Iternal Product Line — Managed AI Workforce Sponsored · Supervised · Stoppable
Iternal Workforce

A digital workforce your company can actually trust. Governed like employees. Provable like software.

AI agents that research, produce, and act for your teams — every action approved where it matters, attributed to a person, budgeted, and stoppable.

Run day to day by your managers, in plain language — not by engineers.

The Offer A scoped pilot in one department, success criteria agreed before day one, that produces your own numbers on capacity, trust, and cost. A go/no-go in weeks, not quarters.
Every action
Attributed to agent + human
Default
Human sign-off on real-world actions
3
Emergency-stop tiers
Zero
Shared or borrowed credentials
IW·01 — The Side Door The governance gap

Your people have identity, least privilege, and an offboarding process. Your AI labor has none of it.

AI labor is arriving faster than the controls to run it — through the side door.

A grand governed front gate stands closed while a thin thread slips in through a small side door — ungoverned AI agents entering the enterprise unmanaged.

Every function already wants agents — sales wants pipeline research, finance wants reconciliations, support wants first-draft replies, operations wants the repetitive work off its desk. The demand is not the problem. The demand is here.

The problem is the agents arriving to meet it. They have the security posture of a hackathon project: a borrowed login, whatever permissions that credential happens to carry, no record of what they did, and no way to stop them once they are running. That is a liability wearing a productivity costume — and the more useful it is, the faster it spreads before anyone governs it.

The uncomfortable part is that the agent often works. It drafts the document, files the report, touches the outside system — and because it produces value, nobody asks who authorized it, what it was allowed to see, what it cost, or how to stop it. The question gets deferred until it is an incident review instead of a design decision.

Scroll the standard sideways

The hiring standard you already enforce — and where AI labor falls short of it
Governance control Your employees Ungoverned AI agents today
Identity A unique, revocable identity per person A shared key or a borrowed human login, indistinguishable across holders
Permissioning Least privilege, scoped to the role and reviewed Whatever the credential happens to carry — often far more than the task needs
Change control Release discipline for anything that changes behavior Silent edits to behavior and permissions, with no versioning and no record
Audit An attributable record of who did what, when No durable record of which agent acted, on whose behalf, or why
Emergency stop Offboarding cuts off access immediately No switch — the agent runs until someone finds and pulls the plug

Agents multiply faster than employees ever did, and they act at machine speed. At any real adoption, ungoverned agents are the audit finding you could see coming.

IW·02 — A Managed Workforce Roles · installs · sponsors

Define the role once. Install it as a digital employee.

This is not a chatbot. This is not a copilot. This is a managed workforce.

You define a role once — how it works and what it is allowed to touch — then install it into a department as a digital employee with a named human sponsor accountable for it from the first day it runs, a pinned version, an explicit access ceiling, a defined knowledge scope, and a set of supervised duties. From there your managers run it the way they run people: assign work in plain language, monitor it, review what it produces, and approve anything consequential.

A digital employee is assembled from the same agentic AI parts every team is now experimenting with — a model, a set of tools, memory and a plan — with the role definition, the access ceiling and the named sponsor wrapped around them.

An org chart as a hanging mobile — solid navy blocks above hold translucent worker blocks on taut lines, one lit: every digital employee hangs under an accountable human.
01

Its own badge

Each agent is its own identity, never a borrowed login — and never more than it and the requester both hold.

02

One door to the outside world

Everything consequential passes a single gate that checks, authorizes, records, and executes — one place to govern.

03

A permanent file, not a chat history

Every run leaves a replayable working file; every real-world action lands on a permanent record.

Iternal Workforce is the management layer of Iternal’s agentic suite — it pairs with Ultramemory for shared memory, the Agent Skills Library, AgentAuth, and Ultracache, each adoptable on its own.

IW·03 — The Working Day Read · produce · act

Assign in plain language. Supervise by exception.

Your managers run agents the way they run people — assign, monitor, review, approve.

01

Read

Consume knowledge: answers grounded in your own documents, with citations — receipts, not recollections.

02

Produce

Create work products, filed in a searchable library and reusable as sources for the next task.

03

Act

Touch the outside world — waits for a human sign-off by default, with the exact draft shown.

The approver sees the exact draft, and whether the action can be undone. A denial is an answer the agent continues from — not a crash.

Fully unsupervised real-world action is not a setting that exists — it cannot be switched on.

A document held by a precision armature above a closed gate slot, its seal glowing — a real-world action suspended until a human signs off.
The authority funnel Illustrative
01 Platform capability set
02 Release declaration
03 Install grants
04 Per-action policy
05 Human approval

Nothing widens on the way down.

Anything not explicitly granted is off — never silently available.

Duties are drawn from a closed, platform-maintained list, and the risk grade of each duty is set by the platform, not by whoever authored the agent.

The desk leads with what needs a human

The operations view puts approvals waiting, exceptions, and the decisions only a person should make first — so managers supervise by exception, not by babysitting a chat window.

It is one governed path whether a person assigns the work, a schedule fires, or another agent hands off. The shapes those hand-offs take when several roles cover one function are set out in the orchestration patterns.

IW·04 — Command and Control Three stop tiers

Stop the work. Cap the spend. Prove both.

Governance is only real if you can stop the work, cap the spend, and prove both.

Three breaker levers of increasing size on a navy control panel, the smallest thrown — the three-tier emergency stop: one agent, a whole role, an entire department.

A budget breach trips the same stop machinery automatically — and re-trips while spend still exceeds the cap.

Automatic brakes on runaway work — depth, retries, and a hard iteration ceiling — trip it too.

Scroll the matrix sideways

The control matrix — scope, default posture, and the evidence each control produces
Control Scope Default posture Evidence produced
Human approval Per agent, per duty Sign-off required for real-world actions Dual-attributed decision record
Emergency stop Agent / role / department Reversible — park, not kill Attributed stop events
Spending caps Agent or department Automatic pause on breach Cap events + usage record
Automatic brakes Depth, retries, iterations Automatic Attributed trips
Upgrade re-consent Per install Required when capability widens Grant record
Revocation Any grant Takes effect at the next action Denial on the record

Every level of the operation is metered, with hard caps that pause the work automatically when a limit is hit. The AI bill becomes a dashboard, not a quarter-end surprise — attributable to the team and the task that spent it.

IW·05 — The Personnel Record Evidence, not assertion

Not a chat history. A permanent file.

Every digital employee has a file — permanent, attributed, and replayable.

An archive drawer open with one bound file stitched through by a single thread — every digital employee’s actions bound into one permanent, attributed record.

Append-only, tamper-evident

Every real-world action is recorded with its outcome and whether it can be undone; an undo is a new entry.

The record is the gate

Logging happens where the action is authorized — nothing can act while dodging the record.

Dual attribution, always

Every action names the acting agent and the person it acted for; delegation chains are auditable hop by hop.

Revocation lands mid-task

Access revoked mid-run is enforced at the very next action, and the denial is on the record.

An agent’s output can never land somewhere more readable than the knowledge the run was allowed to read.

Behavior ships like software

01

Sealed releases

Behavior ships as sealed, numbered versions; records prove exactly which version did any piece of work.

02

Tested at the gate

Test verdicts are recorded on the exact release and shown at activation. Advisory today; hard enforcement is a configuration switch.

03

No silent upgrades

A version that widens capability computes exactly what widened and waits for an explicit human re-grant; rollback is one step.

04

Offboarding that sticks

Retiring an agent cancels open work and revokes access immediately — while keeping its full history.

IW·06 — Headcount Economics Capacity · trust · cost

What the board actually asks about. All six answers.

Six outcomes, each tied to a lever you already own — the terms the board thinks in.

01

Capacity

Recurring schedules and hand-off chains keep repetitive work on a 24×7×365 cadence — throughput without headcount.

02

Trust

Real-world actions wait for sign-off; the approver sees the exact draft; every decision lands on the record.

03

Cost

Usage is metered everywhere, with hard caps that pause work automatically — a dashboard, not a quarter-end surprise.

04

Speed

Drop a document into a team drive and every agent there uses it on its next task.

05

A compounding asset

Every deliverable is filed, cited, and searchable — institutional knowledge accumulates instead of evaporating.

06

Readiness

Versioned behavior, test verdicts at activation, one-step rollback, complete evidence — in place before anyone asks.

Cancelled and failed work still counts, so there are no blind spots. Cost estimates are chargeback-ready at configured rates — always estimates, never billing-grade.

IW·07 — Roles by Function Five functions

Digital employees by function — customer service, HR, sales, marketing, finance.

An AI customer service agent is a digital employee that reads your support history and product documentation, drafts the reply with citations, and holds it at an approval gate until a named human signs it off. The same governed pattern covers HR, sales, marketing and finance roles: assigned work, enforced budgets, and a permanent record.

F·01

Customer service and support

An AI customer service agent here is a digital employee assigned to a queue. It reads the ticket history and the product documentation it has been granted, drafts the reply with citations back to the source, and marks the cases a person should take. Drafting is a produce duty; anything that leaves the company is an act, so it waits at the approval gate. Where the front line is a conversational surface rather than a queue, the build path is AI chatbots for customer service. Size the economics with the AI Customer Service Cost Reduction Calculator, or the IT Help Desk Deflection Calculator for internal support queues.

Governed example

A queue owner signs off a refund response. The approved reply is filed as a governed draft against the ticket, with the policy clauses it cited and the cost of the run on the record. The payback case for customer service automation is worth modeling before the first queue goes live.

What does an AI customer service agent do that a saved reply template does not?

It reads the ticket, the account history and the product documentation it has been granted, then drafts a reply with citations back to the sources it used. A queue owner approves the draft and the decision record carries both names, the cost of the run is metered against the team’s cap, and the reply, its sources and its approval stay on the permanent record.

F·02

Human resources

In HR the constraint is confidentiality rather than drafting. A digital employee answers policy questions from the handbook and benefits documents with citations, assembles onboarding material, and prepares first drafts of role descriptions and review summaries. Authority is the intersection of the agent’s grants and the asking employee’s own read rights, so an agent can never become a channel to a file the person could not open themselves.

Governed example

A people-operations sponsor reviews a compensation-letter draft before anything is filed, and the run’s working file shows every document the agent read to produce it.

Can a digital employee working in HR reach personnel files it should not?

No. Its knowledge scope is declared at install, and the no-widening rule means an agent’s output can never land somewhere more readable than the material the run was allowed to read. A grant revoked mid-task is enforced at the very next action the agent attempts, and the denial itself is written into the working file.

F·03

Sales

Sales teams run digital employees as researchers and preparers: account briefs before a renewal call, competitive and pricing summaries drawn from your own approved material, CRM tidy-ups staged for review, and proposal first drafts. Outbound messages follow the same rule as every other real-world action — they wait for the named owner’s sign-off rather than going out on the agent’s own authority.

Governed example

A Research Analyst role compiles an account brief the morning of a renewal call — sources cited, a hard budget on the run, and the record showing exactly what it read.

How do we keep a digital employee in sales from acting on its own?

Duties are graded read, produce and act, and the risk grade of each duty is set by the platform rather than by whoever authored the role. Fully unsupervised real-world action is not a setting that exists. Spending caps run per agent or per department and pause the work automatically when a limit is hit.

F·04

Marketing

Marketing uses the workforce for volume work that still has to be on-message: campaign briefs, first drafts built from approved positioning, competitive summaries, and repurposing one asset across formats. Answers are grounded in your own library with citations, so every claim can be traced back to the document it came from before anyone publishes it.

Governed example

A content role drafts a launch brief from the approved messaging kit; the marketing sponsor approves it, and the approved draft joins the searchable library of everything the workforce has produced.

How do we stop a digital employee in marketing inventing claims?

It answers from the documents you grant it and cites them, and every run keeps a replayable working file showing which version executed and what it read. The reviewer sees the exact draft and its sources at the approval gate, so an unsupported claim is caught before publication rather than after it.

F·05

Finance

Finance is the function with the most repeatable, evidence-heavy work and the least tolerance for an unexplained action: invoice preparation, month-end close packs, reconciliation, variance commentary for FP&A, and audit evidence. Every run is approvable, budgeted and recorded, which is the same list a controller reads out. The finance desk below sets out the jobs, the controls and the numbers.

Governed example

An accounts-payable role prepares a matched invoice batch with the exceptions listed and each line cited; the posting into your finance system stays a human step, and anything above the approval threshold goes to a second reviewer.

What can AI agents for finance take off the team’s desk?

Invoice preparation and matching, month-end close packs, account reconciliation, variance commentary for planning and analysis, and audit evidence packs — the repeatable, evidence-heavy work. Judgment stays with the team: approvals above threshold, accounting treatment, and anything that changes the ledger. At a Top 10 global professional services firm, Iternal’s finance back-office work cut routine tasks by 68% and took month-end close from 12 days to 5.

A role is authored once and installed per department, so the same governed pattern covers a function this grid does not name. For roles built to a process of your own, see AI agent development services.

IW·08 — The Finance Desk The function, not the industry

AI agents for finance: the close, the ledger, and the audit trail.

AI agents for finance are governed digital employees that take the repeatable work of the finance function: invoice preparation and matching, month-end close packs, account reconciliation, variance commentary for FP&A, and audit evidence. Each one runs under segregation of duties, an approval threshold, a hard budget, and an immutable record of every action.

Scroll the desk sideways

The finance jobs a governed digital employee can hold — and what stays with a person
Finance job What the digital employee produces What stays with a person
Accounts payable and receivable Reads the invoice and the supporting documents it has been granted, prepares the matched batch with every exception listed, and cites the source of each line. The capture, matching and posting mechanics themselves are walked through in manual report prep, close and quoting. The posting into your finance system, and any approval above the threshold you set.
Month-end close Assembles the close pack — checklist status, open items and the supporting schedules — each line citing the document it was read from. Sign-off on the close, and the accounting treatment of anything unusual.
Account reconciliation Compares the two records it has been granted, produces the reconciliation with differences itemised, and flags what it could not resolve rather than guessing. Judgment on unresolved differences, and every write-off decision.
FP&A variance analysis Produces variance commentary against plan with each figure traced back to the report it came from, ready for review the day the numbers land. The narrative that goes to the board, and any change to the forecast.
Audit preparation Collects the evidence an auditor asks for and produces the pack with citations; its own permanent record already shows what ran, when, and whether it can be undone. What is submitted to the auditor, and the representations made with it.

The controls a controller asks for first

Segregation of duties

An agent’s authority is the intersection of its own grants and the requester’s own read rights, and the person who approves an action is recorded separately from the agent that produced it — the decision record is dual-attributed.

Approval thresholds

Real-world actions wait for sign-off with the exact draft in front of the approver, and spending caps set per agent or per department pause the work automatically the moment a limit is hit.

An immutable audit trail

Every action lands in a permanent, tamper-evident record with whether it can be undone; an undo is a new entry referencing the original, never an edit. Each run also keeps a replayable working file.

A declared knowledge scope

What a finance agent may read is declared at install, and its output can never land somewhere more readable than the material the run was allowed to read. Where the ledger cannot leave your environment at all, the same work runs on AirgapAI, which operates fully offline.

What this looked like in production

A Top 10 global professional services firm ran its finance back office this way across 140 countries and 45 currencies: routine finance tasks down 68%, month-end close from 12 days to 5, and roughly 850 hours a year back per analyst — with the financial data staying offline throughout. The detail is in the finance back-office invoice processing case study, and the controllers and analysts who supervise these runs get up to speed through AI training for finance teams.

Finance here means the function — the controller’s org, its close and its ledger. For banks, insurers and asset managers, the industry view is on AI for financial services. To put the first finance role under supervision, start with the pilot.

IW·09 — What Ships Today 12 shipping today

What is running now — and exercisable in your pilot.

12 lines from the register — every one shipping today and exercisable in your own pilot, stated plainly.

Scroll the register sideways for status

Iternal Workforce capability register
RefCapabilityStatus
01 Roles authored once; behavior ships as sealed, numbered releases you can prove did the work Ships
02 Test suites recorded on the exact release, with a pass/fail verdict at activation — advisory today; hard enforcement is a configuration switch Ships
03 Every install sponsor-bound and pinned; upgrades that widen capability require re-approval; rollback is one step Ships
04 Each agent its own identity; authority is the intersection of agent and requester; revoked access stops at the next action Ships
05 Duties graded read / produce / act; real-world actions wait for sign-off, with the exact draft shown to the approver Ships
06 One gate for everything external; a retried or replayed action never fires twice and never double-logs Ships
07 A permanent, tamper-evident record of every action, with whether it can be undone, plus a replayable working file per run Ships
08 Three-tier emergency stop, with a console listing every active pause and who raised it Ships
09 Enforced spending caps and automatic brakes on runaway work — both trip the pause machinery Ships
10 Full usage metering with team and trend views, and chargeback-ready cost estimates Ships
11 Recurring schedules and multi-agent relay chains on the same governed path Ships
12 Answers grounded in your own documents with citations, team drives, and a searchable library of everything produced Ships
IW·10 — The Pilot Weeks, not quarters

One department. A small team of agents. Your own evidence.

A contained pilot in one department, with a clear decision point and nothing locked in either way.

01
See

A working session on your scenarios

An assignment, a sign-off, a budget cap tripping, an emergency stop — in one sitting.

02
Pilot

One department, a small team of agents

Success criteria agreed up front: approval quality, evidence completeness, cost per task.

03
Prove

A go/no-go in weeks, with the record as proof

Backed by your own record. Expand team by team, or stop — nothing stranded.

Your identity, audit, and risk teams review in parallel — the evidence record itself is the deliverable they assess, and a contained two-week pilot is the fastest path to conviction.

IW·11 — Questions Boards Ask Six questions

The six questions that come up first.

Short answers, no hedging.

Q·01

Can we stop it instantly — and prove it stopped?

Yes. A three-tier emergency stop pauses one agent, every copy of a role org-wide, or an entire department — reversibly, with in-flight work parked safely rather than destroyed. Every active pause is listed in the operations console with its scope, target, reason, and who raised it, and every stop and restart is recorded as an attributed event. A pause even applies to agents installed after it was raised.

Q·02

What happens if we revoke access in the middle of a task?

Authorization is checked continuously and shuts access off rather than letting it drift. A permission revoked mid-run is enforced at the very next action the agent attempts — not deferred to the next task — and the denial itself is written to the working file, so the record shows exactly when authority ended and what was refused after that moment.

Q·03

Can an agent show someone a document they could not open themselves?

No. What an agent may draw on is the intersection of its own grants and the requesting person’s own read rights, so it can never become a channel to material the requester could not see. A no-widening rule adds a second wall: an agent’s output can never land anywhere more readable than the knowledge the run was allowed to read.

Q·04

What exactly is on the record afterward?

Two layers. A permanent, tamper-evident record of every real-world action — what ran it, when, the outcome, and whether it can be undone — where an undo is a new entry referencing the original. And a complete, replayable working file for every run: which version executed, what it read with citations, and every step it took — kept beyond the day-to-day task history.

Q·05

How do upgrades avoid privilege creep?

Every install pins a specific version. When a new version would widen what an agent can do, the system computes exactly what widened and refuses to proceed without an explicit human re-approval. Rollback is a single step, and different departments can safely run different versions, so you can trial a new release in one team before it goes anywhere else.

Q·06

Are we locked into one AI model vendor?

No. Agents reference a class of model rather than a hard-wired provider, multiple vendors are supported today, and none of the controls — approvals, budgets, stops, the record — depend on which vendor is in use. You can change model suppliers without changing how the workforce is governed.

Question not on this list? Put it on the pilot agenda

The Bottom Line

Put one governed team of digital employees to work.

The constraint on scaling AI labor is no longer capability — it is governance. The company that can say every agent action is authorized, attributed, budgeted, approvable, traceable, and stoppable is the one that moves AI into revenue-facing work.

Fastest path to conviction: a scoped pilot in one department, success criteria agreed before day one, your own numbers in weeks.

One lit workstation at the head of a dark row — the first governed team of digital employees coming on shift.

Claims trace to the Iternal Workforce product briefings as of July 2026 · Instruments labeled illustrative are concepts, not product screenshots · In-product cost figures are estimates at configured rates, not billing-grade.