AI agents for business · a project by Easytrade · Košice, Slovakia

The agent only does what you allow

Every agent has clearly defined permissions, tools and boundaries. Critical steps – sending a quote, making a payment, changing a record – can require sign-off from a person. And everything it does stays in the log.

A robot hand with a network of connected systems
Four guarantees

What applies to every agent from day one

  • Your data stays in your systems and is never used to train models
  • A complete log of every action – you can see what the agent did and why
  • When unsure, the agent doesn't act on its own – it hands the task to a person with a proposed solution
  • Hosted with trusted providers in the EU or on your own infrastructure, in line with GDPR
Level 1

Proposes

The first weeks of the pilot. The agent prepares a proposal – a record, a reply, a quote – and a person approves every step. We tune the rules on real cases.

Level 2

Acts with approval

It handles routine work on its own. Critical steps – sending to a customer, a payment, a write to a system – wait for one-click confirmation.

Level 3

Acts on its own within limits

Within agreed limits it acts independently, escalates exceptions and logs everything. You can narrow the limits at any time.

How we make it safe

Six safeguards we set up in every deployment

Permissions

The agent has its own account with access only to the systems and actions you allow. Read access is enough to start; write access comes after the pilot.

Approvals

Sending to a customer, a payment or a change in a system waits for a person's confirmation. You define the list of critical steps.

A log of every action

What it read, what it found, what it proposed, who decided. Every step can be traced, corrected and explained – to an auditor too.

Escalation to a person

An unknown code, a price outside the list, an unclear request – the agent doesn't guess; it hands the case to the responsible person with a proposed solution.

Data in the EU or on your premises

Models run with trusted providers in the EU or on your own infrastructure. Your data is never used for training.

GDPR and sensitive data

A data processing agreement, data minimisation, no assessment of sensitive categories – health or personal matters are always handled by a person.

FAQ

What companies ask us about security

Can the agent send an email or change data in a system without us knowing?

No. Every agent has a list of permitted actions. Sending, payments and writes to your systems always require approval at the start; you grant independent action gradually and only within agreed limits. Every action stays in the log and you can narrow the limits at any time.

What if the agent makes a mistake?

The agent works within defined boundaries and escalates to a person when uncertain – it doesn't guess. Critical actions go through approval and every step is logged, so anything can be traced and corrected. During the pilot we also compare the agent's results with how a person handled the same cases.

Where is our data processed and is it safe?

Wherever you need it – with trusted providers in the EU or on your own infrastructure. Your data stays in your systems and is never used to train models. The agent's access is limited to the systems and scope you approve.

What about GDPR and personal data?

The agent processes personal data only to the extent a given process requires, under a data processing agreement, in the EU or on your infrastructure. It never assesses sensitive categories such as health data – it passes such messages, untouched, to an authorised person.

Want to see what the log and approvals look like in practice?

In a free consultation we show how the agent works on one of your real requests – including where it asks a person and what ends up on record.

Free consultation