Six GRC use cases. Twenty atomic agents. One lean, SME-aligned platform built to write once and use many.
6 use cases
ITGC · NIST · TPRM · BCRS · ISO · Privacy
20 atomic agents
Plus 4 foundational A0.x agents
64 personas
Served by on-demand config files
₹2.6Cr
Pipeline, 5 named clients
02 — Executive summary
Write once, use many — without the headcount.
Sixty-four GRC personas would normally mean sixty-four bespoke agents to build, eval, and maintain. AutoX collapses them to twenty atomic agents and a library of on-demand config files. Every persona inherits the same hardened core, with use-case behaviour expressed as configuration, not code.
The atomic-agent collapse
Above the line — every program runs the same shape of work: someone scopes the engagement, someone collects evidence, someone tests controls, someone tracks remediation. Across our six GRC programs that's sixty-four named personas — most doing structurally similar things in different idiom. Hover any tile for the persona and which atomic agent serves it.
A1
A1 · SOX Orchestrator
ITGC→ A1 Workflow Orchestrator
End-to-end ITGC process controller; sequences phases, assigns tasks, tracks deadlines and risks.
A2
A2 · Risk & Controls
ITGC→ A7 Control Mapping & Library
Maintains Risk & Control Matrix; links risks to controls and assertions; flags coverage gaps.
A3
A3 · SOX Scoping
ITGC→ A2 Scope & Context
Identifies in-scope systems and ITGCs; maintains system-to-financial mapping.
A4
A4 · Control Design Review
ITGC→ A9 Control Testing & Validation
Evaluates control design against COSO/SOX; identifies design gaps; recommends improvements.
A5
A5 · Evidence Collection
ITGC→ A8 Evidence Collection
Issues PBC requests, tracks submissions, validates evidence completeness and format.
A6
A6 · Test Planning
ITGC→ A9 Control Testing & Validation
Creates test scripts, defines sampling logic, determines evidence requirements.
A7
A7 · Operating Effectiveness Testing
ITGC→ A9 Control Testing & Validation
Executes test steps, inspects evidence, records pass/fail, identifies deviations.
A8
A8 · SOX Impact Assessment
ITGC→ A10 Gap & Deficiency Analysis
Assesses financial reporting impact; supports materiality and severity judgments.
A9
A9 · Audit Liaison
ITGC→ A15 Audit Liaison
Interfaces with auditors; responds to queries; manages walkthroughs and clarifications.
A10
A10 · SOX Reporting
ITGC→ A14 Reporting & Dashboard
Produces dashboards, KPIs, management and audit reports; tracks pass rate and aging.
A11
A11 · Deficiency Analysis
ITGC→ A10 Gap & Deficiency Analysis
Identifies failures, performs root cause analysis, classifies severity.
Recommends optimal controls per risk; privacy-by-design patterns; cost vs risk optimization.
A60
A60 · Incident Response
Privacy→ A13 Incident Response
Manages privacy incidents and breaches; classification, impact, notification workflows.
A61
A61 · Monitoring and Assurance
Privacy→ A12 Continuous Monitoring
Continuously evaluates control effectiveness; signal ingestion; anomaly detection.
A62
A62 · Reporting & Continuous Improvement
Privacy→ A14 Reporting & Dashboard
Compliance and execution reports; metrics aggregation; trend analysis.
A63
A63 · DFD and ROPA
Privacy→ A20 DFD/ROPA Documentation
Drafts data flow diagrams and ROPA documents via NLP from data inventory.
A64
A64 · DPDPA
Privacy→ A4 Regulatory Knowledge
DPDPA compliance tracking; ROPA documentation aligned to Indian data protection requirements.
+ on-demand config files
Below the line — twenty atomic agents, hardened once and specialised by configuration. Workflow Orchestrator (A1) appears in five programs above. It's not five agents — it's one A1 with five configs. The same collapse repeats for Risk Scoring (A5, six programs) and Remediation Tracking (A11, six programs).
Click any atomic agent below to filter the personas above
A1
A1 · Workflow Orchestrator
Coordinates multi-agent workflows; routes tasks based on use-case context. WebUI for humans, APIs for machines, MCP for tool context, A2A between agents.
Twenty agents cover sixty-four personas because the work has the same shape across programs — scope, evidence, test, remediate, report. A5 (risk) and A11 (remediation) show up in every program; A1 (orchestration) in five. The single-program specialists — A15, A17, A18, A19, A20 — only surface where the work is genuinely unique. Everything else lives in config, not code.
01
Reduced build cost & lean ops
12,936 dev hours and 1,940 manager hours to ship. About 60% of the cost of building 64 bespoke agents. Six developers, one manager, sixteen weeks to first go-live. After go-live the four A0.x foundationals handle the maintenance load, dropping human effort to two developers rotating.
02
SME-aligned evals
SMEs define what good looks like before any code ships. Control coverage, false-positive rate, RTO/RPO accuracy, ROPA completeness. Every build gates against those thresholds before promotion. Quarterly SME review keeps the targets honest as regulations and tooling shift.
03
Enterprise-grade
Per-agent ephemeral identities and per-call sandboxed execution. Every reasoning trace is replayable and attestable for audit. A0.6 Security Fabric red-teams agents continuously and blocks attack patterns inline at runtime, not just by policy. Audit-ready by default.
04
Scalable & secure architecture
Around 15 IaC templates ship the whole landing zone for each new tenant. CMEK and customer-managed keys, VPC Service Controls or Private Link, in-region data residency in asia-south1 or Central India. Horizontal scale per workload while A0.7 keeps spend and infra health in check.
05
Accelerated dev & improvement
A0.8 holds persistent memory and an eval-tracked backlog while A0.9 prototypes every change in a sandbox with ContextHub guardrails. Candidates auto-run against SME thresholds. Humans only see a merge nudge when there is a clean eval gain. No manual loop, no regression slipping through.
03 — Programs × architecture
Six programs. Twenty atomic agents. Pick a program to see its footprint.
GRC agent layer · A1–A20
20 atomic agents · color-coded by use-case coverage
A1
Workflow Orchestrator
5 cfg
A1 · Workflow Orchestrator
Coordinates multi-agent workflows; routes tasks based on use-case context. WebUI for humans, APIs for machines, MCP for tool context, A2A between agents.
ContextHub, guardrails, developer assist for agentic dev and sandbox validation.
Infrastructure · AWS · ap-south-1 (Mumbai)
Landing zone, security, data, observabilityTBD/month run
LZLanding zone — Terraform / CDK (~15 templates)
WEBAmplify · CloudFront · API Gateway
IAMIAM Identity Center · Cognito · per-task roles
KMSKMS (CMK) · Secrets Manager
NETVPC · PrivateLink · WAF
OBSCloudWatch · X-Ray · CloudTrail
DATAAurora PG HA · S3 · Redshift
AIBedrock · OpenSearch Serverless
Programs
ITGC13
NIST CSF9
TPRM12
BCRS9
ISO 2700110
Privacy11
04 — Architecture
AWS architecture and agent network.
Scroll to step through the architecture. A request enters from users, flows into the VPC and through the agent platform. As you keep scrolling the side systems recede and the agent platform expands to reveal the twenty atomic agents and the A2A connections that route work between them.
SCROLLArchitecture overview
Foundation · cross-cutting · always-on
A0.6
Security Fabric
Red-teams every subsequent build · blocks attack patterns inline · saves QA pass per agent.
A0.7
Infrastructure Mgmt
Heals dev infra automatically · FinOps caps · devs don't firefight infra.
A0.8
Performance Mgmt
Eval tracking + backlog before integration test · failing builds caught early.
Three stages, one continuous loop, evaluated by SMEs end-to-end.
One-time build covers infrastructure, A0.x foundations, A1–A20, and the persona configs. SME-defined evals gate go-live. From there A0.6/A0.7/A0.8/A0.9 take over the bulk of the continuous improvement loop.
Stage 01 · One-time build
Build the atomic core, then the configs that ride on it.
Landing zone — ~15 IaC templates, 20 dev hrs build.
Continuous red-teaming, ephemeral identities, sandboxed execution, and full reasoning-trace observability on AWS ap-south-1 (Mumbai). Crucial for the regulated industries this platform serves.
Identity & secrets
Ephemeral by default
IAM Identity Center for human SSO
Cognito user pool fronting the API
Per-agent IAM task roles via STS, short-lived
KMS CMK + Secrets Manager, no long-lived service keys
Network & data
Tenant isolation
VPC with PrivateLink to Bedrock, S3, Secrets
API Gateway + WAF in front; FastAPI has no public IP
Data residency held in ap-south-1 (Mumbai)
Encryption in transit and at rest, customer-managed keys
Sandboxed execution
Reasoning trace observable
ECS Fargate tasks with per-call session scoping
CloudWatch + X-Ray (OTel) for traces, CloudTrail for audit
Every agent decision traceable, replayable, attestable
~15 Terraform / CDK templates accelerate new tenant standup
A0.6 Security Fabric
Continuous red-team
Inline enforcement at runtime, not just policy.
Attack-pattern prevention before tool invocation.
Eval signal feeds A0.8 backlog automatically.
Auditable record of every blocked action.
A0.7 Infra Mgmt
FinOps on autopilot
Health checks, restart, kill, resume.
Budget guardrails; spend caps per workload.
Committed-use posture validated weekly.
Human-validated changes only.
A0.8 + A0.9
Improvement engine
Persistent memory, eval tracking, backlog.
Sandboxed hypothesis testing.
ContextHub and guardrails for dev assist.
Promotion only on eval gain with no regression.
07 — Project timeline
Sixteen weeks to first go-live, then A0.x take over.
Six developers and one manager, parallel workstreams. Foundationals come online W1–W4 — from W5 onward every dev hour above is amplified by A0.x. Continuous improvement cycles post go-live drop human dev effort to ~2 devs rotating.
Foundationals come online W1–W4. From W5 every dev hour above is amplified by A0.x.
Workstream
W1
W2
W3
W4
W5
W6
W7
W8
W9
W10
W11
W12
W13
W14
W15
W16
Owner
Infrastructure & landing zone1 dev · ~15 IaC templates
W1–W4
1 Dev
A0.7 Infrastructure MgmtInduct W1 · heals dev infra · FinOps caps
W1–W2
1 Dev
A0.6 Security FabricInduct W2 · red-teams every subsequent build
W1–W3
1 Dev
A0.8 Performance MgmtInduct W3 · eval tracking + backlog before IT
W2–W3
1 Dev
A0.9 Coding AgentInduct W4 · ContextHub + dev assist for A1–A20
W2–W4
1 Dev
Core Batch 1 — high complexityA9 · A17 · A19 · 40h each
Run cost vs pipeline — what we spend vs what's already qualifying.
AWS ap-south-1 (Mumbai). Cost numbers pending finance review — placeholders shown as TBD. INR conversion at 1 USD = ₹94. Pipeline is five named clients, ₹2.6 Crore total. Optimisation levers below the table; ratio strip at the bottom turns into a real read once numbers land.
Aggressive cache strategy on system prompts cuts inference cost on the heavy tier first.
20→12% orchestrator share
Lever 02 · Tier routing
Tune routing so Tier-1 Heavy carries less of the load; mid and light tiers absorb more without quality regression.
15–25% potential
Lever 03 · Committed use
Once steady state stabilises, lock committed-use discounts on inference, vector, database layers.
Data residency · DPDPA / SEBI / RBI — AWS ap-south-1 (Mumbai). Bedrock, Aurora, S3, OpenSearch, KMS, Secrets Manager all stay in-region. Cross-region inference is disabled; PrivateLink endpoints prevent any public egress for AI calls.