Autonomous
Read-and-report. Triage, analysis, and drafting run unattended: the agent observes and recommends, but changes nothing.
Enterprise AI Agents · Software In A Service
Production-ready agents engineered around your processes: 506 catalogued agents across 8 domains, each a first-class principal with its own identity, scoped credentials, and full action logging. Designed, secured, hosted, and monitored by Citadel.
A governed AI agent catalog is a curated set of production agents that each hold their own identity rather than sharing a service account, and Citadel Cloud Management publishes one as Software In A Service, or SIAS: 506 catalogued agents across 8 domains, designed, secured, hosted, and monitored by Citadel. Every agent is a first-class principal with scoped credentials and full action logging, and risk is bounded by setting autonomy per agent and per action across three tiers. Tier 1 is read-and-report: triage, analysis, and drafting run unattended, because the agent observes and recommends but changes nothing. Tier 2 is supervised: writes to systems of record happen within scoped credentials and change windows, and every write is attributable and reversible. Tier 3 is human-gated: anything touching money, people, or legal is draft-only behind named approvers, with four-eyes enforcement. Autonomy is graduated deliberately: discovery, agent selection and grounding, a sandboxed rollout at Tier 1, then monitored operation.
Most “AI agents” are a demo that impresses in a meeting and stalls in production: no identity, no guardrails, no audit trail, no owner. The blocker to real automation isn’t the model. It’s governance: who is allowed to do what, with which credentials, and how you prove it afterward.
Every agent is a first-class principal with its own identity and full action logging. Autonomy is set per agent, per action, across three tiers, so you graduate trust deliberately instead of betting the business on a black box.
Read-and-report. Triage, analysis, and drafting run unattended: the agent observes and recommends, but changes nothing.
Writes to systems of record within scoped credentials and change windows. Every write is attributable and reversible.
Anything touching money, people, or legal is draft-only behind named approvers, with four-eyes enforcement.
Every action takes the same path, and the tier is set per agent and per action. T1 observes and changes nothing; T2 writes to systems of record inside change windows, attributably and reversibly; T3. Anything touching money, people, or legal. Stops at a named approver before it happens.
Delivery: Discovery → agent selection & grounding → sandboxed rollout at T1 → graduated autonomy → monitored operation.
The catalog is deep, but the buying question is simple: which business problem gets cheaper, faster, or safer, and at which autonomy tier the work runs.
Triage, classification, and first-draft responses run continuously so specialists spend their hours on the exceptions, not the queue.
Mostly T1 to T2Code review, test scaffolding, dependency and release chores handled by governed agents, shorter cycle time without loosening the merge bar.
T1 to T2Alert triage and evidence collection at T1, containment left human-gated at T3. Analysts stop drowning in noise while control of action stays with people.
T1 + T3 gateControl checks, evidence gathering, and audit-trail assembly run on a schedule and are attributable per agent. Audits become a query, not a fire drill.
T1 to T2Cost-anomaly detection, rightsizing recommendations, and idle-resource reporting surface savings; the changes stay supervised or human-gated.
T1, writes T2Runbook execution, ticket enrichment, and knowledge lookups offloaded from senior engineers, the same team ships more without more headcount.
T1 to T2Agents are chosen from this catalog and grounded in your corpora: runbooks, ADRs, policies, catalogs. Search for a capability, tool, or domain to see what fits your stack.
506 agents across 8 domains
The full development lifecycle from design through maintenance, integrated with repos, CI, and issue trackers.
Delivery pipelines, runtime operations, reliability, and cost. Incident-facing agents pull from live telemetry through read-scoped tools.
Configuration, connectivity, and traffic engineering across on-prem, cloud, and edge. Config-writing agents are T2 with change-window enforcement.
Design-time agents: blueprints, reviews, and migration planning grounded in the organization's own standards and reference architectures.
Cluster lifecycle, workload policy, and the internal developer platform. Admission-policy and upgrade agents are T2 with change-window enforcement; cluster-mutating actions are human-gated.
Provider-native control planes, where the operating model genuinely differs per cloud. These sit alongside the vendor-neutral CSPM and FinOps agents rather than replacing them.
Around-the-clock triage, hunting, and response. Tier-1 triage agents run at T1; anything that isolates a host or disables an account requires a human gate.
Frameworks into evidence, evidence into audits. These agents make compliance continuous instead of an annual scramble.
Human identity: joiners and leavers, entitlements, and the attack paths between them. Distinct from the agent-identity groups below, which govern non-human principals.
Pipelines, quality, governance, and the analytics surface. SQL-writing agents run against read-only replicas with row-level security intact.
The platform operating on itself: model lifecycle, agent quality, safety, and spend. These agents gate what every other agent is allowed to become.
Running the AI platform as infrastructure: serving, capacity, and promotion. Where AIM governs how a model behaves, these govern where it runs and how it ships.
The build-test-ship-retire loop for agents themselves. Retirement is a first-class step: a decommissioned agent whose credentials outlive it is the failure mode this group exists to prevent.
The employee-facing service desk and the asset estate behind it. Deflection-first: resolve at T0-T1, escalate with full context.
Hire-to-retire. Screening and review agents carry bias-audit requirements in their eval suites as a deployment precondition.
Transaction processing through planning. Anything that moves money is T3: draft-and-approve only, full audit trail, four-eyes enforcement.
Source-to-pay and plan-to-deliver. Supplier risk agents merge external signals with contract obligations from the legal corpus.
Contracts, counsel, and discovery. Uses the graph-walk retrieval profile against a clause knowledge graph; privileged corpora are tenancy-isolated.
From product definition to portfolio delivery. Synthesis-heavy agents that turn meetings, feedback, and tickets into decisions and artifacts.
Prospect to renewal. CRM-writing agents are T2; pricing approval workflows stay human-owned.
Demand, brand, and comms. Generation agents draft against the brand corpus; publishing is always a human action or an approved automation with rollback.
Every support channel plus the analytics behind them. Deflection with dignity: grounded answers, cited sources, clean handoff with full context when escalation is right.
Clinical, administrative, and research workflows. FHIR R4/R5-aware retrieval; clinical suggestion agents are decision support, never autonomous diagnosis.
Regulated money movement and market-facing work. Every decision-support output carries model-risk documentation per SR 11-7-style governance.
First notice of loss through subrogation. Adjudication agents recommend; adjusters decide above defined thresholds.
Catalog to conversion. Pricing agents operate inside guardrail bands with margin floors enforced by policy, not prompt.
OT-adjacent agents are strictly read-only against historians and SCADA exports; nothing on this platform writes to a control system.
Cleared-environment patterns: IL-appropriate hosting, CUI handling, and FedRAMP-aligned controls from the GRC corpus. Air-gapped model options via the gateway.
Per-role copilots plus the strategy functions that serve the whole leadership team.
First-class identity per agent instance. Attestation binds a running workload to its registry entry; every credential is short-lived and issued by the broker, never checked into code or config.
Every action an agent takes on a user's behalf carries a verifiable delegation chain: token exchange at the boundary, purpose binding on the grant, and scoped tool permissions evaluated at a policy decision point on every call.
Agents multiply non-human identities faster than quarterly reviews can catch. Continuous discovery, ownership attribution, rotation enforcement, and joiner-mover-leaver lifecycle applied to machines the same way it is applied to people.
Runtime defense for agent identities: detect impersonation, token theft and replay, confused-deputy patterns, and privilege escalation, then revoke fast through kill switches wired into the model gateway.
The same governance model, mapped to where the work is in your sector. Every rollout starts at Tier-1 read-and-report and graduates autonomy deliberately. Nothing here is a timeline or savings promise until we scope it with you. Full landing pages for fifteen industries are here.
Fixed-fee engagements sized to where you are, from a single-workflow pilot to a governed platform you own. Priced after a discovery call, no hourly meter. See full pricing. The three-week Agent Assurance Assessment is priced at a fixed $15,000, the same anchor as the Starter Pilot floor, with its full scope and deliverables published on the page.
From $15K fixed-fee
Prove value on one high-friction workflow.
$50K to $150K fixed-fee
Automate a whole function or domain.
$150K to $500K+ fixed-fee
Multi-domain rollout across the org.
From $8K per month
Run and improve the agents you deployed.
Custom engagement
Own a governed agent platform end to end.
A back-of-envelope from your own numbers. Hours a governed agent workforce can return, valued against your investment. It is an illustration, not a quote.
Illustrative first-year estimate
An illustration from your inputs, not a quote. Real savings depend on which agents fit, the autonomy tier, and your data. We size it precisely in a discovery call.
Pressure-test these numbers with an architectFour low-commitment entry points. Most engagements begin with a free call or the readiness assessment, then a scoped pilot.
Scope the highest-value, lowest-risk agents for your stack. No pitch deck.
Book it →A short structured review of your data, workflows, and controls with a prioritized agent roadmap. Scopes whether the fixed-price Agent Assurance Assessment is the right next step.
Book it →A working session that leaves you with a governed reference architecture, not slides.
Book it →The Enterprise AI Agent Blueprint, the governance model behind SIAS, sent to your inbox.
Get the blueprint →The objections a security team raises before agents touch production, answered from the governance model above.
Agents run in or adjacent to your tenancy and are grounded in your corpora, which stay under your control and are tenancy-isolated per engagement. The full posture is on the security & governance page.
Yes. Corpora and agent identities are isolated per engagement, and privileged corpora are isolated per legal domain so one workstream cannot read another.
Writes only happen at supervised (T2) or human-gated (T3) tiers within scoped credentials. Every action is logged, attributable to a specific agent identity, and designed to be reversible, so a wrong action is traceable and can be rolled back. Anything touching money, people, or legal is draft-only behind named approvers.
Each agent is its own principal with attested workload identity (SPIFFE/SPIRE). Credentials are broker-issued, ephemeral, and purpose-bound through OAuth token-exchange (RFC 8693). There are no static long-lived keys.
Engagements start with lower-risk Tier-1 read-and-report agents in a sandboxed rollout, then graduate autonomy deliberately as trust builds. You set the tier per agent, per action.
Fixed-fee, scoped after a discovery call, from a Starter pilot around $15K to multi-domain Enterprise rollouts, with an optional monthly Managed AI Workforce retainer. You know what a phase costs before you commit; there is no hourly meter. Detailed pricing is on the enterprise page.
The configuration and deliverables built for your environment are yours; specific IP terms are set in the engagement agreement so your legal team reviews them before signing.
A 30-minute discovery call to scope the highest-value, lowest-risk agents first, usually T1 read-and-report, then graduate autonomy as trust builds. Or read the security & governance posture.