AutoX GRC · Agentic Platform · Business Case
CloudAWS · ap-south-1
Theme
A management business case

Six GRC use cases. Twenty atomic agents. One lean, SME-aligned platform built to write once and use many.

6 use cases
ITGC · NIST · TPRM · BCRS · ISO · Privacy
20 atomic agents
Plus 4 foundational A0.x agents
64 personas
Served by on-demand config files
₹2.6Cr
Pipeline, 5 named clients
02 — Executive summary

Write once, use many — without the headcount.

Sixty-four GRC personas would normally mean sixty-four bespoke agents to build, eval, and maintain. AutoX collapses them to twenty atomic agents and a library of on-demand config files. Every persona inherits the same hardened core, with use-case behaviour expressed as configuration, not code.

The atomic-agent collapse

Above the line — every program runs the same shape of work: someone scopes the engagement, someone collects evidence, someone tests controls, someone tracks remediation. Across our six GRC programs that's sixty-four named personas — most doing structurally similar things in different idiom. Hover any tile for the persona and which atomic agent serves it.

A1
A1 · SOX Orchestrator
ITGCA1 Workflow Orchestrator
End-to-end ITGC process controller; sequences phases, assigns tasks, tracks deadlines and risks.
A2
A2 · Risk & Controls
ITGCA7 Control Mapping & Library
Maintains Risk & Control Matrix; links risks to controls and assertions; flags coverage gaps.
A3
A3 · SOX Scoping
ITGCA2 Scope & Context
Identifies in-scope systems and ITGCs; maintains system-to-financial mapping.
A4
A4 · Control Design Review
ITGCA9 Control Testing & Validation
Evaluates control design against COSO/SOX; identifies design gaps; recommends improvements.
A5
A5 · Evidence Collection
ITGCA8 Evidence Collection
Issues PBC requests, tracks submissions, validates evidence completeness and format.
A6
A6 · Test Planning
ITGCA9 Control Testing & Validation
Creates test scripts, defines sampling logic, determines evidence requirements.
A7
A7 · Operating Effectiveness Testing
ITGCA9 Control Testing & Validation
Executes test steps, inspects evidence, records pass/fail, identifies deviations.
A8
A8 · SOX Impact Assessment
ITGCA10 Gap & Deficiency Analysis
Assesses financial reporting impact; supports materiality and severity judgments.
A9
A9 · Audit Liaison
ITGCA15 Audit Liaison
Interfaces with auditors; responds to queries; manages walkthroughs and clarifications.
A10
A10 · SOX Reporting
ITGCA14 Reporting & Dashboard
Produces dashboards, KPIs, management and audit reports; tracks pass rate and aging.
A11
A11 · Deficiency Analysis
ITGCA10 Gap & Deficiency Analysis
Identifies failures, performs root cause analysis, classifies severity.
A12
A12 · Remediation Management
ITGCA11 Remediation Tracking
Tracks remediation actions, validates updated controls, schedules re-testing.
A13
A13 · Compliance Governance
ITGCA16 Compliance Governance
Enforces SOX standards, control taxonomy, year-over-year consistency.
A14
A14 · Orchestrator (Central Brain)
NISTA1 Workflow Orchestrator
Manages NIST controls assessment flow; assigns tasks; handles exceptions.
A15
A15 · Asset Intelligence
NISTA3 Asset & Data Discovery
Builds asset & data inventory via CMDB ingestion, cloud discovery, classification tagging.
A16
A16 · Scope & Regulatory Intelligence
NISTA4 Regulatory Knowledge
Interprets NIST CSF / SP 800-53; determines applicability; runs regulatory crosswalks.
A17
A17 · Evidence Collection
NISTA8 Evidence Collection
Collects and validates evidence; scans policy repos; ingests system logs.
A18
A18 · Control Mapping
NISTA7 Control Mapping & Library
Maps controls to policies, processes, tools; detects duplicates and pre-identifies gaps.
A19
A19 · Risk & Gap Analysis
NISTA5 Risk Assessment & Scoring
Converts control gaps into risk insights via threat modelling and business impact correlation.
A20
A20 · Technical Validation
NISTA9 Control Testing & Validation
Performs technical assurance: vuln scans, CIS/STIG checks, IAM analysis.
A21
A21 · Remediation Planning
NISTA11 Remediation Tracking
Generates remediation actions; prioritizes; estimates cost/effort and dependencies.
A22
A22 · Reporting & Governance
NISTA14 Reporting & Dashboard
Communicates status: executive dashboards, regulator reports, audit trails.
A23
A23 · Intake & Discovery
TPRMA2 Scope & Context
Vendor identification and profiling; captures requests; populates inventory.
A24
A24 · Inherent Risk Scoring
TPRMA5 Risk Assessment & Scoring
Determines vendor risk tier via deterministic or ML scoring; routes assessment path.
A25
A25 · Due Diligence
TPRMA8 Evidence Collection
Validates controls: questionnaires, evidence ingestion, certification validation.
A26
A26 · External Intelligence
TPRMA6 Threat Intelligence
Independent posture validation: security ratings, dark web, breach data, threat signals.
A27
A27 · Gap & Findings
TPRMA10 Gap & Deficiency Analysis
Compares expected vs actual controls; flags deficiencies; assigns severity.
A28
A28 · Risk Decision
TPRMA16 Compliance Governance
Calculates residual risk; compares against appetite; triggers approvals or escalations.
A29
A29 · Contract & Controls
TPRMA18 Contract & Legal
Recommends contract clauses; embeds cyber controls; validates pre-signature compliance.
A30
A30 · Continuous Monitoring
TPRMA12 Continuous Monitoring
Monitors posture drift; tracks SLA violations; triggers reassessments automatically.
A31
A31 · Incident Correlation
TPRMA13 Incident Response
Correlates incidents to vendors; assesses scope and impact; recommends notification.
A32
A32 · Onboarding & Access Control
TPRMA17 Vendor Lifecycle
Validates prerequisites; enforces IAM policies; tracks onboarding completion.
A33
A33 · Remediation Tracking
TPRMA11 Remediation Tracking
Tracks corrective actions; verifies remediation evidence; escalates overdue items.
A34
A34 · Offboarding
TPRMA17 Vendor Lifecycle
Revokes access; validates data deletion; closes risk records.
A35
A35 · Orchestrator (BC&R Controller)
BCRSA1 Workflow Orchestrator
BC&R end-to-end workflow coordination; task sequencing; escalation routing.
A36
A36 · Business Context
BCRSA2 Scope & Context
Understands business structure; outputs service prioritisation and criticality scoring.
A37
A37 · BIA
BCRSA5 Risk Assessment & Scoring
Conducts Business Impact Analysis: RTO/RPO, MTPD, service tiering, dependency graph.
A38
A38 · Threat Intelligence & Risk
BCRSA6 Threat Intelligence
Identifies disruption scenarios; runs scenario modelling and risk scoring.
A39
A39 · Resilience Capability
BCRSA9 Control Testing & Validation
Assesses current controls and maturity using DR plans, BCPs, architecture diagrams.
A40
A40 · Strategy & Design
BCRSA19 Strategy & Design
Designs future-state resilience options; cost-risk trade-off modelling.
A41
A41 · Remediation Planning
BCRSA11 Remediation Tracking
Converts gaps into action plans; prioritisation logic; resource estimation.
A42
A42 · Testing & Validation
BCRSA9 Control Testing & Validation
Validates resilience: test scenario orchestration, comparison vs RTO/RPO targets.
A43
A43 · Reporting & Assurance
BCRSA14 Reporting & Dashboard
Regulatory and executive reporting; dashboard generation; audit trail management.
A44
A44 · Orchestrator (Compliance Mgr)
ISOA1 Workflow Orchestrator
ISO assessment central brain; manages stages, sequencing, milestone tracking.
A45
A45 · ISO Knowledge
ISOA4 Regulatory Knowledge
Parses ISO clauses and Annex A; maintains version awareness; translates standards into requirements.
A46
A46 · Scope and Context
ISOA2 Scope & Context
Identifies in-scope entities, systems, locations; analyses business context and stakeholders.
A47
A47 · Control Mapping
ISOA7 Control Mapping & Library
Determines applicability; generates and updates Statement of Applicability.
A48
A48 · Evidence Collection
ISOA8 Evidence Collection
Evidence harvester: requests documents; integrates with GRC, IAM, SIEM, CMDB.
A49
A49 · Risk Assessment
ISOA5 Risk Assessment & Scoring
ISO cyber risk specialist; calculates inherent and residual risk; maintains risk register.
A50
A50 · Control Testing
ISOA9 Control Testing & Validation
Tests design and operating effectiveness; rule-based technical checks; maturity scoring.
A51
A51 · Gap Analysis & Prioritization
ISOA10 Gap & Deficiency Analysis
Identifies compliance gaps; correlates gaps to risk impact; recommends priority.
A52
A52 · Reporting & Audit
ISOA14 Reporting & Dashboard
Generates ISO-formatted reports; produces heat maps; creates audit traceability index.
A53
A53 · Remediation Tracking
ISOA11 Remediation Tracking
Continuous compliance enforcer: tracks corrective actions; triggers re-testing cycles.
A54
A54 · Governance Orchestrator
PrivacyA1 Workflow Orchestrator
Orchestrates privacy agents; enforces lifecycle sequencing; aligns to risk appetite.
A55
A55 · Context and Regulation
PrivacyA4 Regulatory Knowledge
Interprets privacy laws (GDPR/CCPA/HIPAA/DPDPA); maps regulatory obligations to controls.
A56
A56 · Data Discovery & Mapping
PrivacyA3 Asset & Data Discovery
Discovers personal data; builds data inventory and flow maps via metadata scanning.
A57
A57 · Threat & Vulnerability
PrivacyA6 Threat Intelligence
Identifies cyber and privacy threats; correlates vulnerabilities with data assets.
A58
A58 · Privacy Risk Analysis
PrivacyA5 Risk Assessment & Scoring
Constructs privacy risk scenarios; performs risk scoring; calculates residual risk.
A59
A59 · Control Recommendation
PrivacyA11 Remediation Tracking
Recommends optimal controls per risk; privacy-by-design patterns; cost vs risk optimization.
A60
A60 · Incident Response
PrivacyA13 Incident Response
Manages privacy incidents and breaches; classification, impact, notification workflows.
A61
A61 · Monitoring and Assurance
PrivacyA12 Continuous Monitoring
Continuously evaluates control effectiveness; signal ingestion; anomaly detection.
A62
A62 · Reporting & Continuous Improvement
PrivacyA14 Reporting & Dashboard
Compliance and execution reports; metrics aggregation; trend analysis.
A63
A63 · DFD and ROPA
PrivacyA20 DFD/ROPA Documentation
Drafts data flow diagrams and ROPA documents via NLP from data inventory.
A64
A64 · DPDPA
PrivacyA4 Regulatory Knowledge
DPDPA compliance tracking; ROPA documentation aligned to Indian data protection requirements.
+ on-demand config files

Below the line — twenty atomic agents, hardened once and specialised by configuration. Workflow Orchestrator (A1) appears in five programs above. It's not five agents — it's one A1 with five configs. The same collapse repeats for Risk Scoring (A5, six programs) and Remediation Tracking (A11, six programs).

Click any atomic agent below to filter the personas above
A1
A1 · Workflow Orchestrator
Coordinates multi-agent workflows; routes tasks based on use-case context. WebUI for humans, APIs for machines, MCP for tool context, A2A between agents.
ITGCNISTBCRSISOPrivacy
5 configs · 5h build · 15h config · 20h/yr finetune
A2
A2 · Scope & Context
Establishes engagement boundary; identifies in-scope systems, processes, regulations.
ITGCTPRMBCRSISO
4 configs · 10h build · 20h config · 40h/yr finetune
A3
A3 · Asset & Data Discovery
Discovers IT assets, data flows, processing activities for risk and ROPA inputs.
NISTPrivacy
2 configs · 20h build · 10h config · 40h/yr finetune
A4
A4 · Regulatory Knowledge
Maintains up-to-date regulatory clauses; aligned to current control frameworks.
NISTISOPrivacy
3 configs · 15h build · 9h config · 40h/yr finetune
A5
A5 · Risk Assessment & Scoring
Computes inherent and residual risk per asset, process, vendor.
ITGCNISTTPRMBCRSISOPrivacy
6 configs · 10h build · 30h config · 20h/yr finetune
A6
A6 · Threat Intelligence
Ingests threat feeds; tags assets and vendors with relevant TTPs and CVEs.
NISTTPRMBCRSPrivacy
4 configs · 10h build · 20h config · 20h/yr finetune
A7
A7 · Control Mapping & Library
Maps requirements to a unified control library; one control to many regulations.
ITGCNISTISO
3 configs · 15h build · 9h config · 40h/yr finetune
A8
A8 · Evidence Collection
Pulls and indexes evidence from connected systems on demand or on schedule.
ITGCNISTTPRMISO
4 configs · 10h build · 12h config · 20h/yr finetune
A9
A9 · Control Testing & Validation
Runs control tests; validates design and operating effectiveness.
ITGCNISTBCRSISO
4 configs · 40h build · 12h config · 40h/yr finetune
A10
A10 · Gap & Deficiency Analysis
Identifies gaps versus framework expectations; prioritizes by risk.
ITGCNISTTPRMISO
4 configs · 10h build · 20h config · 20h/yr finetune
A11
A11 · Remediation Tracking
Owns issue lifecycle: ticket creation, status, SLA, evidence of fix.
ITGCNISTTPRMBCRSISOPrivacy
6 configs · 10h build · 18h config · 20h/yr finetune
A12
A12 · Continuous Monitoring
Watches signals across vendors, assets, processing for drift and anomalies.
TPRMPrivacy
2 configs · 10h build · 6h config · 20h/yr finetune
A13
A13 · Incident Response
Triages, escalates, documents incidents end-to-end.
TPRMPrivacy
2 configs · 10h build · 10h config · 20h/yr finetune
A14
A14 · Reporting & Dashboard
Generates board, regulator, operational dashboards.
ITGCNISTBCRSISOPrivacy
5 configs · 20h build · 15h config · 40h/yr finetune
A15
A15 · Audit Liaison
Handles auditor queries; assembles evidence packages and walkthroughs.
ITGC
1 configs · 10h build · 3h config · 40h/yr finetune
A16
A16 · Compliance Governance
Tracks policy compliance, attestations, exceptions.
ITGCTPRM
2 configs · 20h build · 6h config · 40h/yr finetune
A17
A17 · Vendor Lifecycle
Onboarding, periodic review, offboarding of third parties.
TPRM
1 configs · 40h build · 3h config · 40h/yr finetune
A18
A18 · Contract & Legal
Extracts obligations from contracts; flags privacy and security clauses.
TPRM
1 configs · 20h build · 3h config · 20h/yr finetune
A19
A19 · Strategy & Design
Designs continuity strategies, RTO/RPO targets, recovery playbooks.
BCRS
1 configs · 40h build · 3h config · 40h/yr finetune
A20
A20 · DFD/ROPA Documentation
Generates and maintains data-flow diagrams and ROPA records.
Privacy
1 configs · 20h build · 3h config · 30h/yr finetune
The math

Twenty agents cover sixty-four personas because the work has the same shape across programs — scope, evidence, test, remediate, report. A5 (risk) and A11 (remediation) show up in every program; A1 (orchestration) in five. The single-program specialists — A15, A17, A18, A19, A20 — only surface where the work is genuinely unique. Everything else lives in config, not code.

01
Reduced build cost & lean ops
12,936 dev hours and 1,940 manager hours to ship. About 60% of the cost of building 64 bespoke agents. Six developers, one manager, sixteen weeks to first go-live. After go-live the four A0.x foundationals handle the maintenance load, dropping human effort to two developers rotating.
02
SME-aligned evals
SMEs define what good looks like before any code ships. Control coverage, false-positive rate, RTO/RPO accuracy, ROPA completeness. Every build gates against those thresholds before promotion. Quarterly SME review keeps the targets honest as regulations and tooling shift.
03
Enterprise-grade
Per-agent ephemeral identities and per-call sandboxed execution. Every reasoning trace is replayable and attestable for audit. A0.6 Security Fabric red-teams agents continuously and blocks attack patterns inline at runtime, not just by policy. Audit-ready by default.
04
Scalable & secure architecture
Around 15 IaC templates ship the whole landing zone for each new tenant. CMEK and customer-managed keys, VPC Service Controls or Private Link, in-region data residency in asia-south1 or Central India. Horizontal scale per workload while A0.7 keeps spend and infra health in check.
05
Accelerated dev & improvement
A0.8 holds persistent memory and an eval-tracked backlog while A0.9 prototypes every change in a sandbox with ContextHub guardrails. Candidates auto-run against SME thresholds. Humans only see a merge nudge when there is a clean eval gain. No manual loop, no regression slipping through.
03 — Programs × architecture

Six programs. Twenty atomic agents. Pick a program to see its footprint.

GRC agent layer · A1–A20
20 atomic agents · color-coded by use-case coverage
A1
Workflow Orchestrator
5 cfg
A1 · Workflow Orchestrator
Coordinates multi-agent workflows; routes tasks based on use-case context. WebUI for humans, APIs for machines, MCP for tool context, A2A between agents.
ITGCNISTBCRSISOPrivacy
5 configs · 5h build · 15h config dev · 20h/yr finetune
A2
Scope & Context
4 cfg
A2 · Scope & Context
Establishes engagement boundary; identifies in-scope systems, processes, regulations.
ITGCTPRMBCRSISO
4 configs · 10h build · 20h config dev · 40h/yr finetune
A3
Asset & Data Discovery
2 cfg
A3 · Asset & Data Discovery
Discovers IT assets, data flows, processing activities for risk and ROPA inputs.
NISTPrivacy
2 configs · 20h build · 10h config dev · 40h/yr finetune
A4
Regulatory Knowledge
3 cfg
A4 · Regulatory Knowledge
Maintains up-to-date regulatory clauses; aligned to current control frameworks.
NISTISOPrivacy
3 configs · 15h build · 9h config dev · 40h/yr finetune
A5
Risk Assessment & Scoring
6 cfg
A5 · Risk Assessment & Scoring
Computes inherent and residual risk per asset, process, vendor.
ITGCNISTTPRMBCRSISOPrivacy
6 configs · 10h build · 30h config dev · 20h/yr finetune
A6
Threat Intelligence
4 cfg
A6 · Threat Intelligence
Ingests threat feeds; tags assets and vendors with relevant TTPs and CVEs.
NISTTPRMBCRSPrivacy
4 configs · 10h build · 20h config dev · 20h/yr finetune
A7
Control Mapping & Library
3 cfg
A7 · Control Mapping & Library
Maps requirements to a unified control library; one control to many regulations.
ITGCNISTISO
3 configs · 15h build · 9h config dev · 40h/yr finetune
A8
Evidence Collection
4 cfg
A8 · Evidence Collection
Pulls and indexes evidence from connected systems on demand or on schedule.
ITGCNISTTPRMISO
4 configs · 10h build · 12h config dev · 20h/yr finetune
A9
Control Testing & Validation
4 cfg
A9 · Control Testing & Validation
Runs control tests; validates design and operating effectiveness.
ITGCNISTBCRSISO
4 configs · 40h build · 12h config dev · 40h/yr finetune
A10
Gap & Deficiency Analysis
4 cfg
A10 · Gap & Deficiency Analysis
Identifies gaps versus framework expectations; prioritizes by risk.
ITGCNISTTPRMISO
4 configs · 10h build · 20h config dev · 20h/yr finetune
A11
Remediation Tracking
6 cfg
A11 · Remediation Tracking
Owns issue lifecycle: ticket creation, status, SLA, evidence of fix.
ITGCNISTTPRMBCRSISOPrivacy
6 configs · 10h build · 18h config dev · 20h/yr finetune
A12
Continuous Monitoring
2 cfg
A12 · Continuous Monitoring
Watches signals across vendors, assets, processing for drift and anomalies.
TPRMPrivacy
2 configs · 10h build · 6h config dev · 20h/yr finetune
A13
Incident Response
2 cfg
A13 · Incident Response
Triages, escalates, documents incidents end-to-end.
TPRMPrivacy
2 configs · 10h build · 10h config dev · 20h/yr finetune
A14
Reporting & Dashboard
5 cfg
A14 · Reporting & Dashboard
Generates board, regulator, operational dashboards.
ITGCNISTBCRSISOPrivacy
5 configs · 20h build · 15h config dev · 40h/yr finetune
A15
Audit Liaison
1 cfg
A15 · Audit Liaison
Handles auditor queries; assembles evidence packages and walkthroughs.
ITGC
1 configs · 10h build · 3h config dev · 40h/yr finetune
A16
Compliance Governance
2 cfg
A16 · Compliance Governance
Tracks policy compliance, attestations, exceptions.
ITGCTPRM
2 configs · 20h build · 6h config dev · 40h/yr finetune
A17
Vendor Lifecycle
1 cfg
A17 · Vendor Lifecycle
Onboarding, periodic review, offboarding of third parties.
TPRM
1 configs · 40h build · 3h config dev · 40h/yr finetune
A18
Contract & Legal
1 cfg
A18 · Contract & Legal
Extracts obligations from contracts; flags privacy and security clauses.
TPRM
1 configs · 20h build · 3h config dev · 20h/yr finetune
A19
Strategy & Design
1 cfg
A19 · Strategy & Design
Designs continuity strategies, RTO/RPO targets, recovery playbooks.
BCRS
1 configs · 40h build · 3h config dev · 40h/yr finetune
A20
DFD/ROPA Documentation
1 cfg
A20 · DFD/ROPA Documentation
Generates and maintains data-flow diagrams and ROPA records.
Privacy
1 configs · 20h build · 3h config dev · 30h/yr finetune
Agent runtime · A0.x foundational agents (one-time build, continuous duty)
The engine behind continuous improvement
A0.6 Security Fabric
Continuous red-teaming, inline enforcement, runtime attack pattern prevention.
A0.7 Infrastructure Mgmt
Service health checks, FinOps; kill/resume/restart unhealthy services.
A0.8 Performance Mgmt
Persistent memory, eval tracking & backlog, sandboxed hypothesis testing.
A0.9 Coding Agent
ContextHub, guardrails, developer assist for agentic dev and sandbox validation.
Infrastructure · AWS · ap-south-1 (Mumbai)
Landing zone, security, data, observabilityTBD/month run
LZLanding zone — Terraform / CDK (~15 templates)
WEBAmplify · CloudFront · API Gateway
IAMIAM Identity Center · Cognito · per-task roles
KMSKMS (CMK) · Secrets Manager
NETVPC · PrivateLink · WAF
OBSCloudWatch · X-Ray · CloudTrail
DATAAurora PG HA · S3 · Redshift
AIBedrock · OpenSearch Serverless
Programs
ITGC13
NIST CSF9
TPRM12
BCRS9
ISO 2700110
Privacy11
04 — Architecture

AWS architecture and agent network.

Scroll to step through the architecture. A request enters from users, flows into the VPC and through the agent platform. As you keep scrolling the side systems recede and the agent platform expands to reveal the twenty atomic agents and the A2A connections that route work between them.

USERSAuditors · SMEsFRONTENDNext.js on AmplifyAPI EDGEAPI Gateway · CognitoCACHEElastiCache RedisSTATEAurora PostgreSQL HAEncrypted · ap-south-1AWS MANAGEDBedrock · OpenSearchS3 · Knowledge BasesEXTERNAL SAASServiceNow · Jira · AuditBoard · OneTrust · SplunkFARGATE · AGENT PLATFORMFastAPI · ECS Fargate · A1–A20Per-agent IAM task role · A2A protocolA15hWorkflow Orchestrator5 CFGA210hScope & Context4 CFGA320hAsset & Data Discovery2 CFGA415hRegulatory Knowledge3 CFGA610hThreat Intelligence4 CFGA510hRisk Assessment & Sc…6 CFGA715hControl Mapping & Li…3 CFGA810hEvidence Collection4 CFGA940hControl Testing & Va…4 CFGA1010hGap & Deficiency Ana…4 CFGA1210hContinuous Monitoring2 CFGA1110hRemediation Tracking6 CFGA1310hIncident Response2 CFGA1740hVendor Lifecycle1 CFGA1820hContract & Legal1 CFGA1940hStrategy & Design1 CFGA2020hDFD/ROPA Documentation1 CFGA1420hReporting & Dashboard5 CFGA1510hAudit Liaison1 CFGA1620hCompliance Governance2 CFG
SCROLLArchitecture overview
Foundation · cross-cutting · always-on
A0.6
Security Fabric
Red-teams every subsequent build · blocks attack patterns inline · saves QA pass per agent.
A0.7
Infrastructure Mgmt
Heals dev infra automatically · FinOps caps · devs don't firefight infra.
A0.8
Performance Mgmt
Eval tracking + backlog before integration test · failing builds caught early.
A0.9
Coding Agent
ContextHub + dev-assist online · biggest leverage on A1–A20 build & config dev.
+ KMS · Secrets Manager · IAM · GuardDuty · Security Hub · CloudTrail · CloudWatch · X-Ray
05 — Lifecycle & evaluation

Three stages, one continuous loop, evaluated by SMEs end-to-end.

One-time build covers infrastructure, A0.x foundations, A1–A20, and the persona configs. SME-defined evals gate go-live. From there A0.6/A0.7/A0.8/A0.9 take over the bulk of the continuous improvement loop.

Stage 01 · One-time build

Build the atomic core, then the configs that ride on it.

  • Landing zone — ~15 IaC templates, 20 dev hrs build.
  • A0.x foundations — A0.6/A0.7/A0.8/A0.9, ~20h each.
  • A1–A20 — 5h to 40h per agent depending on complexity.
  • Per-agent QA: functionality, safety, performance vs evals.
  • Configs — persona files, prompts, tool access. 1 atomic core, N personas.
12,936
Dev hrs · 6 devs (~6.2 FTE)
+ 1,940 mgr hrs

Stage 02 · Evaluation & go-live

SME-defined evals decide what ships.

  • SMEs set initial eval targets per use case.
  • Build validated against evals before go-live.
  • Integration testing across all 6 use cases — week 11–14.
  • UAT and rollback readiness — week 14–16.
  • Manager sign-off at Phase 4 and Phase 5 gates.
See the loop ↓
~16 wks
To first go-live, parallel workstreams

Stage 03 · Continuous

The A0.x agents drive most of the maintenance.

  • SME feedback → A0.8 backlog → sandbox test → deploy.
  • Quarterly SME review and eval recalibration.
  • Annual finetuning sprint — retrieval, prompts, orchestration.
  • A0.7 + A0.8 handle infra optimisation, human-validated.
  • Human dev effort post go-live: ~2 devs rotating.
See A0.x induction in the timeline ↓
~2 devs
Rotating, post go-live · A0.x do the heavy lifting

How evals gate every release.

The finetuning loop

01
SME defines eval targetsAligned to domain benchmarks: control coverage %, false-positive rate, RTO/RPO accuracy, ROPA completeness.
02
Build validated against evalsNo agent or config promotes to production without meeting its threshold.
03
SME feedback feeds A0.8 backlogPerformance Management Agent prioritises the highest-impact gaps first.
04
Hypothesis tested in sandboxA0.9 Coding Agent assists; promotion only on eval gain with no regression.
05
Deploy with rollback readinessQuarterly SME review keeps targets honest as regulations and tooling shift.

Sample eval dimensions

ITGC
Control coverage %, deviation detection rate, evidence completeness
NIST CSF
Control mapping accuracy, threat-to-asset linkage precision
TPRM
Vendor risk-tier accuracy, monitoring signal precision/recall
BCRS
RTO/RPO validation accuracy, recovery playbook completeness
ISO 27001
Annex A clause coverage, deficiency root-cause precision
Privacy
ROPA completeness score, DSR turnaround SLA, DFD accuracy
06 — Secure & scalable landing zone

Observable, auditable, sandboxed by design.

Continuous red-teaming, ephemeral identities, sandboxed execution, and full reasoning-trace observability on AWS ap-south-1 (Mumbai). Crucial for the regulated industries this platform serves.

Identity & secrets

Ephemeral by default

  • IAM Identity Center for human SSO
  • Cognito user pool fronting the API
  • Per-agent IAM task roles via STS, short-lived
  • KMS CMK + Secrets Manager, no long-lived service keys
Network & data

Tenant isolation

  • VPC with PrivateLink to Bedrock, S3, Secrets
  • API Gateway + WAF in front; FastAPI has no public IP
  • Data residency held in ap-south-1 (Mumbai)
  • Encryption in transit and at rest, customer-managed keys
Sandboxed execution

Reasoning trace observable

  • ECS Fargate tasks with per-call session scoping
  • CloudWatch + X-Ray (OTel) for traces, CloudTrail for audit
  • Every agent decision traceable, replayable, attestable
  • ~15 Terraform / CDK templates accelerate new tenant standup
A0.6 Security Fabric

Continuous red-team

  • Inline enforcement at runtime, not just policy.
  • Attack-pattern prevention before tool invocation.
  • Eval signal feeds A0.8 backlog automatically.
  • Auditable record of every blocked action.
A0.7 Infra Mgmt

FinOps on autopilot

  • Health checks, restart, kill, resume.
  • Budget guardrails; spend caps per workload.
  • Committed-use posture validated weekly.
  • Human-validated changes only.
A0.8 + A0.9

Improvement engine

  • Persistent memory, eval tracking, backlog.
  • Sandboxed hypothesis testing.
  • ContextHub and guardrails for dev assist.
  • Promotion only on eval gain with no regression.
07 — Project timeline

Sixteen weeks to first go-live, then A0.x take over.

Six developers and one manager, parallel workstreams. Foundationals come online W1–W4 — from W5 onward every dev hour above is amplified by A0.x. Continuous improvement cycles post go-live drop human dev effort to ~2 devs rotating.

Foundationals come online W1–W4. From W5 every dev hour above is amplified by A0.x.
Workstream
W1
W2
W3
W4
W5
W6
W7
W8
W9
W10
W11
W12
W13
W14
W15
W16
Owner
Infrastructure & landing zone1 dev · ~15 IaC templates
W1–W4
1 Dev
A0.7 Infrastructure MgmtInduct W1 · heals dev infra · FinOps caps
W1–W2
1 Dev
A0.6 Security FabricInduct W2 · red-teams every subsequent build
W1–W3
1 Dev
A0.8 Performance MgmtInduct W3 · eval tracking + backlog before IT
W2–W3
1 Dev
A0.9 Coding AgentInduct W4 · ContextHub + dev assist for A1–A20
W2–W4
1 Dev
Core Batch 1 — high complexityA9 · A17 · A19 · 40h each
W3–W8
2 Devs
Core Batch 2 — mediumA2 · A3 · A4 · A5 · A7 · A14 · A16
W3–W8
2 Devs
Core Batch 3 — lowerA1 · A6 · A8 · A10–A13 · A15 · A18 · A20
W5–W10
2 Devs (post P1)
Config developmentPersona / prompt / tool configs
W5–W12
2 Devs
Integration testing & SME evalAll 6 use cases
W11–W14
All 6 Devs
UAT, rollback & go-livePhase 5 gate
W14–W16
All 6 + Manager
Continuous · finetuning sprintPost-SME · A0.x assisted
Month 5+ · ongoing
2 Devs rotating
Continuous · quarterly reviewSME + eval recalibration
Month 5+ · ongoing
Mgr + 1 Dev
Continuous · annual finetuningRetrieval · prompts · orchestration
Month 5+ · ongoing
3 Devs
Continuous · infra optimisationA0.7 + A0.8 driven · human-validated
Month 5+ · ongoing
A0.x + 1 Dev
A0.x foundational laneCore agent buildConfig developmentContinuous, A0.x-drivenA0.7 → A0.6 → A0.8 → A0.9 inducted across W1–W4.
08 — Run cost & pipeline

Run cost vs pipeline — what we spend vs what's already qualifying.

AWS ap-south-1 (Mumbai). Cost numbers pending finance review — placeholders shown as TBD. INR conversion at 1 USD = ₹94. Pipeline is five named clients, ₹2.6 Crore total. Optimisation levers below the table; ratio strip at the bottom turns into a real read once numbers land.

AWS · ap-south-1 (Mumbai) · monthly run
TBD
Annual
TBD
Top driver
Bedrock inference (Claude Sonnet + Haiku)
LayerMonthly USDMonthly INRShare
LLM inference (Bedrock · Claude Sonnet + Haiku)
Agent runtime (ECS Fargate · ALB)
Frontend hosting (Amplify · CloudFront)
Retrieval (OpenSearch Serverless · Bedrock KB)
Data layer (Aurora PG HA · S3 · Redshift)
Networking (API Gateway · PrivateLink · NAT · WAF)
Security (KMS · Secrets Mgr · GuardDuty · Sec Hub)
Observability (CloudWatch · X-Ray · CloudTrail)
Total · AWS · ap-south-1 (Mumbai)TBD
80% hit-rate target
Lever 01 · Prompt caching
Aggressive cache strategy on system prompts cuts inference cost on the heavy tier first.
20→12% orchestrator share
Lever 02 · Tier routing
Tune routing so Tier-1 Heavy carries less of the load; mid and light tiers absorb more without quality regression.
15–25% potential
Lever 03 · Committed use
Once steady state stabilises, lock committed-use discounts on inference, vector, database layers.
Data residency · DPDPA / SEBI / RBI — AWS ap-south-1 (Mumbai). Bedrock, Aurora, S3, OpenSearch, KMS, Secrets Manager all stay in-region. Cross-region inference is disabled; PrivateLink endpoints prevent any public egress for AI calls.
Croma
₹90 Lacs
Controls automation + continuous monitoring
Unilever
₹50 Lacs
SOC2 assessments + TPRM
ABB
₹50 Lacs
SOC2 assessments + controls testing
GSK
₹50 Lacs
Controls testing automation (replacing TrustCloud)
ABI
₹20 Lacs
SOC2 assessments
Total qualified pipeline
₹2 Crore
60 Lacs
5 clients · 4 use-case footprints overlap with the same atomic core, validating the write-once-use-many thesis from a revenue angle.
TBD
Annual run cost
AWS · 2026
₹2.6Cr
Pipeline
5 named clients
TBD
Run cost as % of pipeline
Annual cost ÷ qualified pipeline
TBD
Pipeline coverage of run cost
First-year revenue : run cost