Its role
ScopeThe job it holds, and just as importantly the jobs it does not. An agent without a bounded role becomes a general-purpose assistant wandering the business.
The agent is not the product.
Most organisations are still framing the opportunity too narrowly. Can we build an agent. Can it answer questions. Can it automate a task. Can it connect to our systems. Those are useful questions. They are not the decisive ones.
A correction
In essay 002 we argued that the enterprise battleground was the control plane: registries, gateways, identity, policy enforcement, observability. That was right, and the major platforms have since moved exactly there.
It does not go far enough. A control plane governs what an agent is permitted to do. It says nothing about whether the agent should exist, who answers for it on a bad day, or how it gets better without quietly drifting.
They need more than a control plane. They need an operating system.
The definition
It is part of a wider system, and that system has to answer three questions before the agent touches anything that matters: what it is, what it may touch, and what it leaves behind.
The job it holds, and just as importantly the jobs it does not. An agent without a bounded role becomes a general-purpose assistant wandering the business.
What it may settle alone and what it may only prepare. We set out the full ladder in essay 003.
A named human who answers for it in production. Not a committee, not the vendor, not the team that built it and moved on.
Which systems and records are in scope, which are closed, and what happens at the edge of that boundary rather than in the middle of it.
What it can actually operate. Read access and write access are different risks and should never be granted in the same motion.
The specific actions that stop and wait. Designed in from the start, not bolted on after something goes wrong.
Where a question goes when the agent cannot resolve it. An agent with no escalation path will guess, confidently.
What it saw, what it recommended, what it changed, what it cost. Enough to replay a decision months later and defend it.
How it gets better from production evidence without drifting away from the behaviour it was approved for.
Without it
Different teams build different agents. Permissions are granted inconsistently. Memory and state become unclear. Actions are hard to audit. Risk ownership is vague. Nobody has a reliable view of what the agent estate is actually doing. That is the sprawl essay 002 described, and it arrives faster than most boards expect.
That is not transformation. That is uncontrolled automation with better branding.
Where to start
Essay 003 set out what every AI-enabled workflow needs. This is the order to build it in. The important number is the first one, because a programme that starts everywhere finishes nowhere.
Consequential is the operative word. A workflow nobody cares about will prove nothing when it works, and cost nothing when it fails. Pick the one where a measurable improvement would be noticed by the board, and where a mistake would be noticed by a customer. That tension is what forces the operating system to be real.
That is how AI moves from demo to capability.
Where Praxis stands
Our view is simple. Enterprise agents need a governed operating system that defines how they are deployed, authorised, observed, improved and held accountable for real work. Not a platform decision. An operating decision, made once per workflow and revisited as the estate grows.
The agent is only the visible surface. The operating system is where the value, trust and scale will come from.
Begin
One conversation, no pitch deck. Bring the workflow that matters most, and we will scope the operating system around it.