A practical blueprint for your agentic mandate

A usable operating model for AI leaders, plus shipped work on facts and claims, governance, and a stronger security posture.

Issue 6·Tony Truong·July 31, 2026

If you inherited an agentic mandate, start here: You Have an Agentic Mandate. Now What?. It is a practical operating model you can take into the next planning conversation, not a product tour.

Use this blueprint with your leadership team

Most programmes stall the same way. A few agents get stood up. A knowledge base gets wired. The demo looks good. Week three brings cold starts, conflicting answers, and forgotten corrections.

The post walks a two-part sequence:

  1. Seed an experience layer from the systems you already run (CRM, ERP, knowledge bases, ITSM, data platforms), so agents do not start empty.
  2. Design the agent architecture on top: who owns which workflow, which tools they may touch, which lessons apply, and where the human gate sits.

The experience-layer diagram from the post is the map to share in the room:

Diagram of the experience layer: enterprise sources feed customer extractors into Hyperstruck entry surfaces. Lessons sit at the centre with branches for claims and facts, instances and evidence, curation, and org-wide promotion, then pass through a govern process. A resolve, work, observe, reinforce loop closes back into Lessons, with security and governance called across the flow.

It also includes a starting sequence you can run without boiling the ocean: pick one costly workflow, map the source systems, seed lessons, govern before you trust the library, define ownership and human gates, then close the loop on day one.

Read and share: You Have an Agentic Mandate. Now What?

Facts and claims: keep the record useful

This cycle tightened how agents use what the business already knows.

Corrected facts pull confidence with them. Example: finance corrects "Customer X is on net-30" to net-60. Lessons that leaned on the old term lose that support, so collections does not keep chasing on the wrong clock.

Trusted facts skip unnecessary work. Example: the record already shows an invoice was paid by bank transfer. Agents can skip the chase step instead of re-pulling the same CRM and ERP checks. Required approvals and hard stops still apply. A useful fact does not turn those off.

Sensitive prompts are scrubbed from durable memory. Example: someone pastes an account number or customer email into a run. The durable record keeps a scrubbed cue for the work, not the raw prompt, so private detail is less likely to stick around in what agents remember.

Governance and security: control what compounds

Compounding intelligence only helps if people can steer it and trust the platform underneath.

Claims curation UI. Reviewers can promote, release, or adopt what agents have come to believe. Example: a collections lead promotes "check the bank statement before chasing" so other finance agents start with that lesson, instead of waiting for bad guidance to age out.

Org spaces, members, and roles. Admins can manage members, roles, and spaces from Settings. Example: finance lessons stay in the finance space and do not show up in legal's agents.

Multi-person approvals. Hosted customers can require multiple distinct approvers before an agent proceeds. Example: a wire transfer or production change needs two different people to sign off. One shared credential or one rushed click is not enough. Approval decisions land once, even under load.

Stronger security posture. Hosted got hardening across auth, rate limits, CSRF on logout, SSRF checks on credential URLs, tighter payload bounds, safer learning-transfer handling, and clearer public health responses. Built for scrutiny, not just demos.

Automatic model selection for learning. Hosted picks models for each part of the learning system automatically. We have benchmarked multiple models for those components so customers do not have to. Better quality where it matters, without a dial for every team to get wrong.

More reading from this cycle