ai.consulting.sa
AI Division

Autonomous AI Agents & Governed Automation

Bespoke AI agents, Retrieval-Augmented Generation (RAG), lead-intake automation, and workflow orchestration — all under a human-in-the-loop governance model with DEFAULT DENY permissions and full audit trails.

Business Agents

Custom Business Agents

We build agents that do real work — qualifying leads at 3am, answering customer questions from your knowledge base, scheduling meetings, and moving data between systems. Each agent is bespoke to your workflows, not a generic chatbot bolted onto a form.

  • Lead qualification and intake agents (24/7)
  • Customer communication over email, chat & WhatsApp
  • Scheduling and calendar coordination
  • Workflow automation across your existing tools
  • Multilingual Arabic/English conversational NLP
  • Prompt-injection hardening and input sanitization
Lead Qualification
Conversational agents qualify leads against your criteria and write them straight into your CRM — 24/7, in Arabic and English.
Communication
Drafted and sent communications across email, chat, and WhatsApp — every outbound action governed by the permission matrix.
Scheduling
Calendar coordination, reminders, and rescheduling handled autonomously within rules you define.
Automation
Repetitive tasks across your tools — data entry, status updates, notifications — handed off to agents that never sleep.
Isolation by design
Tenant isolation isn't a setting we flip — it's structural. Each customer's knowledge base lives in a separate index with its own access policy. There is no code path by which tenant A's documents can surface in tenant B's answers.
  • Customer-specific knowledge bases (documents, policies, FAQs)
  • Hybrid vector + keyword retrieval for precision recall
  • Strict multi-tenant isolation — zero data leakage between tenants
  • Document ingestion pipelines with chunking and embeddings
  • Per-document access policies and expiration
  • Citations back to the source passage for every answer
Knowledge & RAG

Knowledge & RAG Systems

Connect your internal documents, policies, and databases to dedicated AI agents with Retrieval-Augmented Generation. The agent answers from your knowledge — not its training data — and cites the source passage for every claim. Zero leakage between customers.

Automation

Workflow Automation

Agents get powerful when they're wired into your real processes. We orchestrate scheduling, data extraction, and multi-step processes — with n8n for visual workflow design and human-in-the-loop checkpoints wherever the stakes are high.

Scheduling and time-triggered automations
Data extraction from documents, emails and forms
Process orchestration across multiple systems
n8n integration for visual workflow building
Human-in-the-loop checkpoints for sensitive steps
Retry, dead-letter queues and observability on every run
Governance

Agent Governance & Permissions

Every agent operates under a DEFAULT DENY authorization matrix. An agent can do nothing unless it has been explicitly granted permission. High-risk actions require human approval, and every invocation is recorded in a tamper-evident audit log.

Authorization Matrix — Default State by Action Category
CategoryScopeDefault
Read
Query databases, read documents, fetch records
Allowed
Write
Create or update records, files, or configurations
Human Approval
Delete
Remove records, files, or resources permanently
Denied
External Communication
Send emails, messages, or call third-party APIs
Human Approval
Financial
Initiate payments, refunds, or move funds
Denied

Defaults shown above can be tightened per agent but never silently loosened. Any escalation requires documented sign-off and is reflected in the audit log.

Governance guarantees

  • DEFAULT DENY: an agent can do nothing unless explicitly permitted
  • Human approval required for high-risk write/communication actions
  • Tamper-evident audit logging of every agent invocation
  • Per-tenant, per-agent permission scopes
  • Rate limits and spend caps per agent and per day
  • Kill switch to pause any agent instantly
Dependencies

Model & Provider Dependencies

Our agents run on large language models hosted by third-party providers — we are transparent about that. We don't own the models, and we can't override a provider's limits. Here's exactly how the dependency works and what we do to manage it.

  • Transparent disclosure of all LLM providers in use (e.g. OpenRouter)
  • Model change management: we notify you before swapping models
  • Usage limits and rate caps inherited from upstream providers
  • AI cost reporting — you see exactly what each agent spends
  • Fallback model chains so a single provider outage degrades gracefully
  • Right to request an alternative provider where feasible
Why this matters

LLM providers (such as OpenRouter and the model labs behind them) can change models, raise prices, impose rate limits, or deprecate endpoints on their own timeline. We can't prevent that — but we can make it visible and build in resilience.

We maintain fallback model chains so a single provider outage degrades the agent to a weaker but functional model instead of failing outright. And every riyal of AI spend is reported, so costs never surprise you.

The AI Division operates under dedicated AI service terms (docs/legal/AI_SERVICES_TERMS.md).

Limitations

AI Limitations & Responsibilities

AI is a powerful tool with real limits. We design our systems to account for them — but the honest version is: these limits cannot be engineered away. Understanding them is a condition of using our agents responsibly.

Probabilistic by nature
LLMs generate plausible output, not guaranteed-correct output. They can be confidently wrong. Every material output must be reviewed by a human before action.
Human verification required
Agents are assistants, not autonomous decision-makers. A human is accountable for any action taken based on agent output — especially writes, payments, and external messages.
Output validation
We add validation layers (schema checks, rule gates, allow-lists) on agent outputs, but these reduce — they do not eliminate — the risk of bad output.
Prohibited use cases
Our agents must not be used for legal or medical advice, regulated financial decisions, content that violates Saudi law, surveillance, or deceiving end users about AI involvement.
t("ai.inc")
  • Custom business agent design and implementation
  • Customer-specific RAG knowledge base with retrieval pipeline
  • Workflow automation with n8n integration
  • DEFAULT DENY governance matrix configuration
  • Audit logging and human-approval gates
  • Spend monitoring and usage reporting
t("ai.exc")
  • Ownership of the underlying LLM models or providers
  • Guarantees that AI output is always factually correct
  • Autonomous authority to take binding actions without human review
  • Coverage of upstream LLM provider fees and API costs
  • Liability for decisions made using agent output (human remains accountable)
  • Use for regulated advice — legal, medical, or financial decision-making
Process

How to Start

Six steps from first conversation to a governed, monitored, production agent.

1

Discovery

We map the workflows you want automated, the data the agent needs, and the risks involved.

2

Agent Design

We design the agent, its knowledge sources, and a permission scope grounded in DEFAULT DENY.

3

Governance Setup

We configure the authorization matrix, approval gates, audit logging, and spend caps.

4

Build & Integrate

The agent is built, connected to your systems, and wired into n8n or your orchestration layer.

5

Validation

Human-in-the-loop testing against real scenarios before the agent touches production.

6

Deploy & Monitor

The agent goes live with monitoring, audit trails, and a kill switch one click away.

Build agents you can actually trust.ai.consulting.sa

Book an agent architecture workshop. We'll scope your use case, design the governance matrix, and show you exactly how DEFAULT DENY works in practice.