muono
Platform
Agentic Automation

Agents that do the routine work, inside limits you write down.

Automation near an operating plant fails one of two ways: it does too little to be worth having, or it does something nobody authorised. So the work gets graded by consequence. Reading, checking and drafting run on their own. Moving a set point, closing a permit or touching the safety system stops for a person.

Authority levels

What an agent may do, and where it must stop.

Each level is written down, agreed before deployment, and attached to the agent rather than to a policy document nobody reads. Moving an agent up a level is a decision your team makes deliberately.

Observe
Reads the record and reports what it sees. Changes nothing.
Recommend
Proposes an action with the evidence behind it. A person decides whether to take it.
Draft and route
Prepares the work (a work order, a scope item, a permit request) and sends it to a named approver.
Act with approval
Executes only after the named person signs, and records who signed.
Never
Anything irreversible, anything that moves a set point, anything on the safety instrumented system, anything outside the written limits.
Where the chain stops

The agent runs to the gate. It does not run through it.

Reading, checking and drafting happen on their own. The step with consequence waits for a person, by design rather than by configuration.

SIGNAL
CHECKS
DRAFT
APPROVAL
IRREVERSIBLE
ACT
At the gate
A person
Named approver · recorded

A trigger fires: a threshold, a schedule, an event. The agent pulls the readings, runs the checks its charter allows and drafts the work, attaching the evidence it used. All of that is reversible, so none of it needs a signature.

Then it stops. The draft sits with a named approver, and the actuator on the other side of that gate is not something the agent can reach. What happens after the signature is recorded against the person who gave it.

Scoped to a job
An agent is given an outcome and the data it needs for that outcome. Nothing wider.
Graded by consequence
Reading a tag and moving a set point are not the same act, and the agent does not treat them as one.
Stops for a person
Anything that cannot be undone waits for the named person who owns that asset.
Recorded and reversible

Every run can be replayed.

Each step an agent takes is recorded: what it read, what it concluded, what it did. A run can be replayed after the fact, and the changes it made can be undone. There is a visible stop, and limits on how much an agent can do before it has to pause and ask.

Every step on the record
What was read, what was concluded, what was done, in order.
Reversible
Changes an agent made can be rolled back.
A visible stop
Agents can be paused or halted mid-run, by anyone with the authority to do it.

Your questions, answered

What stops an agent doing something it should not?
Its written limits. An agent reaches only the tags and the tools its charter names, and anything irreversible stops for a named person no matter how confident it is. The safety instrumented system is not on that list at any level.
Can we see what an agent did?
Yes. Every run is recorded step by step and can be replayed, and its changes can be rolled back. An action nobody can audit is an action nobody should have authorised.
Is there a stop?
Yes, and it is visible rather than buried. Agents can be paused or halted mid-run, and they have limits on how much work they can do before pausing for a person.
Who decides what an agent is allowed to do?
You do, before it runs. The levels are agreed at deployment and each one names the person who approves at that level.

Put an agent on one routine task and watch it work.

Request a pilotBook a walkthrough