A trained team of agents. Controlled, documented, evidenced, skilled.
You choose the jobs and the frameworks to comply with. We deploy the team. A named person in your business owns every workflow.
Configured, not staffed. Three things are set before any agent does any work.
The jobs. What outcome is required, what “done” looks like, and the constraints. That is what the team is assigned to, and what cost and value are measured against.
The rules. Every framework that applies, configured as enforceable rules the agents work within, not a policy document they are asked to respect. UK GDPR and the DUAA safeguards for everyone; Consumer Duty, SS1/23, the SRA notice, CQC and MHRA boundaries, FRC and ICO recruitment rules where they apply.
The oversight map. A named person with authority over every workflow, agreed before it runs. The direct answer to the question every regulator is now asking.
You are not asked to trust agents. You are asked to trust a configuration you can inspect and a person you can name.
Five names on every workflow.
Accountability and ownership are written down before the first request runs, so a professional whose regulator holds them personally responsible can use the team without carrying the risk alone.
| Role | Who | What they do |
|---|---|---|
| Accountable owner | A named executive in your business — SMF, COLP, clinical safety officer or DPO where relevant | Owns the outcome and the risk. Signs off the configuration. The name given to the regulator. |
| Workflow supervisor | A GenWA human manager | Runs the team day to day. Reviews escalations. Approves configuration changes. Reports cost and quality. |
| Reviewer | Your subject-matter expert | Approves outputs at the checkpoints the rules require. Meaningful human involvement, in the ICO’s sense. |
| Agent | A GenWA agent | Does the job inside its scope. Logs every action and input. |
| Assurance | GenWA’s audit function | Checks logs, approvals and outputs against the rules. Produces the evidence pack. |
This is the operating model the ICO (“a standalone monitoring system to monitor logs, interpret them, and intervene”), the NCSC (scoped credentials, dedicated identities, logging, human oversight, kill-switch) and the EU AI Act (effective oversight by natural persons, with the ability to stop) each describe.
What agents does my business need?
Pick your sector for a suggested bundle, or browse the catalogue. Each card says the benefit, the job, and how effective it is.
Contact-centre adviser assist
Faster, more consistent calls, every one of them monitored.
- Job
- Listens to live calls on Amazon Connect, surfaces the next best answer and drafts the wrap-up note. 100% of calls monitored, not a sample.
- Effectiveness
- 100% of calls monitored, not a 5–10% sample
KYC and onboarding checks
Cases prepared for decision in minutes, not days.
- Job
- Reads identity and address documents, checks them against your rules and third-party sources, and prepares the case for a decision.
- Effectiveness
- Every check, source and reason on file
Collections communications
Compliant letters at volume, signed off where it matters.
- Job
- Drafts letters, emails and SMS from account data, then runs a compliance pass for tone, disclosures and vulnerability.
- Effectiveness
- 100% pass a compliance check before sending
Complaints triage
Acknowledged and routed inside the regulatory deadline.
- Job
- Reads inbound complaints, classifies them, drafts the acknowledgement and routes each to the right handler with the file assembled.
- Effectiveness
- A timeline per complaint, ready for the regulator
Invoice processing
Matched, flagged and ready for the payment run.
- Job
- Extracts invoice data, matches it to purchase orders, flags exceptions and prepares the payment run.
- Effectiveness
- Exceptions documented with the source
Recruitment screening support
Consistent summaries; the decision stays human.
- Job
- Summarises applications against the role description and prepares interview questions.
- Effectiveness
- No ranking, no rejection by AI
Compliance monitoring
Regulatory change mapped to your controls as it happens.
- Job
- Reads new regulation, guidance and internal changes, maps them to your controls and drafts the gap note.
- Effectiveness
- Gap notes with sources, through Change Control
Growth operations
Campaigns and outbound at scale with a brand veto.
- Job
- Plans and drafts campaigns, outbound and content; reports plan against actual.
- Effectiveness
- Every piece checked and approved before it leaves
Eight jobs the team does today.
Contact-centre adviser assist
- Does
- Listens to live calls on Amazon Connect, surfaces the next best answer and drafts the wrap-up note. 100% of calls monitored, not a sample.
- Never
- Cannot speak to the customer. Cannot take a payment. Scripts and disclosures enforced by rule.
- Owner
- Head of Customer Service
KYC and onboarding checks
- Does
- Reads identity and address documents, checks them against your rules and third-party sources, and prepares the case for a decision.
- Never
- Never makes the decision. Flags, ranks and explains; a named person approves or declines.
- Owner
- Head of Onboarding
Collections communications
- Does
- Drafts letters, emails and SMS from account data, then runs a compliance pass for tone, disclosures and vulnerability.
- Never
- Category-based sign-off. Nothing goes to a customer without approval where your rules require it.
- Owner
- Head of Collections
Complaints triage
- Does
- Reads inbound complaints, classifies them, drafts the acknowledgement and routes each to the right handler with the file assembled.
- Never
- Cannot close a complaint or offer redress.
- Owner
- Head of Complaints
Invoice processing
- Does
- Extracts invoice data, matches it to purchase orders, flags exceptions and prepares the payment run.
- Never
- Cannot approve or pay. Budget and duplicate rules enforced.
- Owner
- Financial Controller
Recruitment screening support
- Does
- Summarises applications against the role description and prepares interview questions.
- Never
- Does not rank or reject. Hiring decisions are not permitted for AI under your model policy.
- Owner
- HR Director
Compliance monitoring
- Does
- Reads new regulation, guidance and internal changes, maps them to your controls and drafts the gap note.
- Never
- Advisory only. Every change goes through Change Control.
- Owner
- Head of Compliance
Growth operations
- Does
- Plans and drafts campaigns, outbound and content; reports plan against actual.
- Never
- Brand and compliance veto on every piece. A person approves every send.
- Owner
- Marketing Director
The regulations, roles and skills behind the team.
Each agent is tested in our sandbox against the rules of the job before it reaches you, and retested when a model or a rule changes.
- UK GDPR and DUAA
- FCA Consumer Duty
- CONC and DISP
- SM&CR accountability
- Money Laundering Regulations
- ICO recruitment guidance
- CQC expectations
- SRA Standards
- PCI DSS
- ISO/IEC 42001
- Collections adviser
- KYC analyst
- Complaints handler
- Accounts payable clerk
- Contact-centre adviser assist
- Recruitment coordinator
- Compliance analyst
- Marketing executive
- Document extraction and matching
- Drafting to a house tone
- Classification and routing
- Reconciliation and exception handling
- Vulnerability and disclosure checks
- Escalation to a named owner
- Evidence logging
- Plain-English summarising
New agents every quarter. A dedicated one if you need it.
We add agents and train new skills continually. If you have a specific job to be done inside a controlled framework, we build, test and control a dedicated agent for it: specification sheet, sandbox tests, named owner, Change Control.
The rules of your industry, built in as controls.
Every rule set is mapped to controls the Gateway enforces and the evidence pack reports. Your policy adds to it; it never starts from a blank page.
- UK GDPR and the Data Protection Act 2018
- Data (Use and Access) Act 2025
- ICO guidance on agentic AI and automated decisions
- CMA guidance on AI and consumers
- PECR (marketing and cookies)
- Equality Act 2010
- Employment law and ACAS guidance
- Consumer Rights Act 2015
- Companies Act reporting duties
- Bribery Act 2010 and Modern Slavery Act
- Cyber Essentials and NCSC guidance
- ISO/IEC 27001 and 42001
- PCI DSS (where cards are taken)
- FCA Consumer Duty
- CONC, DISP and SM&CR
- PRA SS1/23 model risk (AI and vendor models)
- Money Laundering Regulations 2017
- CQC AI expectations
- NHS DSPT and Caldicott principles
- MHRA ambient voice and software guidance
- SRA Standards and Regulations and the AI warning notice
- FRC guidance on AI in audit
- ICAEW, ACCA and CIOT guidance on AI
- Client confidentiality and privilege
- Ofcom (online safety, communications)
- Ofgem (energy)
- ASA CAP Code (advertising)
Control sets are mapped to published rules and guidance; they support compliance, they do not constitute legal advice. Coverage is extended each quarter. [Coverage to be confirmed by John.]
The value register: what each agent returned.
Issues detected · needs attention first
| Issue | Rule | Severity | Owner | Status |
|---|---|---|---|---|
| Payroll file uploaded to an external AI tool | R-15 | High | HR Director | Blocked · reviewed |
| 31 personal AI accounts found in Sales | R-02 | High | Head of Sales | Migrating · 27 done |
| Customer data in a prompt without redaction | R-01 | High | Ops lead | Redacted · 0 left |
| Premium model used for internal drafts · 412 requests | R-07 | Medium | Engineering lead | Rerouted |
| CRM "AI assist" running without a DPIA | Policy | Medium | Head of Sales | DPIA in progress |
| Agent attempted an external email | R-12 | Low | S. Reid | Held · approved |
| Job | Owner | RAG | Effort | Cost to date | Forecast | Actual | Variance | Return / yr | Status |
|---|---|---|---|---|---|---|---|---|---|
| Migrate personal accounts to managed | IT Director | 12 d | £4,200 | £6,000 · 20 d | £4,200 · 12 d | −£1,800 · −8 d | risk | Done | |
| Route everyday tasks to standard tier | FD | 3 d | £900 | £1,200 · 4 d | £900 · 3 d | −£300 · −1 d | £58,400 | Done | |
| Payroll upload block (R-15) | HR Director | 1 d | £300 | £300 · 1 d | £300 · 1 d | 0 | risk | Done | |
| Collections letters via Comms agent | Head of Collections | 18 d | £11,600 | £14,000 · 25 d | — | on track | £96,000 | In progress | |
| KYC document checks | Head of Onboarding | 9 d | £5,100 | £9,000 · 15 d | — | on track | £61,000 | In progress | |
| Contact-centre adviser assist | Head of CS | 26 d | £19,800 | £16,000 · 20 d | — | +£3,800 · +6 d | £142,000 | At risk · vendor delay |
Effort, cost and return are recorded against each job as it happens. Done means the job is solved in production with its owner’s sign-off, not that a licence was bought.
Before you book a demo.
Why is this cost-effective as well as compliant?
You buy an outcome at a metered, visible cost rather than headcount or day rates, on governed models rather than premium-by-default. Compliance is a property of the configuration, not of individual diligence: rules are enforced at the point of action, every step is logged, and a person with authority is attached to every workflow.
Who is accountable when an agent gets it wrong?
A named person in your business owns every workflow, and it says so in the register. The agent's permitted actions are rules; anything outside them is held for that person.
Can an agent send anything externally on its own?
Not unless a rule permits it for that category. Everything else is held for a named human, with a time limit and a record.
How were the agents trained, and can we see it?
Each agent is built through an auditable process: every design decision, test and sign-off is recorded, and the agent's specification sheet is part of your evidence pack.
What are they not allowed to do?
Credit, hiring and medical decisions are not permitted for AI under the default model policy. You can make that list longer; you cannot make it shorter without a signed change.
Find out where your AI stands. Then decide.
Under a minute, an upload, or a visit. Something for the board either way.