Skip to contentThe Observability LayerSearch

Enterprise handbook · Section 16 of 30

14. Worked enterprise applications

These are synthetic design examples. They contain no private customer data, measured enterprise outcomes, or estimates of actual deployment prevalence.

14.1 Financial research and advisor support

Mandate: Retrieve and summarize approved financial evidence for a human advisor. The agent cannot execute trades, grant suitability approval, or provide unreviewed personalized recommendations outside its authorized role.

Design: Restrict sources and data classes; record retrieval/effective dates; use deterministic calculation tools for financial arithmetic; distinguish observations, assumptions, scenarios, and advice. Require citations that support the exact entity, period, currency, and claim. Where evidence is unavailable or conflicting, produce an explicit unresolved result.

Evaluation: Include revised filings, stale rates, similarly named entities, currency conversion dates, inconsistent units, unsupported comparative claims, and malicious source content. Verify both answer correctness and evidence traceability. The reference value of FinFIRST is its workflow-oriented evaluation approach, not automatic suitability assurance. [S22]

Acceptance artifacts: Source register, versioned calculation recipe, adjudicated answer rubric, citation checks, disclosure handling, and advisor review outcomes. Enable drafting autonomy only within that approved evidence and tool perimeter.

14.2 Back-office payment or reconciliation workflow

Mandate: Reconcile records and propose bounded corrective actions. Payment initiation, beneficiary changes, and account modifications receive their defined consequence-specific controls.

Design: Keep the agent separate from the resource authorization service. Bind approvals to normalized payloads and expiry; enforce shared budgets across children; use idempotency keys; independently query committed state. A retry after a timeout first resolves whether a transaction already occurred.

Evaluation: Change the beneficiary after approval, reuse an old approval, distribute spend across children, inject a delayed instruction through a document, delay a monitor, and revoke credentials mid-run. Exercise partial commits and recovery without relying on the agent's completion statement.

Acceptance artifacts: Denied/accepted call records, transaction receipts, state reconciliation, duplicate-prevention evidence, global exposure ledger, and a halt drill that includes queued work. Increase autonomy by permitted action class rather than by a single workflow-wide trust score.

14.3 Customer service, complaints, and covered decisions

Mandate: Answer routine questions and prepare evidence for a human decision where policy or applicable law requires review. Account closure, credit decisions, restricted data disclosure, and customer redress follow their specific rules.

Design: Separate explanation from decision authority. Preserve the actual factual/policy basis, give reviewers correction authority, and make reopening accessible. Scope vulnerable-customer and accessibility safeguards to the process and applicable obligation.

Evaluation: Include thin-file customers, incomplete records, conflicting documents, language differences, repeated document requests, an unjustified refusal, a wrong adverse-action reason, and a correction that changes the decision basis. Compare stage-level outcomes with aligned eligible populations.

Acceptance artifacts: Decision-stage inventory, approved policy boundaries, actual reason record, reviewer competence evidence, notices, reopening results, and a remediation lookback. An agent-assisted human decision still requires evidence that the human review changed outcomes when it should have.

14.4 A payment example from request to reconciliation

This example is synthetic. Its amount, limits, and sequence illustrate a control design; they are not a recommended financial threshold or an executed transaction. The workflow is permitted to prepare reconciliations and execute an approved payment of 1,250 currency units to Supplier-A. Beneficiary changes are excluded from the mandate.

Evidence table: Step, Agent or operator activity, Independent control, Evidence and state
StepAgent or operator activityIndependent controlEvidence and state
RequestAn authorized operator requests reconciliation of Invoice-47.Identity and mandate permit scoped invoice reads and draft preparation.Workflow W-47; approved configuration D-47; read-only preparation state.
RetrieveAgent reads invoice and purchase-order data.Source and tenant checks apply; document instructions have no authority.Source versions, purpose, and provenance.
ProposeAgent proposes 1,250 units to existing Supplier-A.Normalize the operation and compare beneficiary, amount, currency, account, and tool against policy.Proposed action A-47 and its digest.
ReviewReviewer examines invoice match and proposed effect.Reviewer can reject or correct; approval binds A-47, a specific beneficiary, and expiry.Reviewer identity, rationale, scope, and approval digest.
CommitExecution gateway submits the approved payload.Current policy, grant, approval, and global budget are rechecked; idempotency key K-47 is required.Allowed decision, request digest, resource receipt.
UncertaintyResource accepts the operation but the client times out.Dependent work and retry remain held until resource status is independently queried.Pending reconciliation; no asserted success and no duplicate submission.
VerifyResource query confirms exactly one expected payment.Independent postcondition verifies beneficiary, amount, currency, and transaction status.Matched resource state and verified completion.
CloseWorkflow reports the verified outcome.Evidence reconciliation checks the authority-to-effect chain.Closed task, complete evidence, and any retained limitation.

A useful negative variant changes the beneficiary after approval. The expected outcome is rejection before commit, with the changed action and reason recorded. Another variant splits spending across two children; the shared budget must still apply. The oracle for either test is resource state and authorization evidence, rather than the agent's claim that it behaved safely.

14.5 A research answer with an evidence contract

For a synthetic research task asking whether an issuer's margin improved, the agent must identify the issuer, reporting periods, currency, unit, source versions, and margin definition. If operating profit is 18 and revenue 120 in one period, the margin is 15%. If the prior comparable margin is 13%, the change is 2 percentage points. These inputs are invented for teaching and are not issuer data.

The acceptance record should preserve the source-to-input mapping, deterministic calculation, comparable-period check, answer wording, and independent rubric. If the sources describe different consolidation boundaries or a revised period, the answer should state the unresolved comparison. A link to a document does not establish that the document supports the exact claim.

14.6 A customer correction that changes the decision

In a synthetic service workflow, an incomplete record leads the agent to recommend rejecting a request. The reviewer must be able to obtain the missing evidence, correct the record, and change the recommendation. The customer-facing explanation should reflect the basis actually used, with applicable notice and review rights.

The test oracle checks the stage records and corrected outcome. It also checks whether derived summaries, open tasks, and later agents retain the earlier rejection. An accessible reopening channel is effective only if corrected evidence can reach the decision and any affected downstream use.