Home / AI & Agentic Readiness / AI & Agent Operating Model

AI & Agent Operating Model Design

Design the authority before you grant it.

The control design an AI or agentic system needs ahead of go-live — accountable ownership, permitted actions, data boundaries, approval thresholds, escalation, and a shutdown that works.

Operating-model design, applied to agents.

  • 4 to 8 weeks
  • Per use case or portfolio
  • Independent
  • Evidence-ready

Agentic failure follows a predictable pattern.

Authority lands inside a process built to grant authority to people. Afterwards, nobody can explain what the system was permitted to do, or why.

The pattern repeats: ownership sits nowhere, permitted actions were never written down, the approval threshold was set by whoever configured it, the escalation path assumes a role that has since changed, and the rollback was never tested. Every one of these is an operating-model question.

So we start where value is created or lost — the decisions, the decision rights, and the handovers between them — and design the agent into that structure.

Where we start

We design the stop before the start.

Eighty-four per cent of Australian firms have already rolled back or shut down a customer-facing agent. Boards are asking what happens when an agent has to be pulled, and whether the reason stands up afterwards.

  • Intervention and shutdown — who can pause or stop the system, through what mechanism, and how quickly. Tested before go-live.
  • Rollback and recovery — the state the process returns to, the treatment of work in flight, and the person who reconciles it.
  • Incident response — what counts as an AI incident, who is told, in what timeframe, and what gets recorded.
  • The manual path — the process still runs without the agent. Where it cannot, the agent waits.
Detect Pause Roll back Reconcile Manual path Every step named, owned and exercised before go-live.

This mirrors the Commonwealth's agentic AI technical guidance, which names intervention and shutdown mechanisms as one of five domains agencies are expected to apply.

The control set

What we design

Eleven things, written down, owned, and specific enough for someone outside the room to test.

  • Accountable business owner — one named person for each use case.
  • Permitted and prohibited actions — the actions the system may take, and the boundaries it holds to.
  • Data-access boundaries — what it reads, what it writes, and what stays out of reach.
  • Financial and operational authority limits — the ceiling on what it can commit or change.
  • Human approval thresholds — where a person decides, expressed so the threshold can be audited.
  • Exception and escalation paths — the route when the system meets something outside its design.
  • Incident response — definition, notification, containment, record.
  • Performance and risk indicators — what is monitored, by whom, at what cadence, against what baseline.
  • Third-party responsibilities — vendor accountabilities, written into the contract.
  • Change and release governance — the process when the model, the prompt or the tool set changes underneath you.
  • Shutdown and recovery — designed first, tested before go-live.
Accountable owner · one named person AGENT · PERMITTED ACTIONS ONLY Intake Assess Approval threshold Authority limit Commit Shutdown & rollback Exception → escalation

Anchored to what you will be asked about

The design maps to the instrument that governs you, so the output doubles as evidence.

Government

The DTA agentic AI addendum

Published June 2026 as an addendum to the Australian Government AI technical standard, covering governance and controls, data and memory management, evaluation against defined outcomes, human oversight and real-time monitoring, and intervention and shutdown. Agencies are expected to apply it, and it is what an internal auditor or the ANAO will reach for.

Regulated enterprise

APRA's letter to industry, April 2026

Sets expectations across governance and board AI literacy, information security including prompt injection and manipulation of autonomous agents, lifecycle management and AI inventory, supply-chain visibility to fourth parties, and continuous assurance. APRA states plainly that assurance practice is falling behind.

Critical infrastructure

SOCI Enhanced CIRMP Rules

Core cyber risks now expressly include the deployment or hostile use of advanced, novel or emerging technology including AI, covering both your own deployment and AI used against you. The design feeds directly into the risk management program and the annual board-approved report.

Standards

ISO/IEC 42001 and NIST AI RMF

The design is expressed so it maps cleanly onto an AI management system and onto the NIST functions — the two frameworks Australian regulators name. Accredited bodies issue certification; we handle readiness and evidence design.

What you get

  • The agent operating model — the eleven controls above, designed, owned and documented per use case.
  • The redesigned process — human and agent work designed together, as one flow.
  • A control-to-obligation map — each control traced to the policy, standard or regulator expectation it satisfies.
  • The evidence specification — what your platforms must record for this design to be provable, expressed as requirements on systems you already own.
  • A tested shutdown — the intervention and rollback path, exercised before go-live.
  • The baseline — the measured starting point the benefit will be tracked against.

Retained afterwards through the Value Realisation Office, where the portfolio is reviewed monthly, new use cases are assessed, and the benefit is tracked to the ledger.

Start a conversation

Most engagements begin with the Agent-Ready X-ray, because the design works better from a measured process. Where you already hold that evidence, we can start here.