AI agents you can answer for.
Any consultancy can get an agent working in a demo. The questions that stall deployments are security questions wearing a business hat: what the agent can reach, what it does when it fails, and whether you can prove either to a customer, a prime, an insurer or a regulator. JEGASEC answers those three first and builds second. That order is the whole method.
This is a professional-services capability, delivered on the same model as Security Engineering — fixed scope, fixed fee, published price — and intended to help fund continued product development.
Three questions before the build.
Every engagement starts here, whether it ends in a written determination or a running agent. An organisation that cannot answer all three does not have an AI problem — it has an access-control problem that an agent is about to make considerably larger.
What can it reach?
An agent inherits the permissions of the identity it is given, and most are given a staff account because that was the quickest way to make the demo work. Every JEGASEC build gets a dedicated service identity with an explicit, documented tool scope, provisioned by you rather than by us.
What happens when it fails?
Not accuracy — behaviour. The malformed record, the instruction hidden in an inbound customer email, the API returning stale data. Failure modes are written down before anything is built, and the kill switch is a deliverable walked through at handover, not a feature request for later.
Who can prove it?
Insurers, primes, procurement teams and boards are all asking, and a screenshot of the agent working is not an answer. Engagements produce written artefacts built to be handed over, mapped to the National AI Centre's six essential practices for AI adoption.
Five engagements.
Fees are fixed and stated in full, exclusive of GST, payable 50% on commencement and 50% on delivery. The Feasibility Note is a paid qualifier rather than a sales call: it prices a build honestly, and it will tell you when there isn't one worth doing.
Agent Feasibility Note — a written go or no-go across up to five candidate workflows, including the two we would not automate and why.
Agent Sprint — one workflow mapped and instrumented, with one agent running in production against it, scoped and documented.
Agent Deployment — up to three agents across a connected process, integrated to the systems already in use, with an evaluation harness you keep.
Assured Agent Architecture — a written determination, no system access, for organisations that must hand something to a prime, a board or an assessor.
Agent Operations — behaviour monitoring, evaluation regression, tool-scope review and a written quarterly review. $6,500 per month to eight agents.
One workflow, one agent, in production
For small businesses where a single high-volume workflow is consuming staff hours that should be going somewhere else — quoting, intake triage, reconciliation, document preparation, first-line response. The engagement maps that workflow as it is actually performed, not as the process document describes it, then builds one agent against it.
- The workflow, described end to end, with volumes
- Twenty to fifty representative records or transactions
- Read access details for the systems involved
- A named owner who will run the agent after handover
- The cases where a wrong answer would actually cost something
- One agent running in production against the workflow
- A dedicated service identity with an explicit tool scope
- Written kill-switch and escalation procedure
- Staff runbook: what it does, what it will not do
- Two revision rounds, then 30 days of adjustment
A written determination, before anything is deployed
For regulated and defence-adjacent organisations where the agent cannot be built until someone has written down what it will be able to do. Delivered on the same document-based model as JEGASEC's Security Engineering practice: no system access, no configuration, no testing of live environments. The analysis is performed on documentary evidence you supply, and that boundary is what makes a fixed fee and a clean liability position possible for everyone involved.
- The intended agent scope and the systems it would touch
- Data classification and residency requirements
- Identity and access management arrangements
- Existing security policy suite and risk framework
- The questionnaire, gate or clause driving the deadline
- Agent access and data-flow map across the deployment
- Threat model against published agentic AI risk categories
- Control set mapped to the six essential practices, gaps named
- Residency and sovereignty position, evidenced
- Procurement-ready attestation and questionnaire responses
The threat model works from the joint guidance on agentic AI published by the Australian Signals Directorate's Australian Cyber Security Centre with allied agencies, which identifies prompt injection, an attack surface expanded by tools and memory, cascading failure across connected agents, excessive agent privilege, and reduced accountability as the categories that matter. The control set is mapped to the National AI Centre's Guidance for AI Adoption.
How an engagement runs.
Document-based rather than meeting-based. Your time goes into evidence and into the handover, not into a standing calendar slot.
Scope confirmation
You receive the engagement scope, the input manifest and available start dates in writing. What is in, what is out, what the deliverable will contain, and the fee. Nothing starts before it is agreed in writing.
Written · 2 business daysEvidence and access
You upload process documentation, sample records and system inventories to a per-engagement encrypted workspace before the agreed freeze date. For build engagements, the scoped service identity is provisioned by you, not by us.
Client-side · Deadline-drivenAnalysis and build
Ten to thirty business days depending on the engagement. You may submit up to three consolidated written query bundles during this window, answered within two business days. No standing check-ins.
10 to 30 business daysHandover
Written deliverables plus two rounds of consolidated comments within the agreed scope. For build engagements, a runbook, a kill-switch procedure and an administrator walkthrough. A recorded briefing where a walkthrough is useful.
Deliverable · Two revision roundsBefore you enquire.
These engagements suit a specific kind of client and are a poor fit for others. Rather than discover that on a call neither of us wanted, here is the filter in full.
A good fit if
- You have a workflow with real volume and a clear right answer
- Your data sits in systems that expose an API or an export
- Someone identifiable will own the agent after handover
- You need to show a customer, prime or board how it is controlled
- You would rather read a determination than sit through a workshop
A poor fit if
- You want an agent that decides about a person — hiring, credit, eligibility, tenancy or discipline
- You want unattended write access to payments, payroll or the ledger
- You are looking for a managed service provider or an ongoing helpdesk
- The requirement is exploratory and no workflow has been named
- You need regular check-ins as part of the delivery model
The first two items in the second column are permanent exclusions rather than preferences. If the rest of that column describes you, say so in your enquiry and we will point you to a firm better suited to it.
JEGASEC holds no ISO 27001, IRAP, DISP, SOC 2 or Essential Eight maturity certification, and does not represent authority to accredit or assess against any standard or framework. Where a deliverable maps controls to the National AI Centre's Guidance for AI Adoption or to published agentic AI security guidance, it does so as independent technical analysis. No determination in a JEGASEC deliverable binds any regulator, assessor or delegate.
JEGASEC is not an Australian legal practice and does not provide legal services, legal advice or legal opinions. Where a deliverable addresses privacy, consumer protection, anti-discrimination or sector-specific obligations, it does so as technical and structural analysis of the requirements those instruments impose on systems, evidence and organisational design. Obtain independent advice from an admitted legal practitioner before acting on any matter bearing on your legal position.
Retainer engagements cover the behaviour of agents JEGASEC has built or assessed. They are not a managed security service and do not cover your identity platform, endpoints, network or third-party software. Fees are in Australian dollars and exclude GST. Do not send classified, protected or operationally sensitive material to JEGASEC without a separate written agreement and appropriate handling arrangements in place.