We design, build, and operate governed agentic systems: tool-using AI that acts inside defined contracts, approval gates, and telemetry. For South African enterprises and larger SMEs that are done with pilots that go nowhere.
Assessment output: a control gap map, a scoped memo, and one technical walkthrough. You keep the artifacts whether or not we build together. No logo wall, no invented metrics.
of enterprise software applications are projected to include agentic AI by 2028, up from under 1% in 2024.
Source: Gartner, December 2024of AI-related data breaches are projected to involve shadow AI by 2027, up from 7% in 2024.
Source: Gartner, 2025OWASP maintains a Top 10 of LLM application risks. The failures cluster around agency, permissions, and missing evaluations, not model quality.
Source: OWASP LLM Top 10Teams feel pressure to adopt AI, so they adopt it. Tools ship features, staff provision them, and shadow usage grows. The result is scattered experiments, duplicated spend, and data moving through tools nobody approved, with no single owner for systems that now touch operations.
Business owners ask for outcomes. The project stops at a notebook or a chatbot with no path to production. The budget line is spent; the workflow is unchanged.
Staff use consumer tools for work documents. The CISO inherits exposure without a control, and nobody can say what left the organisation.
Platform agents run with broad permissions and no approval step. The CIO discovers the blast radius after an incident, not before.
The CFO cannot see scope, controls, or exit criteria. Without artifacts the purchase cannot be defended, so it stalls.
Personal information moves between tools with no data map, no stated purpose, and no retention plan. Compliance and legal find out last.
When an agent misbehaves, issues bounce between the vendor and the team. There is no named owner, no runbook, no review cadence.
Who is accountable when an agent acts?
One named owner per system, an escalation path, and a review cadence. Control is an operating feature, not a slide.
Does this fit our architecture?
Tool contracts describe any system we integrate. No platform swap, no lock-in. Lifecycle ownership is yours at handover.
What can the agent touch, and can we see it?
Dedicated identity, least privilege, and a full run trace for every action. Blast radius is designed, not discovered.
Where does our data go, and who decides?
Data mapping, purpose limitation, retention, and an audit trail. POPIA-aware by design, with an exception register.
What exactly are we buying?
Phased scope, named artifacts per phase, and go/no-go gates you control. Spend is tied to deliverables you keep.
A governed agentic system has three fixed components. Everything else is configuration.
Every tool an agent can touch is declared: name, purpose, allowed operations, data boundaries, rate limits, and the owner of the contract. The agent cannot call what is not in the contract.
Actions above a defined risk line pause for a named approver. The gate is part of the workflow, not an afterthought. Denials are logged as exceptions, not deleted.
Every run is traced end to end. An eval suite guards each change. You can see what the agent did, why it did it, and whether the change improved anything.
Every system also gets a named owner, a review cadence, and a retirement path. We do not build ChatGPT reskins, open-ended research projects, or agents that act on production data without a gate. If a workflow should not be automated, we say so in the assessment memo.
Five failure modes show up repeatedly in production. Each has a known signature and a known control. We build the control in from the first commit.
The agent can act anywhere. You learn about actions after the fact, from a customer or an auditor.
ControlScoped tool contracts and risk-ranked approval gates.
The agent inherits the operator's identity, or a service account with everything. One credential now covers every system.
ControlDedicated agent identity with least privilege and per-tool scopes.
Every model update or prompt change is a blind release. Behaviour drifts between versions and no test catches it.
ControlAn eval suite in the delivery pipeline with a regression gate.
Nothing can be reconstructed after the fact. Incidents are investigated from memory and screenshots.
ControlRun traces, structured logs, and an audit trail on every action.
Issues bounce between vendor and team. Nobody owns the system, so nobody is accountable for its behaviour.
ControlA named system owner, review cadence, and retirement path.
None of these modes require heroic engineering to avoid. Each has a known control, applied at design time. That discipline is what MazeTech sells: not intelligence, but boundaries.
Five layers, one rule: nothing executes without an owner, a contract, and a trace. Human oversight runs the length of the stack.
Policy, audit, and compliance run alongside the stack. High-impact decisions always involve a person. The stack is not a substitute for judgement; it is the structure that makes judgement accountable.
An agent never holds broader access than its workflow requires.
An action above the risk line never executes without an approval decision.
A change never ships without passing the eval suite.
A run never happens without a trace, and a trace never expires without a retention rule.
These are reference patterns, not claims about delivered results. Each one ships with contracts, gates, telemetry, and named artifacts. We do not publish client names or metrics without their consent.
Invoice intake, reconciliation support, and variance flags. The agent prepares; a person disposes.
Structured response drafting, case triage, and SLA monitoring. Drafts are reviewed before any customer-facing send.
RFQ comparison, contract clause checks against policy, and vendor data assembly. Commitments stay human.
Evidence collection, control testing, and report assembly. The agent gathers; the accountable person certifies.
Change request triage, runbook drafting, and incident timeline assembly. Infrastructure changes keep the change process.
Security and privacy controls are specified before the first line of agent code. Compliance teams review the design, not the aftermath.
Data mapping first
We map what the agent touches, where that data moves, and why, before any build. Purpose and minimality are POPIA obligations; they are also engineering inputs.
Purpose limitation in the contract
Tools receive data scopes, not blanket access. The contract states what the agent may read, transform, and produce, and what it may never do.
Retention and deletion
Logs, traces, and collected data follow a declared retention schedule with a deletion path. Nothing is kept because it is convenient.
Access and review
Named approvers for high-impact decisions. Access reviews run on a schedule, and scope creep is a reportable event.
Vendor processing
Any third-party model or tool is assessed as a processor: where data goes, what is retained, and what the contract says.
Exception register
Anything that deviates from the declared design is recorded, dated, and reviewed. Exceptions are managed, not hidden.
No open-ended engagements. Every phase has fixed scope, named deliverables, and an explicit go/no-go decision before the next phase starts.
Procurement needs scope; operators need ownership; compliance needs a trail. The phase model gives all three. Spend is tied to deliverables you keep, and the riskiest phase, the pilot, is deliberately the smallest and most controlled one.
Every engagement produces inspectable artifacts. If a claim cannot be backed by a document you can read, we do not make it.
Every tool, its scopes, boundaries, and owner, in writing.
Risk lines, approvers, and decision records, versioned.
Test cases, pass criteria, and results per release.
End-to-end records of what each agent did and why.
Why each control exists, dated and attributed.
Every deviation, its date, and its review.
The control gap map you keep before any build.
Operations, escalation, and retirement in one document.
We build against these references and can show where each control maps. Alignment is documented in the artifacts. Certification is only claimed with evidence.
We do not publish invented metrics, client logos, or case studies. If you want proof, we give you artifacts you can inspect: specifications, configurations, traces, and evaluation reports. Before you buy, we walk you through the assessment memo, the control map, a live run trace, and the eval suite. You see the evidence, then you decide.
If you are defending this purchase to a board, a risk committee, or a CFO, these are the questions you will hear.
Most pilots fail at governance and scope, not model quality. The assessment starts from your existing attempts and reviews their artifacts. If the blocker was data or workflow, we say so and scope accordingly.
The assessment tells you honestly. Sometimes the correct answer is to fix the data or the workflow first, and we will write that in the memo. The memo is yours whether or not we build together.
The deliverable of phase one is a memo with a control gap map you can keep and circulate. We are paid for artifacts, and you keep every one of them. There is nothing to sign before you have seen them.
Data map, purpose limitation, retention schedule, processor review, and an audit trail. POPIA-aware by design, documented before build. Your data stays inside the boundaries the contract states.
That is the point of a controlled pilot: small scope, gated actions, and criteria you approved in advance. If the criteria are not met, you have an exception record and a clean exit, not a sunk project.
Tool contracts describe any system, from an ERP to a shared spreadsheet. The contracts are the integration. We do not require a platform swap, and the assessment memo identifies integration points before any build.
Each phase has fixed scope and named artifacts. Spend is tied to deliverables, and every phase ends in a go/no-go gate that you control. The assessment memo defines the scope of the pilot in writing before it starts.
You do. Lifecycle ownership is built into the engagement: a named owner, a runbook, a review cadence, and an operate phase that continues until your team is ready to run it alone.
One questionnaire, one control gap map, one walkthrough. You keep the artifacts whether or not we build together.
Subject line: Agentic Systems Assessment. Include the workflow you have in mind and the buyers who will review the decision.
Send the brief →