Solution 03

Agentic User Experiences

Agents that understand users, use trusted tools, and take useful action.

A capable model is not a product

A model that answers well is not yet something people can rely on. To act, an agent has to know who it is talking to, what that person is allowed to do, and when to stop. The hard part sits at those boundaries, not in the prompt.

Boundaries that make action safe

  1. 01

    A known user, not an anonymous prompt

    The session runs behind an authenticated OIDC boundary, so the agent acts as a known user with known entitlements.

  2. 02

    Context is assembled, not hoped for

    The model reasons over facts gathered deliberately rather than guessing at what it was never given.

  3. 03

    Tools hold the sensitive parts

    Typed MCP tools act on the user’s behalf — running diagnostics, raising tickets, writing results back — while credentials stay behind the tool boundary.

  4. 04

    Determinism where models are unreliable

    Validation and explicit failure handling cover the steps that must not vary, so uncertainty ends in a defined outcome.

  5. 05

    A way out to a person

    When entitlement or confidence runs out, the agent hands off with its session context attached instead of looping on the problem.

What has been built

Support assistant

Career record

An assistant that establishes the user, gathers its own context, acts through authenticated tools, and escalates to a person when it should.

Repository-aware automation

Personal project

A GitHub App that catalogs repositories and runs queued background work on a cloud-neutral compute boundary. In active development.

Context generation for agents

Career record

Context assembly, prompt construction, and deterministic handling for the steps where model output cannot be trusted.

Agentic workflows

Personal project

Packaged specification, review, and implementation workflows for agent runtimes — the practice used to build this site.

All solutions

Contact

Submission is not yet available.