Skip to content

Every AI system you run, on one layer you own

A business operating system is the layer a company builds and runs its own AI on: one governed way into its systems, one answer to who may see what, one route to the models, one place where applications and agents are built and released, and one record of what they did. Applicat AI builds it inside your own environment, on your own accounts, for your people to build on.

Nobody sets out to build an estate of nine AI vendors.

AI arrives one tool at a time: a chatbot from one vendor, a document tool from another, an agent bolted onto a single process by a third. Each purchase is defensible on its own. Together they become an estate nobody can govern, upgrade or switch off.

  1. 01

    A copy of your company in every vendor

    Each tool indexes your policies, contracts and tickets into its own store. The same document lives in five places, and five answers may disagree.

  2. 02

    Permissions that are not your permissions

    Every tool arrives with its own idea of who may see what, usually a service account with wider access than any employee holds, because that made the demo work.

  3. 03

    No shared answer to what happened

    Ask why a decision came out the way it did in March and you get as many log formats as you have vendors, several of which kept nothing worth reading.

  4. 04

    Nowhere for anything to be retired

    No register, no named owner, no review date. A tool nobody uses keeps its access and its invoice.

None of this is an argument against buying software. It is an argument about where the seams go. The parts that ought to be shared, the connections, the permissions, the record of what happened, are the parts each product keeps inside itself.

Five layers, and three things that run across all of them.

The phrase sometimes means a framework of meetings and metrics. This is not that. It is a set of parts assembled inside your own environment, most of them standard and several of them bought, so that what every application needs is held once, by you.

FIG. 03Business operating system

Everything your company does with AI passes through one layer, and the layer belongs to you.

Follow one piece of work

Systems of record, which you already run

  • Finance and ERP
  • CRM and service
  • Documents and mail
  • Data warehouse

Models, outside the layer

  • Frontier
  • Open weight
  • In your region

Reached through layer 04 and never held. Models keep changing, so the next one is a decision you take rather than a system you rebuild.

The three pieces of work are examples of a mechanism, not a report of anything a client has run.

Your cloud tenancy

One layer. Your company owns it.

What your people build on it

  • Agents
  • Internal apps
  • Assistants
  • Automations
  1. It arrives through one doorLayer 01 Connections and tools

    From the mailbox your accounts team already uses, through one connection.

  2. The layer knows who is askingLayer 03 Identity and permissions

    Nobody asked for this one. The agent has its own name and its own limits.

  3. It reads only what they may readLayer 02 Knowledge and retrieval

    This supplier, their contract and their open orders. Nothing else.

  4. One door to every modelLayer 04 Model gateway

    Sent to the model that reads documents best, and to another when that changes.

  5. A person signs, where you said one mustThe checkpoint

    Anything above the value your finance team set waits for a named approver.

Held once, for every application on the layer

  • 05 The build surface

    Built here

    Made from a template, and released through a review.

  • 06 Evaluation harness

    Tested here

    Your own cases run again before a new model is let near the work.

  • 07 Observability and audit

    Recorded here

    Every run written once, in one format, whoever built it.

  • 08 The register

    Listed here

    One named owner, one review date, one way to switch it off.

What comes back

The invoice coded, matched to its order, and queued for payment.

And what is written down

  • What was asked
  • What it read
  • Which model answered
  • Who approved it
  • What it cost
FIG. 03 One piece of work, followed from the system it came out of to the answer and the record it leaves behind. Everything inside the drawn line runs in your own environment; the models sit outside it, reached through one gateway. The second view shows the same eight parts bought again inside each product. The work shown is an example, not a report of anything a client has run.

In the stack, from your systems upward

01

Connections and tools

One governed route into the systems the business runs on, so no application holds its own copy of your credentials.

02

Knowledge and retrieval

Search across your own material, inheriting the permissions of the system it came from, so nobody sees what their login would not show them.

03

Identity and permissions

Agents and applications are principals in the identity provider you already run, each with a named owner. No more service accounts created on a Friday to make a demo work.

04

Model gateway

Every model is reached through one gateway, so the choice of model is settled by a test result and changed by configuration.

05

The build surface

The templates, components and review path that turn something working on a laptop into something allowed to run.

Across every layer

06

Evaluation harness

One place your test cases live, so a model upgrade is a test run across everything you have built.

07

Observability and audit

One trail across everything that runs: what was asked, what was retrieved, which tools were called, which model answered and who approved it.

08

The register

What exists, who owns it, what it costs and whether anyone still uses it. Sprawl is prevented by having somewhere for things to be retired.

What each layer actually containsEight layers, item by item

01Connections and tools

one path into your systems

Finance, CRM, service desk, documents, mail and the warehouse, connected onceCredentials brokered once, never embedded in an applicationReads and writes exposed as named, scoped tools, revocable in one place

02Knowledge and retrieval

permission-aware, and cited

Documents, records and tickets indexed from the connected systemsOne refresh path, so an answer is not quietly six weeks oldA citation back to the source record on every answer

03Identity and permissions

every agent has a name

Least privilege, scoped to a task and bounded in timeActing for a user, or on its own behalf, whichever the task requiresOne place to change what an agent may do

04Model gateway

swap the model, keep the system

Frontier and open models behind a single interfaceRouting by task, with fallbacks when a provider degradesCost and rate limits per application and per teamResidency respected where data cannot leave a jurisdiction

05The build surface

where apps and agents are made

Templates and components for the patterns you repeatEnvironments and versioning, so every change goes through a path someone approvedThe same surface for your engineers and for ours

06Evaluation harness

your cases, run again

A suite of your own cases behind every application and agentRegression gates: nothing is released until it has passed those cases againBaselines kept, so a new model is scored on your work and not a public benchmark

07Observability and audit

one trail, one format

Run-level logging of inputs, retrieval, tool calls, model and costHuman decisions recorded at the checkpoints where they are requiredOne export for internal audit, customer due diligence and AI regulation

08The register

what exists, and who owns it

Usage, cost and test status against every entryA review date, and a defined way to switch something off

One screen for everything the company runs.

A layer nobody can see is a layer nobody can govern, so it has a front. Everything running is listed with its owner, anything needing a person waits for one, and the next application is added without starting again.

FIG. 04 Business operating system, the console

Concept drawing

Your tenancy

Everything the company runs, in one place

Layer 08 · The register

Every application and agent the business depends on, the team that owns it, and how it is doing today.

  • Claims triageReads a new claim and routes itClaims operationsNamed agent FrontierSuite attachedRunning
  • Supplier checksChecks a new supplier before it is set upProcurementNamed agent FrontierSuite attached
  • Policy answersAnswers staff questions from the policy libraryRisk and complianceActs as the user Open weightSuite attachedRunning
  • Contract reviewPulls out the terms that matter, for a lawyer to checkLegalNamed agent In your regionBaseline recordedIn review
  • Tariff lookupLooks up the duty owed on a partFinance operationsNamed agent Open weightSupersededBeing retired
Ordered by what needs attention

The moment it stops and asks a person

The checkpoint

You set the line. It stops there every time, and both the asking and the answer are written down.

Waiting for Procurement

Supplier checks has stopped and is asking.

A new supplier came through with an insurance certificate that has run out. Procurement wrote the rule that covers this, so it has set nothing up and put the question to a person.

The rule it stopped onNo supplier is set up without current insurance.

Held at the checkpoint · Approver named in the register

ApproveSend it backDrawn, not live

Written down, whichever way it goesLayer 07 · Audit

  • What was asked, and who asked it
  • What it read before it stopped
  • Which model answered, and which version
  • What it did, and what it stopped short of
  • Who decided, and when

Until someone answers, nothing happens.The work waits where it was left. It does not decide the question for itself.

What it takes to add the next one

Layer 05 · The build surface

Most of what a new one needs is already there. The team decides the few things that belong to the job itself.

Decided by the team that wants it

  • What it should doMatch a delivery note to the order
  • Who owns itWarehouse operations
  • What it may touchThe order book, read only
  • When it must askAnything that does not match
  • What it may never doChange an order, or pay anything

Already there, from the ones before it

  • The connection to the order bookLayer 01
  • What it is allowed to readLayer 02
  • Who is allowed to use itLayer 03
  • The way it reaches a modelLayer 04
  • The tests it has to passLayer 06
  • The record of everything it doesLayer 07
  • One owner, one review date, one off switchLayer 08

Held for a named approverNothing on the layer goes live on its own.

FIG. 04A drawing, not a screenshot: there is no Applicat AI product with this screen in it. A real one is assembled on your own accounts out of your own components, so no two would look alike. Every name, owner and state here was invented to show the shape of an interface, and nothing in it reports what any system has done.

How it gets built

The layer is what a programme leaves behind.

Nothing is bought in advance. Each part is built the first time a real system needs it, which is why the sequence is the same ladder as every other engagement.

  1. 01

    Frame and Prove

    Applied AI Sprint

    The first use case is proved on your real data, inside your own environment, and the parts of the layer it needs are built properly the first time.

    • One working system, measured on your own cases
    • Tests built from your cases, with baselines and a written go or no-go
  2. 02

    Build and Deploy

    Applied AI Programme

    The second and third systems reuse what the first one needed, and that reuse is what turns a system into a layer. Your engineers build alongside ours.

    • Shared connections, identity, model access and a build surface
    • The register and the audit trail, on your own accounts
  3. 03

    Run

    Managed AI Operations

    The layer is operated. New models are tested on your cases before they are adopted, and entries that no longer earn their place are retired.

    • Model upgrades proven before they reach users
    • A register that is reviewed, with cost and quality reported monthly

When you do not need one

A company that will only ever run one AI system does not need a business operating system, and we will say so. The layer earns its cost where a second and a third system would otherwise each arrive with their own connections, permissions and version of the truth.

Who builds on it

Your people, mostly. That is the point.

A layer only we can build on is a dependency with better manners. What your own people put on it is safe because the layer makes it so, not because someone remembered to be careful.

Your engineers

They inherit the connections, the identity model, the gateway and the test suites, so a new application starts at what is specific to your business.

Your analysts and operators

The people who know the process build the first version from a template, inside limits the layer enforces. Engineering comes in when a template will not carry it further.

Our engineers, at the start and on the hard ones

We build the first systems, the ones carrying real consequence, and the shared components everything else reuses. The balance shifts to your team as the layer fills out.

We report the split: the share of what runs on the layer that your own people built. It is meant to rise, and if it does not, the layer is not doing its job and we would rather say so than invoice around it.

End the relationship tomorrow and it keeps running.

Ownership is a test: could your team, or another firm, pick this up and carry it on? From the first sprint, the answer is meant to be yes.

Independence

The lock-in that matters is the layer, not the model.

Lock-in arguments are usually about whose model you use, which is the easiest part to change. What is hard to change is everything around it: the connections, the permissions, the index, the record of what happened. Whoever holds that layer holds the account. No lab, cloud, consultancy or fund owns us, so we build it for you to own, including against ourselves.

Why independence matters now
  • 01The code and the infrastructure

    Repositories, infrastructure as code and configuration, in your accounts and under your source control from the first week.

  • 02Your environment, your data

    The layer runs in your own Microsoft Azure, AWS or Google Cloud tenancy, and model access goes through enterprise endpoints that do not train on your data.

  • 03The tests and the baselines

    The cases, the scoring and the baselines are yours. They let you judge the next model, or the next supplier, without taking anyone at their word.

  • 04No licence of ours in the middle

    The layer is assembled from standard and open components. There is no Applicat AI runtime to license, no fee per seat, and nothing that stops working when a contract with us ends.

One honest limit. The models, and most of the systems the layer connects to, are other people's software, so independence here means you can swap any of them.

Questions about the business operating system

Start with one system. Keep the layer.

An Applied AI Sprint proves the first use case on your own data in four to six weeks. The parts of the layer it needs are yours from the first week.