Iternal Product Line — Managed AI Workforce Sponsored · Supervised · Stoppable
Iternal Workforce

A digital workforce your company can actually trust. Governed like employees. Provable like software.

AI agents that research, produce, and act for your teams — every action approved where it matters, attributed to a person, budgeted, and stoppable.

Run day to day by your managers, in plain language — not by engineers.

The Offer A scoped pilot in one department, success criteria agreed before day one, that produces your own numbers on capacity, trust, and cost. A go/no-go in weeks, not quarters.
Every action
Attributed to agent + human
Default
Human sign-off on real-world actions
3
Emergency-stop tiers
Zero
Shared or borrowed credentials
IW·01 — The Side Door The governance gap

Your people have identity, least privilege, and an offboarding process. Your AI labor has none of it.

AI labor is arriving faster than the controls to run it — through the side door.

A grand governed front gate stands closed while a thin thread slips in through a small side door — ungoverned AI agents entering the enterprise unmanaged.

Every function already wants agents — sales wants pipeline research, finance wants reconciliations, support wants first-draft replies, operations wants the repetitive work off its desk. The demand is not the problem. The demand is here.

The problem is the agents arriving to meet it. They have the security posture of a hackathon project: a borrowed login, whatever permissions that credential happens to carry, no record of what they did, and no way to stop them once they are running. That is a liability wearing a productivity costume — and the more useful it is, the faster it spreads before anyone governs it.

The uncomfortable part is that the agent often works. It drafts the document, files the report, touches the outside system — and because it produces value, nobody asks who authorized it, what it was allowed to see, what it cost, or how to stop it. The question gets deferred until it is an incident review instead of a design decision.

Scroll the standard sideways

The hiring standard you already enforce — and where AI labor falls short of it
Governance control Your employees Ungoverned AI agents today
Identity A unique, revocable identity per person A shared key or a borrowed human login, indistinguishable across holders
Permissioning Least privilege, scoped to the role and reviewed Whatever the credential happens to carry — often far more than the task needs
Change control Release discipline for anything that changes behavior Silent edits to behavior and permissions, with no versioning and no record
Audit An attributable record of who did what, when No durable record of which agent acted, on whose behalf, or why
Emergency stop Offboarding cuts off access immediately No switch — the agent runs until someone finds and pulls the plug

Agents multiply faster than employees ever did, and they act at machine speed. At any real adoption, ungoverned agents are the audit finding you could see coming.

IW·02 — A Managed Workforce Roles · installs · sponsors

Define the role once. Install it as a digital employee.

This is not a chatbot. This is not a copilot. This is a managed workforce.

You define a role once — how it works and what it is allowed to touch — then install it into a department as a digital employee with a named human sponsor accountable for it from the first day it runs, a pinned version, an explicit access ceiling, a defined knowledge scope, and a set of supervised duties. From there your managers run it the way they run people: assign work in plain language, monitor it, review what it produces, and approve anything consequential.

An org chart as a hanging mobile — solid navy blocks above hold translucent worker blocks on taut lines, one lit: every digital employee hangs under an accountable human.
01

Its own badge

Each agent is its own identity, never a borrowed login — and never more than it and the requester both hold.

02

One door to the outside world

Everything consequential passes a single gate that checks, authorizes, records, and executes — one place to govern.

03

A permanent file, not a chat history

Every run leaves a replayable working file; every real-world action lands on a permanent record.

Iternal Workforce is the management layer of Iternal’s agentic suite — it pairs with Ultramemory for shared memory, the Agent Skills Library, AgentAuth, and Ultracache, each adoptable on its own.

IW·03 — The Working Day Read · produce · act

Assign in plain language. Supervise by exception.

Your managers run agents the way they run people — assign, monitor, review, approve.

01

Read

Consume knowledge: answers grounded in your own documents, with citations — receipts, not recollections.

02

Produce

Create work products, filed in a searchable library and reusable as sources for the next task.

03

Act

Touch the outside world — waits for a human sign-off by default, with the exact draft shown.

The approver sees the exact draft, and whether the action can be undone. A denial is an answer the agent continues from — not a crash.

Fully unsupervised real-world action is not a setting that exists — it cannot be switched on.

A document held by a precision armature above a closed gate slot, its seal glowing — a real-world action suspended until a human signs off.
The authority funnel Illustrative
01 Platform capability set
02 Release declaration
03 Install grants
04 Per-action policy
05 Human approval

Nothing widens on the way down.

Anything not explicitly granted is off — never silently available.

Duties are drawn from a closed, platform-maintained list, and the risk grade of each duty is set by the platform, not by whoever authored the agent.

The desk leads with what needs a human

The operations view puts approvals waiting, exceptions, and the decisions only a person should make first — so managers supervise by exception, not by babysitting a chat window.

It is one governed path whether a person assigns the work, a schedule fires, or another agent hands off.

IW·04 — Command and Control Three stop tiers

Stop the work. Cap the spend. Prove both.

Governance is only real if you can stop the work, cap the spend, and prove both.

Three breaker levers of increasing size on a navy control panel, the smallest thrown — the three-tier emergency stop: one agent, a whole role, an entire department.

A budget breach trips the same stop machinery automatically — and re-trips while spend still exceeds the cap.

Automatic brakes on runaway work — depth, retries, and a hard iteration ceiling — trip it too.

Scroll the matrix sideways

The control matrix — scope, default posture, and the evidence each control produces
Control Scope Default posture Evidence produced
Human approval Per agent, per duty Sign-off required for real-world actions Dual-attributed decision record
Emergency stop Agent / role / department Reversible — park, not kill Attributed stop events
Spending caps Agent or department Automatic pause on breach Cap events + usage record
Automatic brakes Depth, retries, iterations Automatic Attributed trips
Upgrade re-consent Per install Required when capability widens Grant record
Revocation Any grant Takes effect at the next action Denial on the record

Every level of the operation is metered, with hard caps that pause the work automatically when a limit is hit. The AI bill becomes a dashboard, not a quarter-end surprise — attributable to the team and the task that spent it.

IW·05 — The Personnel Record Evidence, not assertion

Not a chat history. A permanent file.

Every digital employee has a file — permanent, attributed, and replayable.

An archive drawer open with one bound file stitched through by a single thread — every digital employee’s actions bound into one permanent, attributed record.

Append-only, tamper-evident

Every real-world action is recorded with its outcome and whether it can be undone; an undo is a new entry.

The record is the gate

Logging happens where the action is authorized — nothing can act while dodging the record.

Dual attribution, always

Every action names the acting agent and the person it acted for; delegation chains are auditable hop by hop.

Revocation lands mid-task

Access revoked mid-run is enforced at the very next action, and the denial is on the record.

An agent’s output can never land somewhere more readable than the knowledge the run was allowed to read.

Behavior ships like software

01

Sealed releases

Behavior ships as sealed, numbered versions; records prove exactly which version did any piece of work.

02

Tested at the gate

Test verdicts are recorded on the exact release and shown at activation. Advisory today; hard enforcement is a configuration switch.

03

No silent upgrades

A version that widens capability computes exactly what widened and waits for an explicit human re-grant; rollback is one step.

04

Offboarding that sticks

Retiring an agent cancels open work and revokes access immediately — while keeping its full history.

IW·06 — Headcount Economics Capacity · trust · cost

What the board actually asks about. All six answers.

Six outcomes, each tied to a lever you already own — the terms the board thinks in.

01

Capacity

Recurring schedules and hand-off chains keep repetitive work on a 24×7×365 cadence — throughput without headcount.

02

Trust

Real-world actions wait for sign-off; the approver sees the exact draft; every decision lands on the record.

03

Cost

Usage is metered everywhere, with hard caps that pause work automatically — a dashboard, not a quarter-end surprise.

04

Speed

Drop a document into a team drive and every agent there uses it on its next task.

05

A compounding asset

Every deliverable is filed, cited, and searchable — institutional knowledge accumulates instead of evaporating.

06

Readiness

Versioned behavior, test verdicts at activation, one-step rollback, complete evidence — in place before anyone asks.

Cancelled and failed work still counts, so there are no blind spots. Cost estimates are chargeback-ready at configured rates — always estimates, never billing-grade.

IW·07 — What Ships Today 12 shipping today

What is running now — and exercisable in your pilot.

12 lines from the register — every one shipping today and exercisable in your own pilot, stated plainly.

Scroll the register sideways for status

Iternal Workforce capability register
RefCapabilityStatus
01 Roles authored once; behavior ships as sealed, numbered releases you can prove did the work Ships
02 Test suites recorded on the exact release, with a pass/fail verdict at activation — advisory today; hard enforcement is a configuration switch Ships
03 Every install sponsor-bound and pinned; upgrades that widen capability require re-approval; rollback is one step Ships
04 Each agent its own identity; authority is the intersection of agent and requester; revoked access stops at the next action Ships
05 Duties graded read / produce / act; real-world actions wait for sign-off, with the exact draft shown to the approver Ships
06 One gate for everything external; a retried or replayed action never fires twice and never double-logs Ships
07 A permanent, tamper-evident record of every action, with whether it can be undone, plus a replayable working file per run Ships
08 Three-tier emergency stop, with a console listing every active pause and who raised it Ships
09 Enforced spending caps and automatic brakes on runaway work — both trip the pause machinery Ships
10 Full usage metering with team and trend views, and chargeback-ready cost estimates Ships
11 Recurring schedules and multi-agent relay chains on the same governed path Ships
12 Answers grounded in your own documents with citations, team drives, and a searchable library of everything produced Ships
IW·08 — The Pilot Weeks, not quarters

One department. A small team of agents. Your own evidence.

A contained pilot in one department, with a clear decision point and nothing locked in either way.

01
See

A working session on your scenarios

An assignment, a sign-off, a budget cap tripping, an emergency stop — in one sitting.

02
Pilot

One department, a small team of agents

Success criteria agreed up front: approval quality, evidence completeness, cost per task.

03
Prove

A go/no-go in weeks, with the record as proof

Backed by your own record. Expand team by team, or stop — nothing stranded.

Your identity, audit, and risk teams review in parallel — the evidence record itself is the deliverable they assess, and a contained two-week pilot is the fastest path to conviction.

IW·09 — Questions Boards Ask Six questions

The six questions that come up first.

Short answers, no hedging.

Q·01

Can we stop it instantly — and prove it stopped?

Yes. A three-tier emergency stop pauses one agent, every copy of a role org-wide, or an entire department — reversibly, with in-flight work parked safely rather than destroyed. Every active pause is listed in the operations console with its scope, target, reason, and who raised it, and every stop and restart is recorded as an attributed event. A pause even applies to agents installed after it was raised.

Q·02

What happens if we revoke access in the middle of a task?

Authorization is checked continuously and shuts access off rather than letting it drift. A permission revoked mid-run is enforced at the very next action the agent attempts — not deferred to the next task — and the denial itself is written to the working file, so the record shows exactly when authority ended and what was refused after that moment.

Q·03

Can an agent show someone a document they could not open themselves?

No. What an agent may draw on is the intersection of its own grants and the requesting person’s own read rights, so it can never become a channel to material the requester could not see. A no-widening rule adds a second wall: an agent’s output can never land anywhere more readable than the knowledge the run was allowed to read.

Q·04

What exactly is on the record afterward?

Two layers. A permanent, tamper-evident record of every real-world action — what ran it, when, the outcome, and whether it can be undone — where an undo is a new entry referencing the original. And a complete, replayable working file for every run: which version executed, what it read with citations, and every step it took — kept beyond the day-to-day task history.

Q·05

How do upgrades avoid privilege creep?

Every install pins a specific version. When a new version would widen what an agent can do, the system computes exactly what widened and refuses to proceed without an explicit human re-approval. Rollback is a single step, and different departments can safely run different versions, so you can trial a new release in one team before it goes anywhere else.

Q·06

Are we locked into one AI model vendor?

No. Agents reference a class of model rather than a hard-wired provider, multiple vendors are supported today, and none of the controls — approvals, budgets, stops, the record — depend on which vendor is in use. You can change model suppliers without changing how the workforce is governed.

Question not on this list? Put it on the pilot agenda

The Bottom Line

Put one governed team of digital employees to work.

The constraint on scaling AI labor is no longer capability — it is governance. The company that can say every agent action is authorized, attributed, budgeted, approvable, traceable, and stoppable is the one that moves AI into revenue-facing work.

Fastest path to conviction: a scoped pilot in one department, success criteria agreed before day one, your own numbers in weeks.

One lit workstation at the head of a dark row — the first governed team of digital employees coming on shift.

Claims trace to the Iternal Workforce product briefings as of July 2026 · Instruments labeled illustrative are concepts, not product screenshots · In-product cost figures are estimates at configured rates, not billing-grade.