Enterprise AI · The flagship
How we run AI on estates we are accountable for
Our operating account rather than a capability list: five commitments and what each costs you, three refusals we hold, one Tuesday as it actually runs, and what crosses back to your side every month.
What we find on arrival
Nearly every estate we walk into has already proved that an assistant can produce a good answer. What has not been settled is who owns the decision that follows it.
AI has usually arrived as four separate procurements, so no single person can describe how it is governed. The pilot worked with three enthusiastic users and a supplier in the room, and the rollout exposed the part nobody scoped: who reviews the output on the days the enthusiast is on leave. We now scope the reviewing before the capability, which loses us some goodwill in the first meeting and saves the programme later.
What we commit to
Five commitments, and what each one costs you
Data work, operations work, reporting work and user support get the same treatment, which is why a client can describe how AI is governed on their estate in one conversation. None of the five is free.
- 01
Every stream of work gets a purpose, a boundary and an owner, in writing, before it runs
What it costs you. A scoping meeting with people who are hard to get in a room, including whoever signs off production change. Our test is whether the boundary can be described to an auditor in one sentence.
- 02
Every workflow sits in one of three modes, and never starts in the widest one
What it costs you. The first weeks feel slower than the demonstration did. Assist is advisory. Draft requires a named person to approve before anything is published or applied. Controlled automation is for repeatable work inside a boundary agreed in advance.
- 03
Generative stages and deterministic checks stay apart
What it costs you. You inherit the obligation to tell us which of your requirements have one correct answer, and some of them will be contested internally. Anything compliance-critical is implemented as a rule, not inferred.
- 04
Higher-impact work stops at a gate and waits for a named person
What it costs you. Standing review work that has to be named, diarised and covered during leave. They approve, edit, defer or reject; if nobody reviews, nothing happens. We would rather you funded fewer workflows properly.
- 05
The record stays attached to the run, and a lesson is its own approval
What it costs you. Your improvement rate is set by how often somebody works the approval queue. What was proposed, what was corrected, who approved it, when, and against which version of the rules, is captured as the work happens.
A Tuesday, told properly
The part of the week a demonstration leaves out
One estate, one week, read from both ends. Roles rather than names; timings and conditions are illustrative.
What the workflow did
What a person did
02:14
A scheduled check reports the same condition on a non-production environment for the third time this month, and opens a case inside its remit: one stream, one environment class, reading and drafting only.
Nobody is woken. Nothing about the hour is allowed to justify acting without a person.
02:31
A diagnosis and a remediation sequence are drafted, with the two prior occurrences and what was done about each attached.
Classified as requiring approval, because a shared environment is in scope. Then it queues.
02:31 to 07:20
Nothing. The run holds at the review gate rather than proceeding on its own judgement.
Five hours of waiting, which is the design and not a shortcoming.
07:20
The corrected sequence runs, not the original, and the difference between the two stays visible afterwards.
The client platform owner reads the draft, finds two steps that would run in the wrong order against this environment, corrects them and approves. Ninety seconds of estate knowledge a model does not hold.
10:40
The same correction is offered back as a change to what this role knows next time.
She approves that separately. Permission to act and permission to learn are two permissions.
Wednesday
A classification batch on one pump population is prepared for review, each candidate carrying its basis.
An engineer who knows the plant accepts most of it, rejects duplicate pairs that are two physical units with similar tags, and returns four records where the written standard is ambiguous. Slower, and correct.
Thursday
A supervisor covering an unfamiliar site asks how that site handles a returned rotable, inside the application he is already in.
He gets an answer grounded in his own organisation’s procedures, under his own authorisation, and confirms the transaction himself. Recorded against him, at that moment. No ticket, no elevated account.
Friday
Four questions are answerable without an investigation: what ran, what it proposed, who approved each material outcome, and what changed.
Because the evidence was captured as the work happened rather than assembled when somebody asked.
Where we hold the line
Three refusals we hold, however convenient
These are the three refusals we are asked to relax most often.
We do not let an agent widen its own scope
A run that cannot complete inside its remit stops and says so. It does not retry against a broader target, escalate its own permissions, or proceed on the balance of probability. Sitting at a gate for five hours is correct behaviour, not a fault to be tuned out.
We do not let a correction change future behaviour on its own
A reviewer correction is captured as a correction. Turning it into something the agent knows next time is a second, separate approval, because permitting work to touch the estate and permitting a lesson to change behaviour are different permissions.
We do not run user-facing assistance on an elevated account
Answers and actions are assembled under that user’s own authorisation, from procedures their organisation wrote. Where there is nothing to ground an answer on, the user is told that rather than given something plausible.
What stays yours
What crosses, which way, and who signs for it
Control that requires raising a request with a supplier is not control. Procurement should press hardest on the first row and read the last panel twice.
| What moves | From | Direction | To | Signed by |
|---|---|---|---|---|
| Scope, mode, and the on/off switch for each agent, action and workflow | Your named owner | → | The workflow configuration | Your own people, in an afternoon, without a change request to us |
| Approved outcomes of AI-assisted work | A governed workflow | ← | Your Maximo estate, which stays the system of record | The named approver for that decision type |
| The run record: stages, draft as produced, reviewer edits, approver, timestamps, cost, lineage | MaxIron AI Engine execution controls | ← | Your monthly pack, and any assurance sample you take | Drafted by us, corrected by your service delivery manager, issued over a human signature |
| A reviewer correction promoted into what an agent knows next time | A review gate | ↔ | The standing knowledge for that role | The owner of the role being changed, as a separate dated approval |
What never crosses, and what we will not do quietly
- A second store of your data beside Maximo, which you would have to extract on exit.
- An answer or an action taken on a service account where a named person should own it.
- A review queue that went unworked, quietly retried. It is named in the monthly pack, because an unworked queue is a staffing conversation.
- A boundary widened by us to keep throughput up. An unworked queue means putting that workflow back to advisory mode.
Where the time goes
What this changes, and what it leaves in place
Running it this way does not shorten a decision. It shortens the assembly before one and removes the reconstruction afterwards, and it adds one cost that is easy to leave out of a business case.
Unchanged, and we would not claim otherwise
Still exactly the same work
- The judgement on whether a risk is acceptable, which belongs to a person with authority to take it
- Change control on anything that touches production
- Deciding who may approve what, which no software answers
- The reviewing itself, named, diarised and covered during leave
Gone, on every job
Off the week, on work of this shape
- Assembling the same history by hand at three in the morning
- Writing the first draft of the report that gets written every month
- Reconstructing who decided what from chat logs, calendars and memory
- Making the same correction to the same output every week and losing it every time
Across the Tuesday above, the decisions took minutes. The gathering beforehand, the drafting, and the reconstruction six weeks later are most of the cost, and they are the parts that can be industrialised.
Keep the decisions. Remove the surrounding labour. Budget for the reviewing.
Timings and volumes on this page are illustrative. Your position depends on which workflow types are in scope, how mature the underlying procedures are, and how quickly reviewers clear a queue. Where the asset data will not carry the decision being asked of it, the data work comes first.
MaxIron Intelligence, frequently asked questions
- What is MaxIron Intelligence?
- One operating model over four products rather than four procurements. AI Engine holds the governed workflows, AI Smart Data the data proposals, Assist the in-Maximo answers, and AI Crew the in-Manage assistance. The distinguishing feature is that scope, mode, named ownership, review commitment and evidence are agreed once and applied to all four.
- What does a person keep hold of?
- The decision on anything with consequence. Approval before a higher-impact change reaches the estate, and separately before a lesson changes how an agent behaves. The ruling on what a data standard says. The judgement on whether a risk is acceptable. And the authority to reduce a workflow back to advisory mode without asking us.
- How does this complement IBM Maximo and MAS?
- It sits alongside them and improves data quality and user productivity. Maximo remains the system of record for everything written, and nothing here replaces the IBM platform underneath. Delivery agents support upgrade, build and test orchestration; operations agents support triage, diagnosis and scheduled runs.
- What evidence exists after a week of this?
- Per run: the stages passed, the draft as produced, the reviewer edits, the named approver, the timestamps, the cost, and the lineage where one run resumed from another. The design goal is that answering "who decided this" is a lookup rather than an investigation, because assurance questions arrive weeks later. Governance and assurance registers the artefacts.
- Does MaxIron run this, or hand it over?
- Both, in that order. Production support comes from the same teams accountable for platform outcomes rather than from a separate AI function, and the switches in the ledger above are yours from day one. That is the part that matters if the relationship ever ends.
Bring two pieces of work and the names of two people.
Not a conversation about agentic AI. Two unglamorous operational tasks that ran more than twice last month, and the two people who would approve the outcomes. We apply the five commitments to both, name the mode each should start in, and give you an honest estimate of the weekly review time it commits you to.
Bring this to the first call
- Two routine operational tasks that recurred more than twice last month
- The names of the two people who would approve those outcomes, and whether they have the time
- Your current change control position on anything that touches production
- The last question your assurance or audit function asked about an automated change