioning and Live Ops.
Sales became discovery-led rather than demonstration-led, with a qualified activation target inside 24 hours, because a pilot that starts without the knowledge hub populated and the approvers named has already failed and simply does not know it yet.
What the system has produced, in the words of the people who ran it.Four customers agreed in September 2026 to be quoted by name. Their engagements span autonomous financial workflows, executive search, and outbound sales in two different markets.
An agentic chief financial officer function running autonomous financial workflows was the part we expected to take a year. Getting there was a matter of weeks, and the governance around it is what made it defensible internally.
CO-FOUNDER AND CEO, STRATIQAI
A leadership hiring workflow that used to take two days now completes in under twenty minutes. The work that remains is the judgement, which is the part we wanted to keep.
FOUNDING PARTNER, WINNSIGHT EXECUSEARCH
NORA produced eight qualified leads by day three. What convinced the team was not the volume, it was that every one arrived with a dossier we could check.
SALES MANAGER, MADMONK AI
Ten meetings with senior principals in Bengaluru, from a standing start. The approval gate meant nothing went out that we would not have sent ourselves.
FOUNDER AND CEO, SOPHOZ
Quotations are approved in substance; confirm exact wording with each named individual before publication. Portrait slots P-01 to P-04, square crop at 400 pixels minimum.
The campaign that made the argument
The Emami engagement on Navratna remains the clearest quantitative proof point available for publication: eight AI personas, more than twenty films, more than 24.5 million total views and more than 11 million views on a single film. It is cited here not as a volume claim but as the origin of the thesis, since it was the engagement in which the decision constraint became undeniable.
(source: campaign reporting shared with Nagent)
A short reel showing several personas from the same campaign, with an on-screen count of assets produced. Confirm usage rights with the client before this artefact is shared externally.
The Friday report from a live engagement, redacted. Buyers respond more strongly to the reporting artefact than to the dashboard, because it is what they will actually receive.
The questions that decide an enterprise deal are not product questions.
Deployment
Enterprise clients are deployed into a private virtual private cloud, with tenant-controlled storage and content delivery endpoints, and vector storage on Pinecone where the tenant requires it. Sovereign deployment designs have been produced for regulated Indian infrastructure where data residency and consent architecture are contractual rather than advisory.
Tenant isolation is a platform property rather than a configuration: knowledge is scoped, never pooled, and no retrieval crosses an organisation boundary. Within a tenant, scope narrows by level, by team and by agent, and a retrieval outside scope returns nothing rather than falling back to a general answer.
Certification programme
Nagent is in process across five frameworks. Status is stated plainly below rather than implied, because a compliance claim that overstates its stage is the fastest way to lose an enterprise security review.
| FRAMEWORK | SCOPE | STATUS |
|---|---|---|
| ISO 27001 | Information security management across the platform and the operating organisation | IN PROCESS |
| SOC 2 Type II | Operating effectiveness of security, availability and confidentiality controls over a period | IN PROCESS |
| GDPR | Processing of personal data of subjects in the European Union, including sub-processor disclosure | IN PROCESS |
| HIPAA | Handling of protected health information for healthcare deployments | IN PROCESS |
| DPDPA | India's Digital Personal Data Protection Act, including consent and data principal rights | IN PROCESS |
| Private VPC deployment | Single-tenant deployment inside the client's own cloud boundary | AVAILABLE |
| Append-only audit trail | Every action by every actor, enforced at the point of write | AVAILABLE |
Contractual practice has followed the same discipline. A logistics technology engagement was signed with data protection terms revised down to a sub-processor schedule and a 48-hour breach notification commitment, which is the standard the programme is being built to meet consistently rather than case by case.
Intellectual property
Four patents have been filed on orchestration and agentic memory management. Three are published by the Indian Patent Office, in Journal 29/2026, July 2026. Publication links are available on request and are placed below for the published set.
Orchestration method
Indian Patent Office, Journal 29/2026, July 2026. Publication link to be inserted
Agentic memory management
Indian Patent Office, Journal 29/2026, July 2026. Publication link to be inserted
Memory and context assembly
Indian Patent Office, Journal 29/2026, July 2026. Publication link to be inserted
A fourth application is filed and not yet published. Titles above are placeholders pending the exact published titles, which should be transcribed verbatim from the journal entries.
The hypothesis was sharpened in public, with people who pushed back.
Nagent's thesis was not developed in isolation. Four institutions gave the company access to enterprise buyers, technical infrastructure and the kind of scrutiny that changes a position rather than confirming it.
nasscom
Through the GenAI Foundry programme, including a founder feature. Access to the Indian enterprise technology buyer community and to peer scrutiny of the governance argument.
iHub, IIT Mandi
Research grounding and technical validation for the orchestration and memory work that became the patent filings.
MATH at T-Hub
Go-to-market structure and the discipline of testing the model against buyers rather than against advisors.
CII
Enterprise access including an industry delegation to Japan in August 2026 with the Commerce and Industry Minister, which tested the model against buyers outside the home market.
Nagent is also an official Anthropic partner, which matters less as a badge than as a working relationship: the platform is model-agnostic by design, with more than 365 models selectable per agent, and the partnership sits alongside that rather than constraining it.
Advisors
Four advisors have shaped the thesis, each on a different axis: enterprise services and delivery economics, brand and marketing organisation design, product and platform architecture, and commercial strategy.
Raja Renganathan
One line on remit and background to be supplied.
Asavari Moon
One line on remit and background to be supplied.
Ankur Jain
One line on remit and background to be supplied.
Gaurang Gupta
One line on remit and background to be supplied.
The team
Thirteen people, ten of them in engineering, based in Bengaluru. Pratap Behera is co-founder and chief executive, with a background in retail and commerce that includes prior work with BigBasket. Chinmoy Nanda is co-founder and chief product and technology officer, and owns platform architecture and engineering, having built infrastructure at Palo Alto Networks, Dell and HPE.
The engineering weighting is deliberate and is the clearest signal of what the company believes. A three-layer model where the platform is the durable asset can only be built by a team that is mostly building it.
Working photograph rather than a lined-up group shot. Natural light, screens visible, no stock treatment. A second frame of the founders in conversation is worth capturing at the same session.
Whoever holds the record of agentic work holds the category.
Model capability is converging and will keep converging. The agents that can be built on any competent stack next year will be broadly as capable as each other. What will not converge is the record: the accumulated, tenant-specific account of what an organisation's agents were asked to do, what they did, what was approved, what was corrected, and what they learned from the correction.
That record is the switching cost, and it is the only durable one in this category. It cannot be exported as a prompt library or reconstructed from a model provider. It grows with every approval and every correction, and it is what makes an agent estate in year two materially better than the same estate in year one.
Nagent's position is that the record must be a first-class product surface rather than a log: readable as files, replayable turn by turn, scored into trust that moves in both directions, and legible to the person accountable for the outcome. Everything in the platform layer exists to produce it. The application layer exists to make organisations willing to start producing it. The operation layer exists to make sure they get far enough in to see it compound.
Capability makes the first sale. The record makes the second one, and every one after that.
What is being built next
Agent-team hierarchy with team leads across departments, so a chief of staff agent coordinates a real reporting structure rather than a flat pool.
Tenant-scoped Live Ops and installed-agent views, so a client sees their own estate rather than a filtered slice of a shared surface.
Multiplayer agent chat with instruction capture and approvals as the default working surface, replacing the console as the place work starts.
Agents with their own email addresses, and human document upload directly into knowledge and memory, so the boundary between a colleague and an agent narrows on the practical dimensions rather than the cosmetic ones.
Meeting presence and voice, so agents are in the room where decisions are actually made rather than reading the notes afterwards.
Deeper knowledge retrieval, user-controlled model selection across providers, and organisation-level and team-level knowledge access controls.
The commercial shape
Approximately 250,000 US dollars raised to date, with a pre-seed round in progress on a simple agreement at an 8 million dollar valuation cap and a 25 % discount, targeting 1.5 million dollars with 500,000 committed. Use of funds is weighted 40 % to go-to-market, 20 % to technology and infrastructure, 20 to 25 % to team expansion and 15 % to operations. The six-month milestone is 1 million dollars of annual recurring revenue.
The pricing model runs from self-serve entry points for a single agent, through an agentic system licence, to enterprise engagements with forward deployed engineering and managed operations priced against outcomes. The platform licence includes the agentic customer record and the search and competitive data subscriptions, so a client's cost to run a department is one line rather than five.
One take, no cuts, no slides. The argument is strongest when it sounds like a position held rather than a script read. Shoot in the office with the team visible behind, not against a plain wall.
