Trading companyDelivered
A copilot alongside the live back-office system, in the team’s own chat interface. Stock, order status, customer history: on a question, not on a click.
running in production
I want to work with agents, not screens
ITLine develops AI agents that work beside a company’s running systems: the team asks in plain text, the answer comes from the system’s real data, and where two parties collaborate, permissions are enforced by the shape of the interface. A risky action the agent only prepares; a person approves it.
You have a system, and everything is in it. Except that whoever wants to answer a question has to open it, find the right view and know where to look. That way the quick question is slower than asking a colleague.
A copilot alongside the system, where the team already talks. The question goes in as text, and the answer comes from the system’s real data, not from a separate copy that was refreshed last night.
The other form: a gate between two agents, with privilege separation. The partner does not see what they have no right to, and that is not forbidden by a rule, the interface simply does not offer it. The difference matters the moment someone makes a mistake.
To what is already there. The rule is the same as for our other systems: what works stays, and the agent connects to it. In practice that means the ERP or back-office system, the invoicing software, the webshop, e-mail and Monday.com. If an n8n workflow already runs, the agent connects to it; new workflows we no longer build in n8n, but with Claude and custom code.
If there is nothing to connect to, we say so. An agent does not replace a missing system: if the data lives in spreadsheets and people’s heads today, the system comes first, and only then is there something to ask it. That is not an upsell but an order of operations: the reverse of it is what produces the field’s 95% pilot failure rate.
A copilot alongside the live back-office system, in the team’s own chat interface. Stock, order status, customer history: on a question, not on a click.
running in production
Two parties work on shared material, but they do not see the same thing. The gate is privilege-separated: permission is not a setting, it is the shape of the interface.
241 live orders replayed, 465 paired line items. Correctness is measured against the item the operator actually approved.
The safety net is not the score. The safety net is that every article number is validated against the catalogue, and that a human approves before anything financial happens.
Because we measure it, and the measurement is part of the system, not a good wish after launch. We look at three things: how much of the output is right first time; for the wrong cases, how confident the model was; and whether it asked back on an uncertain case or passed it on silently. The third matters most, because a confident, silent error is the one that reaches a financial consequence unnoticed.
Those three numbers, measured on a system in production, are in the Measured section above, together with the basis and the date of the measurement. The same numbers show where human approval belongs in the chain. We do not set that threshold by instinct but by where a silent error becomes expensive.
This is the most common unasked question, and a fair one: an agent is not a finished box but a system working on the company’s data. We hand over phase by phase, and at the end of each phase you keep a part that runs in production. If the work stops there, what exists so far is yours, and it works, not a half-state only we can start.
The agent works on the company’s own database, not on a copy we hold. Which language model drives it and where it runs is decided at the survey and settled by contract, as are the data-processing details. That matters because the model is replaceable: if a provider changes its price or terms, that is maintenance, not a rewrite, because the agent is bound to the company’s data and rules, not to one vendor.
What this page does not promise: no published service level. Support and operations are a matter of contract, stated after the survey and sized to the real load, not picked from a package on a website.
A website chatbot talks to visitors and usually answers from a text. This agent works with the team, inside the company’s own system: it looks up stock, order status and customer history, and prepares actions. We do not build website chatbots.
Beside a system that already runs, faster than a new system: the data and the permissions exist, and the agent sits on top. We give the timeline after the survey, and at the end of the first phase the agent already answers on live data.
The quote is made after the survey, for a fixed scope. Running cost (the model usage fee) is a separate item, estimated at the survey for the expected volume. How the quote is formed: What it costs.
No, quite the opposite: the agent is built beside the existing system and works from its real data, not from a nightly copy. The team asks where it already talks.
It does, and according to the measurement most of its errors look confident, so the safety net is not the model’s score. The agent is given no action that would hurt to undo: anything risky it prepares, and a person approves. The details of the measurement are in the Measured section above.
Only what the given user is entitled to. In a gate between two parties this is not a rule that forbids it; the interface simply does not offer what there is no right to. Where the model runs and who processes the data is settled by contract (a GDPR data processing agreement).
An automation repeats a fixed sequence of steps: when the input is always the same, it is the cheapest and most reliable option. An AI agent is needed where the input is text and varies (an e-mail, a question, an incomplete order) and the next step depends on what it says. The two sit well side by side: the agent (Claude, in our systems) interprets, and custom code carries the fixed steps, versioned and tested, not an n8n workflow.
In the systems we deliver, Claude (Anthropic) runs in production today: Haiku for fast classification, Sonnet for interpretation and agent work. We do not tie the system to one provider: we also measure Chinese and open-weight models (GLM, Qwen) on our own tasks, and for sensitive data the model can run inside the company network. Which model and where is decided at the survey and settled by contract.
Most internal business AI agents are not high-risk systems under the AI Act, because they make no decisions about employees, creditworthiness or official matters. Even then, anyone talking to an AI must know they are talking to a machine, and the team using it must know the system’s limits. If the task touches a high-risk area, we flag it in the survey; the exact classification is a legal question.
Headcount does not decide it; repetition does. If the same question or the same step comes up many times a week and the data already sits in a system, it pays off even for a company of a few people. If the question is rare, or the data still lives on paper and in people’s heads, the system comes first and the agent after.
A one-hour conversation where you tell us what you get asked five times a week. After that, access to the system’s data, one person on the team who checks the answers in the first weeks, and a few real examples of the common questions. The whole process: How we work.
Agentic AI is artificial intelligence that does not just answer but takes steps towards a goal: it queries data, calls tools and decides the next step from the result. An AI agent is one concrete instance of it, here beside the company’s own system. In detail: What is agentic AI?
We do not recommend replacing it, and that is not what we build. What works: the agent looks the answer up in the company’s own data (order status, delivery, invoice, earlier correspondence) and drafts the reply, which a person reviews and sends. What disappears is the typing and the searching, not the person. We have no measurement of our own on replacing a phone line with a voice system, so we do not offer it.
We do not build a chatbot for your website. That is a different job, a different price and usually not what is needed.
And we do not hand the agent an operation whose undo would hurt. Anything risky it prepares, and a human approves it.
The same point appears here: Who this is not for