Skip to main content

What are you looking for?

Explore our services and discover how we can help you achieve your goals

Enterprise AI agent platform: run AI agents with approvals, audit logs and cost limits

An enterprise AI agent platform is a governed runtime where AI agents plan and carry out multi-step work through approved tools, while approvals, audit logs, access rules and cost limits keep every action accountable. Netbase offers it as a forward-looking solution, built inside your own environment rather than licensed as a product.

Review this solution for your workflow View relevant work

Reviewed by David (CEO) · Updated 17 Sep 2026

star

What an agent platform is, and where it stops

An AI agent is software that takes a goal, decides the next steps and uses tools, such as a search, a database query or an API call, to complete them. An enterprise AI agent platform is the shared layer that helps operations leaders, IT and risk teams run many such agents safely: it registers each agent and its tools, controls what each one may touch, asks people to approve risky steps, records everything and caps the spend.

"Platform" here means a runtime Netbase builds for you inside your own cloud, not a Netbase product for licence. It also stops short of full autonomy: agents propose and prepare, and people stay accountable for decisions with financial, legal or customer impact. Single, well-defined automations that need no reasoning are often better as plain workflow rules; our agentic AI automation service helps decide which is which.

This is a strategic vision offer. Netbase has not yet published an agent platform it operates for a client or a division, so this page describes the target design and how we would get there. It belongs to the digital products family.

Why agent pilots stall

  • Current state
    Each team runs its own agent experiment with its own keys
    Target state
    One platform registers every agent, owner and tool
  • Current state
    Agents hold broad credentials to be useful
    Target state
    Each tool call runs with the smallest permission the task needs
  • Current state
    Nobody can say what an agent did last Tuesday
    Target state
    A full audit trail of prompts, tool calls, approvals and results
  • Current state
    Risky steps run without review
    Target state
    Approval rules pause the agent until a named person decides
  • Current state
    Model bills arrive as a surprise
    Target state
    Budgets per agent and team, with hard stops and alerts
  • Current state
    No evidence the agent is getting better or worse
    Target state
    Evaluation suites run before each release and on live samples

How an agent run is governed

The workflow, step by step:

  1. Register

    An agent is registered with its owner, purpose, allowed tools, data scope and budget.

  2. Trigger

    A person, a schedule or a system event starts a run with a clear goal.

  3. Plan

    The agent proposes the steps it will take; the plan is logged.

  4. Check policy

    Each planned tool call is checked against the agent's permissions and the platform's rules.

  5. Act

    Allowed low-risk steps run in the requesting user's context, with inputs and outputs logged.

  6. Approve

    Steps marked risky, such as sending external messages, changing records or spending money, pause for a named approver.

  7. Limit

    Token, time and cost counters stop the run if it exceeds its budget or loops.

  8. Complete

    The result and a readable summary return to the requester and the system of record.

  9. Evaluate

    Sampled runs are scored against expected outcomes, and failures feed the next release.

Capability modules

Agent definitions and owners → Records purpose, tools and scope → Catalogue of approved agents

Tool calls from agents → Enforces permissions and input checks → Mediated, least-privilege access

Users, roles, service accounts → Runs actions in the right user context → Scoped credentials

Risky steps → Routes to approvers with context → Recorded decisions

Rules on data, tools and topics → Blocks or flags violations → Enforced guardrails

Usage per run, agent and team → Applies quotas and hard stops → Predictable cost

Every prompt, call and result → Logs, traces and dashboards → Explainable history

Test scenarios and live samples → Scores success and safety → Release decisions

Requests to AI models → Routes, caches and swaps providers → Provider independence

Row of blade servers lit in blue

Agents can reuse building blocks from the Netbase productized module library, such as the workflow automation toolkit for deterministic steps and the AI chatbot and WorkChat integrator as a chat front end.

AI in this solution

Where AI already runs in delivered work, and where it is offered as a growth capability.

Governance, integrations, data and deployment

  • Human-in-the-loop points

    Approval rules are set per tool and per threshold: an agent may draft an email but not send it, or prepare a purchase order but not submit it. Owners review agent performance on a regular schedule.

  • Evaluation

    Each agent has scenario tests for task success, refusals and safe failure, run before release and on sampled live runs. The NIST AI Risk Management Framework and its Generative AI Profile structure how risks are mapped, measured and managed; our responsible AI and MLOps service runs that lifecycle.

  • Access control

    OWASP's guidance on excessive agency, one of its Top 10 risks for LLM applications, recommends minimal tools, minimal permissions, actions in the user's context, human approval and complete mediation. The tool gateway applies each of these.

  • Audit log

    Every plan, tool call, approval, result and cost is logged with agent, user and time, and retained under your policy.

  • Data boundary

    Agents reach data only through registered tools. Which models may see which data classes, the hosting region and prompt retention are decided in architecture and written into the contract.

  • Cost limits

    Budgets per run, agent and team, loop detection and a model gateway with caching keep spend inside agreed limits.

  • Security and certifications

    Netbase security practices apply: secure code review, TLS in transit and AES at rest, role-based access with MFA, vulnerability scanning, penetration testing and disaster recovery. Netbase holds ISO 27001 certification and a SOC 2 Type II attestation for its own operations; they do not extend to the platform built for you, which gets its own controls. See the data and AI stack for tooling choices.

  • Deployment

    The platform runs in your cloud account, next to the systems agents act on.

Implementation phases, roles and support

  1. Agent opportunity review

    List candidate tasks, their risk and the systems involved, and choose one or two with clear value and limited blast radius.

  2. Governance design

    Agree roles, approval rules, data classes, budgets and evaluation criteria with IT and risk owners.

  3. Platform core

    Build the registry, tool gateway, approvals, logging and budget control.

  4. First agents

    Deliver the chosen agents with scenario tests, then run them in shadow mode before they act.

  5. Scale

    Onboard more agents and teams through the same controls.

  6. Operate

    Review logs, costs and evaluation results, and retire agents that do not earn their keep.

A typical team combines a solution architect, AI and backend engineers, a security engineer, QA and a project manager. Controls are designed before the first agent is built, every tool is registered as a documented API, and each sprint ends in a weekly review of logged runs and costs. The team works remote-first from Hanoi in English, with work tracked in Jira or GitHub. Most Netbase projects are delivered on fixed-price contracts, with scope and price agreed after the opportunity review; milestone-based, monthly team retainer and KPI-linked terms are also offered.

Configuration, customization, IP and lock-in

  • Configured

    Agents, tools, permissions, approval rules, budgets and evaluation thresholds.

  • Customized

    Tool connectors to your systems, policy rules for your industry and the approval experience.

  • Ownership

    You own the IP Netbase creates for your custom development, including agent definitions and tests; Netbase productized modules are licensed, not transferred. The model gateway keeps you free to change AI providers.

Industry variants and use cases

Professional services

Agents that prepare proposals, staffing plans and project reports for review; see professional services.

Professional services

Finance and back office

Invoice matching, reconciliation preparation and variance notes, with approval before posting.

IT operations

Ticket triage, log summaries and runbook steps under change control.

Sales operations

Account research and CRM updates drafted for the account owner to approve.

Platform proof: Cloodo

Cloodo, one of the Netbase Business Divisions, is an AI-powered digital workplace for company profiles, services, projects and team collaboration that connects internal staff and outsourced specialists in one hybrid workspace, with CRM, HRM, Cloud ERP and AI modules. Netbase builds and runs it.

Cloodo is platform proof, not an agent-platform case: it shows Netbase operating an AI-enabled, multi-module product. No usage figures are published. Read the Cloodo Workspace record and see more in our work.

Cloodo Workspace: the work-management SaaS Netbase built and operates
Cloodo Workspace: the work-management SaaS Netbase built and operates

Cloodo Workspace is the work-management SaaS Netbase built and operates for service businesses.

Keep Reading
MLOps pipeline for an anonymous client
MLOps pipeline for an anonymous client

This anonymous portfolio record describes only the kind of AI system and what Netbase did; it publishes no client name, logo, location, dates, models, figures or results.

Keep Reading

Frequently asked questions

Usually not. One agent can run with its own controls; a platform pays off when several teams build agents and need the same approvals, logs and budgets.

Only for steps you classify as low risk. Everything else waits for an approver.

Any provider allowed by your data policy, through the model gateway, including models from OpenAI, Anthropic (Claude), Google (Gemini) and Meta (Llama) and open-weight models.

Each agent gets a baseline and target in the opportunity review, measured in the pilot.

AI automation and agents that keep people in charge AI automation and agents that keep people in charge

Netbase provides AI automation and agent development for operations teams that want repetitive, multi-step work done by software while people keep approval over the decisions that matter. We combine rule-based workflow automation with AI steps where they add value, design the human approval points in, and measure return against a baseline taken before the build.

Learn More
line

Related solutions and next step

Explore the other Netbase solutions or view relevant work. Send us the tasks you would like agents to take on and the systems they touch, and we will review this solution for your workflow.

Contact Netbase

Discuss a project

Netbase JSC helps organizations design, build, modernize, and operate digital products and AI-enabled business systems.
Project enquiries

[email protected]

WhatsApp

+84 937 869 689

Office address

91 Nguyen Chi Thanh, Dong Da, Hanoi, Vietnam

Get in touch

Tell us what you want to build, modernize, or operate.

Tell us what you want to build, modernize, or operate.

Contact Netbase