Enterprise AI · The flagship

How we run AI on estates we are accountable for

Our operating account rather than a capability list: five commitments and what each costs you, three refusals we hold, one Tuesday as it actually runs, and what crosses back to your side every month.

Platform owner reviewing and correcting an AI-drafted remediation sequence before approving it against a live Maximo estate

What we find on arrival

Nearly every estate we walk into has already proved that an assistant can produce a good answer. What has not been settled is who owns the decision that follows it.

AI has usually arrived as four separate procurements, so no single person can describe how it is governed. The pilot worked with three enthusiastic users and a supplier in the room, and the rollout exposed the part nobody scoped: who reviews the output on the days the enthusiast is on leave. We now scope the reviewing before the capability, which loses us some goodwill in the first meeting and saves the programme later.

What we commit to

Five commitments, and what each one costs you

Data work, operations work, reporting work and user support get the same treatment, which is why a client can describe how AI is governed on their estate in one conversation. None of the five is free.

  1. 01

    Every stream of work gets a purpose, a boundary and an owner, in writing, before it runs

    What it costs you. A scoping meeting with people who are hard to get in a room, including whoever signs off production change. Our test is whether the boundary can be described to an auditor in one sentence.

  2. 02

    Every workflow sits in one of three modes, and never starts in the widest one

    What it costs you. The first weeks feel slower than the demonstration did. Assist is advisory. Draft requires a named person to approve before anything is published or applied. Controlled automation is for repeatable work inside a boundary agreed in advance.

  3. 03

    Generative stages and deterministic checks stay apart

    What it costs you. You inherit the obligation to tell us which of your requirements have one correct answer, and some of them will be contested internally. Anything compliance-critical is implemented as a rule, not inferred.

  4. 04

    Higher-impact work stops at a gate and waits for a named person

    What it costs you. Standing review work that has to be named, diarised and covered during leave. They approve, edit, defer or reject; if nobody reviews, nothing happens. We would rather you funded fewer workflows properly.

  5. 05

    The record stays attached to the run, and a lesson is its own approval

    What it costs you. Your improvement rate is set by how often somebody works the approval queue. What was proposed, what was corrected, who approved it, when, and against which version of the rules, is captured as the work happens.

A Tuesday, told properly

The part of the week a demonstration leaves out

One estate, one week, read from both ends. Roles rather than names; timings and conditions are illustrative.

Time

What the workflow did

What a person did

02:14

A scheduled check reports the same condition on a non-production environment for the third time this month, and opens a case inside its remit: one stream, one environment class, reading and drafting only.

Nobody is woken. Nothing about the hour is allowed to justify acting without a person.

02:31

A diagnosis and a remediation sequence are drafted, with the two prior occurrences and what was done about each attached.

Classified as requiring approval, because a shared environment is in scope. Then it queues.

02:31 to 07:20

Nothing. The run holds at the review gate rather than proceeding on its own judgement.

Five hours of waiting, which is the design and not a shortcoming.

07:20

The corrected sequence runs, not the original, and the difference between the two stays visible afterwards.

The client platform owner reads the draft, finds two steps that would run in the wrong order against this environment, corrects them and approves. Ninety seconds of estate knowledge a model does not hold.

10:40

The same correction is offered back as a change to what this role knows next time.

She approves that separately. Permission to act and permission to learn are two permissions.

Wednesday

A classification batch on one pump population is prepared for review, each candidate carrying its basis.

An engineer who knows the plant accepts most of it, rejects duplicate pairs that are two physical units with similar tags, and returns four records where the written standard is ambiguous. Slower, and correct.

Thursday

A supervisor covering an unfamiliar site asks how that site handles a returned rotable, inside the application he is already in.

He gets an answer grounded in his own organisation’s procedures, under his own authorisation, and confirms the transaction himself. Recorded against him, at that moment. No ticket, no elevated account.

Friday

Four questions are answerable without an investigation: what ran, what it proposed, who approved each material outcome, and what changed.

Because the evidence was captured as the work happened rather than assembled when somebody asked.

Where we hold the line

Three refusals we hold, however convenient

These are the three refusals we are asked to relax most often.

We do not let an agent widen its own scope

A run that cannot complete inside its remit stops and says so. It does not retry against a broader target, escalate its own permissions, or proceed on the balance of probability. Sitting at a gate for five hours is correct behaviour, not a fault to be tuned out.

We do not let a correction change future behaviour on its own

A reviewer correction is captured as a correction. Turning it into something the agent knows next time is a second, separate approval, because permitting work to touch the estate and permitting a lesson to change behaviour are different permissions.

We do not run user-facing assistance on an elevated account

Answers and actions are assembled under that user’s own authorisation, from procedures their organisation wrote. Where there is nothing to ground an answer on, the user is told that rather than given something plausible.

What stays yours

What crosses, which way, and who signs for it

Control that requires raising a request with a supplier is not control. Procurement should press hardest on the first row and read the last panel twice.

What moves From Direction To Signed by
Scope, mode, and the on/off switch for each agent, action and workflow Your named owner The workflow configuration Your own people, in an afternoon, without a change request to us
Approved outcomes of AI-assisted work A governed workflow Your Maximo estate, which stays the system of record The named approver for that decision type
The run record: stages, draft as produced, reviewer edits, approver, timestamps, cost, lineage MaxIron AI Engine execution controls Your monthly pack, and any assurance sample you take Drafted by us, corrected by your service delivery manager, issued over a human signature
A reviewer correction promoted into what an agent knows next time A review gate The standing knowledge for that role The owner of the role being changed, as a separate dated approval

What never crosses, and what we will not do quietly

  • A second store of your data beside Maximo, which you would have to extract on exit.
  • An answer or an action taken on a service account where a named person should own it.
  • A review queue that went unworked, quietly retried. It is named in the monthly pack, because an unworked queue is a staffing conversation.
  • A boundary widened by us to keep throughput up. An unworked queue means putting that workflow back to advisory mode.

Where the time goes

What this changes, and what it leaves in place

Running it this way does not shorten a decision. It shortens the assembly before one and removes the reconstruction afterwards, and it adds one cost that is easy to leave out of a business case.

Unchanged, and we would not claim otherwise

Still exactly the same work

  • The judgement on whether a risk is acceptable, which belongs to a person with authority to take it
  • Change control on anything that touches production
  • Deciding who may approve what, which no software answers
  • The reviewing itself, named, diarised and covered during leave

Gone, on every job

Off the week, on work of this shape

  • Assembling the same history by hand at three in the morning
  • Writing the first draft of the report that gets written every month
  • Reconstructing who decided what from chat logs, calendars and memory
  • Making the same correction to the same output every week and losing it every time

Across the Tuesday above, the decisions took minutes. The gathering beforehand, the drafting, and the reconstruction six weeks later are most of the cost, and they are the parts that can be industrialised.

Keep the decisions. Remove the surrounding labour. Budget for the reviewing.

Timings and volumes on this page are illustrative. Your position depends on which workflow types are in scope, how mature the underlying procedures are, and how quickly reviewers clear a queue. Where the asset data will not carry the decision being asked of it, the data work comes first.

MaxIron Intelligence, frequently asked questions

What is MaxIron Intelligence?
One operating model over four products rather than four procurements. AI Engine holds the governed workflows, AI Smart Data the data proposals, Assist the in-Maximo answers, and AI Crew the in-Manage assistance. The distinguishing feature is that scope, mode, named ownership, review commitment and evidence are agreed once and applied to all four.
What does a person keep hold of?
The decision on anything with consequence. Approval before a higher-impact change reaches the estate, and separately before a lesson changes how an agent behaves. The ruling on what a data standard says. The judgement on whether a risk is acceptable. And the authority to reduce a workflow back to advisory mode without asking us.
How does this complement IBM Maximo and MAS?
It sits alongside them and improves data quality and user productivity. Maximo remains the system of record for everything written, and nothing here replaces the IBM platform underneath. Delivery agents support upgrade, build and test orchestration; operations agents support triage, diagnosis and scheduled runs.
What evidence exists after a week of this?
Per run: the stages passed, the draft as produced, the reviewer edits, the named approver, the timestamps, the cost, and the lineage where one run resumed from another. The design goal is that answering "who decided this" is a lookup rather than an investigation, because assurance questions arrive weeks later. Governance and assurance registers the artefacts.
Does MaxIron run this, or hand it over?
Both, in that order. Production support comes from the same teams accountable for platform outcomes rather than from a separate AI function, and the switches in the ledger above are yours from day one. That is the part that matters if the relationship ever ends.

Bring two pieces of work and the names of two people.

Not a conversation about agentic AI. Two unglamorous operational tasks that ran more than twice last month, and the two people who would approve the outcomes. We apply the five commitments to both, name the mode each should start in, and give you an honest estimate of the weekly review time it commits you to.

Bring this to the first call

  • Two routine operational tasks that recurred more than twice last month
  • The names of the two people who would approve those outcomes, and whether they have the time
  • Your current change control position on anything that touches production
  • The last question your assurance or audit function asked about an automated change