Every AI system you run, on one layer you own
A business operating system is the layer a company builds and runs its own AI on: one governed way into its systems, one answer to who may see what, one route to the models, one place where applications and agents are built and released, and one record of what they did. Applicat AI builds it inside your own environment, on your own accounts, for your people to build on.
Nobody sets out to build an estate of nine AI vendors.
AI arrives one tool at a time: a chatbot from one vendor, a document tool from another, an agent bolted onto a single process by a third. Each purchase is defensible on its own. Together they become an estate nobody can govern, upgrade or switch off.
- 01
A copy of your company in every vendor
Each tool indexes your policies, contracts and tickets into its own store. The same document lives in five places, and five answers may disagree.
- 02
Permissions that are not your permissions
Every tool arrives with its own idea of who may see what, usually a service account with wider access than any employee holds, because that made the demo work.
- 03
No shared answer to what happened
Ask why a decision came out the way it did in March and you get as many log formats as you have vendors, several of which kept nothing worth reading.
- 04
Nowhere for anything to be retired
No register, no named owner, no review date. A tool nobody uses keeps its access and its invoice.
None of this is an argument against buying software. It is an argument about where the seams go. The parts that ought to be shared, the connections, the permissions, the record of what happened, are the parts each product keeps inside itself.
Five layers, and three things that run across all of them.
The phrase sometimes means a framework of meetings and metrics. This is not that. It is a set of parts assembled inside your own environment, most of them standard and several of them bought, so that what every application needs is held once, by you.
FIG. 03Business operating system
Everything your company does with AI passes through one layer, and the layer belongs to you.
Follow one piece of work
Systems of record, which you already run
- Finance and ERP
- CRM and service
- Documents and mail
- Data warehouse
Models, outside the layer
- Frontier
- Open weight
- In your region
Reached through layer 04 and never held. Models keep changing, so the next one is a decision you take rather than a system you rebuild.
The three pieces of work are examples of a mechanism, not a report of anything a client has run.
Your cloud tenancy
One layer. Your company owns it.
What your people build on it
- Agents
- Internal apps
- Assistants
- Automations
It arrives through one doorLayer 01 Connections and tools
From the mailbox your accounts team already uses, through one connection.
The layer knows who is askingLayer 03 Identity and permissions
Nobody asked for this one. The agent has its own name and its own limits.
It reads only what they may readLayer 02 Knowledge and retrieval
This supplier, their contract and their open orders. Nothing else.
One door to every modelLayer 04 Model gateway
Sent to the model that reads documents best, and to another when that changes.
A person signs, where you said one mustThe checkpoint
Anything above the value your finance team set waits for a named approver.
Held once, for every application on the layer
05 The build surface
Built here
Made from a template, and released through a review.
06 Evaluation harness
Tested here
Your own cases run again before a new model is let near the work.
07 Observability and audit
Recorded here
Every run written once, in one format, whoever built it.
08 The register
Listed here
One named owner, one review date, one way to switch it off.
What comes back
The invoice coded, matched to its order, and queued for payment.
And what is written down
- What was asked
- What it read
- Which model answered
- Who approved it
- What it cost
Buy it one product at a time and you buy the same eight parts again inside every one of them.
Each one arrives with its own connections, its own copy of your documents, its own idea of who may see what and its own log. None of it is shared with the next product, and none of it is yours.
Nine products, and what each of them brings with it
Chat assistant
- Connections
- Knowledge
- Identity
- Models
- Build
- Tests
- Records
- Register
Document reader
- Connections
- Knowledge
- Identity
- Models
- Build
- Tests
- Records
- Register
Meeting notes
- Connections
- Knowledge
- Identity
- Models
- Build
- Tests
- Records
- Register
Ticket triage
- Connections
- Knowledge
- Identity
- Models
- Build
- Tests
- Records
- Register
Sales assistant
- Connections
- Knowledge
- Identity
- Models
- Build
- Tests
- Records
- Register
Contract review
- Connections
- Knowledge
- Identity
- Models
- Build
- Tests
- Records
- Register
Forecasting tool
- Connections
- Knowledge
- Identity
- Models
- Build
- Tests
- Records
- Register
Knowledge search
- Connections
- Knowledge
- Identity
- Models
- Build
- Tests
- Records
- Register
Onboarding helper
- Connections
- Knowledge
- Identity
- Models
- Build
- Tests
- Records
- Register
- One layer
- Eight parts, held once, and held by you.
- Nine products
- The same eight, nine times over, and held by them. Nine answers free to disagree, nine logs in nine formats, and no register, so nothing is ever retired.
An illustration of where the seams go, not a count of anybody’s estate. Nine is the number this page uses for an estate assembled one purchase at a time, and the products named are categories rather than anyone’s software.
In the stack, from your systems upward
Connections and tools
One governed route into the systems the business runs on, so no application holds its own copy of your credentials.
Knowledge and retrieval
Search across your own material, inheriting the permissions of the system it came from, so nobody sees what their login would not show them.
Identity and permissions
Agents and applications are principals in the identity provider you already run, each with a named owner. No more service accounts created on a Friday to make a demo work.
Model gateway
Every model is reached through one gateway, so the choice of model is settled by a test result and changed by configuration.
The build surface
The templates, components and review path that turn something working on a laptop into something allowed to run.
Across every layer
Evaluation harness
One place your test cases live, so a model upgrade is a test run across everything you have built.
Observability and audit
One trail across everything that runs: what was asked, what was retrieved, which tools were called, which model answered and who approved it.
The register
What exists, who owns it, what it costs and whether anyone still uses it. Sprawl is prevented by having somewhere for things to be retired.
What each layer actually containsEight layers, item by item
01Connections and tools
one path into your systems
Finance, CRM, service desk, documents, mail and the warehouse, connected onceCredentials brokered once, never embedded in an applicationReads and writes exposed as named, scoped tools, revocable in one place
02Knowledge and retrieval
permission-aware, and cited
Documents, records and tickets indexed from the connected systemsOne refresh path, so an answer is not quietly six weeks oldA citation back to the source record on every answer
03Identity and permissions
every agent has a name
Least privilege, scoped to a task and bounded in timeActing for a user, or on its own behalf, whichever the task requiresOne place to change what an agent may do
04Model gateway
swap the model, keep the system
Frontier and open models behind a single interfaceRouting by task, with fallbacks when a provider degradesCost and rate limits per application and per teamResidency respected where data cannot leave a jurisdiction
05The build surface
where apps and agents are made
Templates and components for the patterns you repeatEnvironments and versioning, so every change goes through a path someone approvedThe same surface for your engineers and for ours
06Evaluation harness
your cases, run again
A suite of your own cases behind every application and agentRegression gates: nothing is released until it has passed those cases againBaselines kept, so a new model is scored on your work and not a public benchmark
07Observability and audit
one trail, one format
Run-level logging of inputs, retrieval, tool calls, model and costHuman decisions recorded at the checkpoints where they are requiredOne export for internal audit, customer due diligence and AI regulation
08The register
what exists, and who owns it
Usage, cost and test status against every entryA review date, and a defined way to switch something off
One screen for everything the company runs.
A layer nobody can see is a layer nobody can govern, so it has a front. Everything running is listed with its owner, anything needing a person waits for one, and the next application is added without starting again.
FIG. 04 Business operating system, the console
Concept drawing
Everything the company runs, in one place
Layer 08 · The register
Every application and agent the business depends on, the team that owns it, and how it is doing today.
- Claims triageReads a new claim and routes itClaims operationsNamed agent FrontierSuite attachedRunning
- Supplier checksChecks a new supplier before it is set upProcurementNamed agent FrontierSuite attached
- Policy answersAnswers staff questions from the policy libraryRisk and complianceActs as the user Open weightSuite attachedRunning
- Contract reviewPulls out the terms that matter, for a lawyer to checkLegalNamed agent In your regionBaseline recordedIn review
- Tariff lookupLooks up the duty owed on a partFinance operationsNamed agent Open weightSupersededBeing retired
The moment it stops and asks a person
The checkpoint
You set the line. It stops there every time, and both the asking and the answer are written down.
Waiting for Procurement
Supplier checks has stopped and is asking.
A new supplier came through with an insurance certificate that has run out. Procurement wrote the rule that covers this, so it has set nothing up and put the question to a person.
The rule it stopped onNo supplier is set up without current insurance.
Held at the checkpoint · Approver named in the register
Written down, whichever way it goesLayer 07 · Audit
- What was asked, and who asked it
- What it read before it stopped
- Which model answered, and which version
- What it did, and what it stopped short of
- Who decided, and when
Until someone answers, nothing happens.The work waits where it was left. It does not decide the question for itself.
What it takes to add the next one
Layer 05 · The build surface
Most of what a new one needs is already there. The team decides the few things that belong to the job itself.
Decided by the team that wants it
- What it should doMatch a delivery note to the order
- Who owns itWarehouse operations
- What it may touchThe order book, read only
- When it must askAnything that does not match
- What it may never doChange an order, or pay anything
Already there, from the ones before it
- The connection to the order bookLayer 01
- What it is allowed to readLayer 02
- Who is allowed to use itLayer 03
- The way it reaches a modelLayer 04
- The tests it has to passLayer 06
- The record of everything it doesLayer 07
- One owner, one review date, one off switchLayer 08
Held for a named approverNothing on the layer goes live on its own.
How it gets built
The layer is what a programme leaves behind.
Nothing is bought in advance. Each part is built the first time a real system needs it, which is why the sequence is the same ladder as every other engagement.
01
Frame and Prove
Applied AI Sprint
The first use case is proved on your real data, inside your own environment, and the parts of the layer it needs are built properly the first time.
- One working system, measured on your own cases
- Tests built from your cases, with baselines and a written go or no-go
02
Build and Deploy
Applied AI Programme
The second and third systems reuse what the first one needed, and that reuse is what turns a system into a layer. Your engineers build alongside ours.
- Shared connections, identity, model access and a build surface
- The register and the audit trail, on your own accounts
03
Run
Managed AI Operations
The layer is operated. New models are tested on your cases before they are adopted, and entries that no longer earn their place are retired.
- Model upgrades proven before they reach users
- A register that is reviewed, with cost and quality reported monthly
When you do not need one
A company that will only ever run one AI system does not need a business operating system, and we will say so. The layer earns its cost where a second and a third system would otherwise each arrive with their own connections, permissions and version of the truth.
Who builds on it
Your people, mostly. That is the point.
A layer only we can build on is a dependency with better manners. What your own people put on it is safe because the layer makes it so, not because someone remembered to be careful.
Your engineers
They inherit the connections, the identity model, the gateway and the test suites, so a new application starts at what is specific to your business.
Your analysts and operators
The people who know the process build the first version from a template, inside limits the layer enforces. Engineering comes in when a template will not carry it further.
Our engineers, at the start and on the hard ones
We build the first systems, the ones carrying real consequence, and the shared components everything else reuses. The balance shifts to your team as the layer fills out.
We report the split: the share of what runs on the layer that your own people built. It is meant to rise, and if it does not, the layer is not doing its job and we would rather say so than invoice around it.
End the relationship tomorrow and it keeps running.
Ownership is a test: could your team, or another firm, pick this up and carry it on? From the first sprint, the answer is meant to be yes.
Independence
The lock-in that matters is the layer, not the model.
Lock-in arguments are usually about whose model you use, which is the easiest part to change. What is hard to change is everything around it: the connections, the permissions, the index, the record of what happened. Whoever holds that layer holds the account. No lab, cloud, consultancy or fund owns us, so we build it for you to own, including against ourselves.
Why independence matters now01The code and the infrastructure
Repositories, infrastructure as code and configuration, in your accounts and under your source control from the first week.
02Your environment, your data
The layer runs in your own Microsoft Azure, AWS or Google Cloud tenancy, and model access goes through enterprise endpoints that do not train on your data.
03The tests and the baselines
The cases, the scoring and the baselines are yours. They let you judge the next model, or the next supplier, without taking anyone at their word.
04No licence of ours in the middle
The layer is assembled from standard and open components. There is no Applicat AI runtime to license, no fee per seat, and nothing that stops working when a contract with us ends.
One honest limit. The models, and most of the systems the layer connects to, are other people's software, so independence here means you can swap any of them.
Questions about the business operating system
Start with one system. Keep the layer.
An Applied AI Sprint proves the first use case on your own data in four to six weeks. The parts of the layer it needs are yours from the first week.