SolutionsWorkshopsBlogNewsAboutLet's Talk
HomeNewsAI security and governance
Product

Intuit built disaster recovery AI agent with full audit layer

EWOK Agent runs production failover using natural language. Every decision is logged and auditable—critical architecture for regulated organisations.

Automush
Published 13.09.2026
What this means for your business

If you're considering an AI agent that will touch production systems, audit layer design is the first step, not the last. Before choosing a vendor or platform, verify they can log every agent decision, link it to a specific system action, and export structured logs to your organisational audit tools. Without this, you have no way to prove compliance to regulators or investigate incidents.

Intuit built an AI agent called EWOK Agent using Amazon Bedrock that enables on-call engineers to run production system failover using natural language requests. Every action passes through layers of predefined policy, approval mechanisms, and complete documentation. Every agent decision is traceable and auditable.

What they built and why it works

EWOK Agent handles disaster recovery scenarios—situations where production systems need to move between availability zones or data centres. Instead of running manual scripts or working through long checklists, an on-call engineer sends a natural language request, and the agent translates it into a sequence of actions.

The architectural innovation is in the audit layer. Every agent decision is documented, every action passes through predefined policy, and every system change can be traced back to the original request. This isn’t “AI doing whatever it wants”—it’s an agent operating within a strict framework built upfront.

Why this matters for regulated organisations in Israel

Banks, insurance companies, and financial organisations in Israel operate under information security and regulatory standards similar to those Intuit faces. They must prove to regulators that every production system change is documented, approved, and auditable.

This case proves you can build AI agents that perform sensitive operations on production systems, but only if you build them correctly from the start. It’s not a question of “whether to use AI” but “how to build the layers around it”—policy, approvals, documentation, and audit.

Organisations already running critical automation systems can look at this architecture as a test case. The question isn’t just “what does the agent do” but “how do I prove what it did”.

What to do this week

If you’re considering an AI agent for production systems, start from the end: design the audit layer before choosing a model or platform. Ask vendors how they log decisions, how they link them to actions, and how they export logs to your organisational audit tools.

If you’re already running critical automations, check whether you can investigate an incident: can you link every system change back to the request or event that triggered it? If the answer isn’t clear, now is the time to build that layer.

For organisations wanting to build AI systems under security and regulatory standards, custom AI systems require precise architectural planning from the start.

Sources

Frequently asked

Can you use an AI agent in production systems without breaking regulatory compliance?

Yes, but it requires specific architectural planning. You need to build an audit layer that logs every agent decision, links it to a system action, and exports structured logs to organisational audit tools. Without this, there's no way to prove compliance or investigate incidents.

What's the difference between an AI agent and regular automation from an audit perspective?

Regular automation runs a fixed sequence of actions that can be documented upfront. An AI agent makes dynamic decisions at runtime, so you need to log both the decisions and the actions. This requires a more complex audit layer that links the two together.

Want to know what this means for you?

A short call, no commitment, and we will tell you whether it is relevant to your business or not.