If you're considering an AI agent that will touch production systems, audit layer design is the first step, not the last. Before choosing a vendor or platform, verify they can log every agent decision, link it to a specific system action, and export structured logs to your organisational audit tools. Without this, you have no way to prove compliance to regulators or investigate incidents.
Intuit built an AI agent called EWOK Agent using Amazon Bedrock that enables on-call engineers to run production system failover using natural language requests. Every action passes through layers of predefined policy, approval mechanisms, and complete documentation. Every agent decision is traceable and auditable.
What they built and why it works
EWOK Agent handles disaster recovery scenarios—situations where production systems need to move between availability zones or data centres. Instead of running manual scripts or working through long checklists, an on-call engineer sends a natural language request, and the agent translates it into a sequence of actions.
The architectural innovation is in the audit layer. Every agent decision is documented, every action passes through predefined policy, and every system change can be traced back to the original request. This isn’t “AI doing whatever it wants”—it’s an agent operating within a strict framework built upfront.
Why this matters for regulated organisations in Israel
Banks, insurance companies, and financial organisations in Israel operate under information security and regulatory standards similar to those Intuit faces. They must prove to regulators that every production system change is documented, approved, and auditable.
This case proves you can build AI agents that perform sensitive operations on production systems, but only if you build them correctly from the start. It’s not a question of “whether to use AI” but “how to build the layers around it”—policy, approvals, documentation, and audit.
Organisations already running critical automation systems can look at this architecture as a test case. The question isn’t just “what does the agent do” but “how do I prove what it did”.
What to do this week
If you’re considering an AI agent for production systems, start from the end: design the audit layer before choosing a model or platform. Ask vendors how they log decisions, how they link them to actions, and how they export logs to your organisational audit tools.
If you’re already running critical automations, check whether you can investigate an incident: can you link every system change back to the request or event that triggered it? If the answer isn’t clear, now is the time to build that layer.
For organisations wanting to build AI systems under security and regulatory standards, custom AI systems require precise architectural planning from the start.
Frequently asked
Yes, but it requires specific architectural planning. You need to build an audit layer that logs every agent decision, links it to a system action, and exports structured logs to organisational audit tools. Without this, there's no way to prove compliance or investigate incidents.
Regular automation runs a fixed sequence of actions that can be documented upfront. An AI agent makes dynamic decisions at runtime, so you need to log both the decisions and the actions. This requires a more complex audit layer that links the two together.
A short call, no commitment, and we will tell you whether it is relevant to your business or not.