AI Agents in Business Operations: What They Do, and Where the Line Is
KodDelta builds AI agents on top of the systems a company already runs. An enterprise AI assistant or RAG agent is $5,000–12,000 and ships in 2–4 weeks. The licence is perpetual, users are unlimited, and the source code is delivered to the client, so the agent stays under the client's control.
Somebody in your company has already put a chat window on the website. Meanwhile the same team still opens every inbound email by hand to decide whether it is an order, a complaint or a supplier chasing payment. The chat window and that inbox are two different technology problems, and confusing them is why most corporate AI pilots end up as a demo nobody uses.
A chatbot answers. An agent acts.
A chatbot receives a question and returns text. Its output goes to one person, its blast radius is that conversation, and if it is wrong the cost is a confused customer.
An agent receives an input — a message, a document, a scheduled trigger — and then does something in your systems. It reads records, applies rules, writes a result back, and reports what it did. Its output is a change in the business, not a paragraph. That difference drives everything else in this article: permissions, audit trails, approval gates and the list of actions it is not allowed to take.
If the question in front of you is really about front-line customer conversations rather than internal operations, the chatbot versus live support comparison covers that decision separately.
Five things an agent actually does inside a company
These are the patterns that survive contact with real operations. Each one takes an input a person currently handles by hand and produces a record a person can check.
| Job | What the agent does | Who approves |
|---|---|---|
| Inbound email to ticket | Reads the message, classifies it, extracts customer and order references, opens a ticket in the right queue with the right priority | Nobody for routine items; low-confidence classifications go to a review queue |
| Draft a quote | Pulls the current price list, applies the customer's agreed terms, produces a complete draft quote document | A salesperson reviews and sends. The agent never sends. |
| Match an invoice to an order | Extracts line items from the supplier invoice, matches them against the purchase order and goods receipt, flags every discrepancy with the figures side by side | Finance approves the payment. The agent never releases it. |
| Summarise and classify a document | Reads a contract, spec sheet or report, produces a structured summary, tags it and files it against the right customer or project | Nobody for filing; a person reads the summary before acting on it |
| Answer a reporting question in natural language | Converts "which open orders are past their promised date?" into a query against your database and returns the result with the underlying rows | Read-only. No approval needed because nothing changes. |
Note the pattern in the third column. The agent does the reading, matching and drafting — the parts that consume hours. The commitment stays with a person. That split is the design, not a limitation to be engineered away later.
RAG, in one paragraph
Retrieval-augmented generation is how an agent answers questions about your business rather than about the internet in general. Your documents and records are split into passages and indexed by meaning, not just by keyword. When a question arrives, the system first retrieves the handful of passages most relevant to it — the specific clause in the specific contract, the three rows in the order table — and only then asks the language model to compose an answer using those passages, with the sources cited alongside. The model is not asked to remember your business; it is asked to read the pages you just handed it. That keeps answers current when a document changes, makes every answer traceable to a source a person can open, and means the failure mode is "I could not find this" rather than a confident invention. Our guide to enterprise AI assistants goes further into the retrieval architecture.
Where the data sits and how permissions are bounded
This is the part IT procurement asks about first, and rightly so.
- Your records stay where they are. The agent does not need a copy of your database. It queries the systems that already hold the data through their APIs or read-only views, so there is one system of record and no synchronisation drift. See how we connect existing systems.
- The agent runs under a service account, not a superuser. It gets exactly the tables, endpoints and document folders the task requires, and nothing else. Scope the permissions to the job, then review them when the job changes.
- Permissions follow the user, not the agent. When an employee asks a question, the retrieval step filters to documents that employee is already allowed to see. An agent that ignores this becomes a very efficient way to leak the salary spreadsheet.
- Only the passage travels. What leaves your infrastructure for the model is the retrieved passage needed for one answer, not the archive.
- The deployment model is your choice. A commercial API under a contractual no-training clause, a private cloud instance, or an open-weight model on your own servers. Each trades capability against control.
- Everything is logged. Which question, which sources retrieved, which action taken, by which account, at what time. Without that log you cannot investigate an incident or pass an audit.
What an agent must not be allowed to do
State this in the specification, enforce it in the permission model, and do not let it erode as confidence grows.
-
1. Move money
No payment release, no transfer, no refund issued without a named person approving it. An agent may prepare a payment run, flag the mismatches and present it for approval. Pressing the button is a human act with a human accountable for it.
-
2. Sign or accept contracts
No agreement executed, no supplier terms accepted, no click-through consented to on the company's behalf. Contractual liability cannot be delegated to a statistical system, and no court will accept that it was.
-
3. Make a binding commitment to a customer unsupervised
No price promise, no delivery date, no warranty or credit note offered without review. An agent drafting a quote is useful; an agent sending it is a liability the moment its price list is a day stale.
-
4. Delete or overwrite records irreversibly
Agents mark, flag and supersede. They do not destroy. Every write is reversible and attributable, or it does not ship.
-
5. Act on unverified instructions found inside content it reads
An agent processing an inbound email must treat that email as data, never as a command. Otherwise anyone who can email your company can instruct your systems. Separate the instruction channel from the content channel in the design.
How to start without a twelve-month programme
Pick one input that arrives in volume and is currently opened by hand — the shared inbox, the supplier invoice folder, the tender documents. Build the agent for that single input, with a confidence threshold that routes uncertain items to a person, and run it in parallel with the manual process for two weeks so you can compare outputs before switching over.
- Enterprise AI assistant or RAG agent: $5,000–12,000, 2–4 weeks.
- Platform with AI throughout: $20,000+, 3–6 months.
- Annual maintenance: optional, 12–25% of build cost.
- Licence: perpetual, unlimited users, source code delivered.
Before scoping an agent at all, check whether the task actually needs one: many back-office jobs are deterministic and belong to a workflow engine, which is cheaper and easier to audit. The 5-question automation test sorts them. And if the task is one you were about to add headcount for, the hire-or-automate comparison is the calculation to run first.
An agent is only as useful as the structured data underneath it, which is why our AI work sits on operational systems: Elevatora SAHA for lift maintenance and field service management, SEMP Group's group-wide operations platform, and SmartHukuk in legal technology.
Bring the input you would put in front of an agent first and we will tell you whether it needs one. Request a quote, or read more about AI integration into existing systems.
Frequently asked questions
What is the difference between a chatbot and an AI agent?
A chatbot answers. An agent acts. A chatbot returns text to the person who asked; an agent reads data from your systems and writes a record back — creating a ticket, drafting a quote, flagging a mismatch — then reports what it did. The second requires permissions, an audit trail and a supervision model that the first does not.
What does RAG mean in plain terms?
Retrieval-augmented generation. Instead of relying on what a model absorbed during training, the system first searches your own documents and records for the passages relevant to the question, then asks the model to answer using only those passages, with the sources shown. It keeps answers tied to your data and makes them checkable.
Where does our data sit when we use an AI agent?
Your records stay in the systems that already hold them. The agent queries them under a service account with scoped permissions. What is sent to a language model is the specific passage needed for one answer, and you choose the deployment model — a commercial API under a no-training agreement, a private cloud instance, or a model running on your own infrastructure.
What must an AI agent never be allowed to do?
Move money, sign or accept contracts, or make a binding commitment to a customer without a named person approving it. Those actions carry legal and financial liability that cannot be delegated to a statistical system. Build them as a draft-and-approve step, never as an automatic one.
How much does an enterprise AI agent cost and how long does it take?
An enterprise AI assistant or RAG agent is $5,000–12,000 and ships in 2–4 weeks. A larger platform with AI throughout is $20,000+ over 3–6 months. Annual maintenance is optional at 12–25% of build cost, the licence is perpetual with unlimited users, and the source code is delivered.
Let's talk about what you need.
The 30-minute discovery call is free and carries no commitment.