SolutionsWorkshopsBlogNewsAboutLet's Talk
HomeNewsAI security and governance
Product

Intuit built disaster recovery AI agent with Amazon Bedrock

EWOK Agent lets on-call engineers run production failover from natural language requests, while maintaining full audit control over every action.

Automush
Published 08.09.2026
What this means for your business

If you are considering building an AI agent that performs critical operations on your infrastructure, the first requirement is an audit layer that logs every decision and action before execution. Banks and regulated organisations in Israel cannot afford an agent that operates as a black box - every request must pass through predefined policies, receive explicit approval, and be preserved for audit. If you do not have the capability to build this yourself, do not start.

Intuit built an AI agent called EWOK Agent for disaster recovery using Amazon Bedrock. The agent allows on-call engineers to run production system failover from natural language requests, while maintaining audit, policy, and control over every action.

What Intuit built and how it works

EWOK Agent is an autonomous agent that receives natural language requests from on-call teams and executes disaster recovery operations on production systems. Instead of requiring engineers to remember specific commands or navigate complex interfaces, the agent translates the request into concrete actions.

The key is that the agent does not operate freely. Every action passes through layers of predefined policy, approval mechanisms, and complete documentation. Intuit built the system so that every agent decision is traceable and auditable, a critical requirement for a company operating under strict security and regulatory standards.

Why this matters for regulated organisations in Israel

Banks, insurance companies, and financial organisations in Israel operate under security and regulatory standards similar to those of Intuit. They cannot adopt new technology simply because it is “smart” - it must meet audit, documentation, and control requirements.

What Intuit proved is that it is possible to build AI agents that perform sensitive operations on production systems, but only if you build them correctly from the start. This is not a matter of taking a language model and connecting it to infrastructure - it is a matter of designing architecture where every action passes through policy, every decision is documented, and every change is auditable.

For Israeli organisations considering building similar systems, this is an important architectural case study. It shows that the real challenge is not technological - it is organisational and procedural.

What to do if you are considering building something similar

Before you start building an AI agent for critical processes, you need to define the audit layer. Every action the agent performs must pass through predefined policy - who is authorised to request what, under what conditions, and with what approval.

The second step is documentation. Every request, every decision, and every action must be preserved in a way that enables complete audit. This is not just a regulatory requirement - it is also the only way to identify problems and improve the system over time.

If you do not have the internal capability to build this, do not try to take shortcuts. Systems that perform critical operations in production require expertise in building AI agents for business under security and regulatory standards.

Sources

Frequently asked

Can you use an AI agent for production operations without building a full audit layer?

No, at least not in a regulated organisation. Every critical action must pass through defined policy, explicit approval, and complete documentation. Without this, you expose the organisation to operational and regulatory risks that cannot be justified.

What is the difference between an AI agent for disaster recovery and regular automation?

Regular automation executes predefined actions based on clear triggers. An AI agent receives a natural language request, decides what action is required, and executes it - but only if built with audit layers and policy that ensure it will not do anything outside defined boundaries.

Want to know what this means for you?

A short call, no commitment, and we will tell you whether it is relevant to your business or not.