Governed AI Agents

Give AI a clear task. Keep control.

Let an Agent analyse a dispute, assess fraud signals or review a document. Choose the information and tools it can use, then let your process act on the result or ask a person to review it.

Agent Studio: Analyse a dispute activity, three allowed tools, and Fetch invoice configuration.
Tools authorized for one Agent activity
Activities

Give each AI task its own contract

An Agent can contain several business activities. The process invokes one precise activity from one Agent revision and maps that activity’s typed inputs.

This keeps prompts, model/provider choices and guardrails behind a business-facing contract. Process authors depend on the activity outcome rather than on a free-form chat surface.

Buyer
Transaction
Checkout context
Agent activity

Analyze transaction fraud

  • Rules & signals
  • AI model
  • Risk analysis

Output

risk_level
72%
recommendation
human_review
  • accept
  • reject
  • human_review
Illustrative Agent activity · Inputs, analysis and process routing
Governance
A clear task. Approved tools. Controlled data access.

Each agent operates within a defined scope: a specific business task, explicitly approved tools and a policy governing which data it can access. Sensitive values are pseudonymised where required, so the model receives only what it is authorised to see.

Implication

What this boundary changes in the design

You decide what agents can do — and what data they can see.

Tool permissions and data disclosure are governed separately. Authorising an action does not automatically grant access to the underlying sensitive data.

Continuity

Reuse working context only when the activity needs it

Agent Memory is a persistent working-context resource owned by an Agent definition and reusable across its revisions. Memory is optional: an Agent Task does not require a memory merely to run.

A process may use an Agent role when it needs continuity across several Agent Tasks, but the role does not choose which Agent or revision executes the work.

Control

Human review is a normal policy choice, not a failure mode

Processes can insert approval or review when confidence is insufficient, impact is high or an internal or regulatory rule requires human authority.

The model can contribute analysis or an explicitly authorised action; the process still materialises the actual control policy around that activity.

Governed AI Agents

See Ormuz in action, then start building.

Explore a real journey, then open the console to build your own processes.