The CiBRAI Agentic Business Framework
Build teams of humans and agents. Design the work, the relationships and the authority together.
Human-agent collaboration is a business design decision.
Imagine introducing a brilliant new colleague to the business. They work quickly, never tire and can coordinate a dozen tasks before the morning meeting. Excellent. Now give them the customer database, the pricing model, the production console and permission to recruit assistants before anyone has agreed who manages them.
You would have questions. Quite possibly for the person who hired them.
This is the organisational problem behind the excitement about agentic AI. Software can now plan, use tools and coordinate work.[14] The business therefore needs to decide how people and agents will work together, what each contributes and where their authority ends.
The opportunity is a better team. People bring business judgement, relationships and responsibility. Agents can gather approved information, prepare options, challenge assumptions and coordinate permitted work. Neither needs every secret or every power to make a valuable contribution.
The person making the burgers does not need the secret sauce formula to serve lunch. Likewise, a sales agent can help prepare an offer without seeing every contract, and a research agent can support a security analyst without holding the keys to production.
A company organises expertise so that people can collaborate without any one role becoming the company. Its agentic architecture should do the same. Human judgement belongs throughout the workflow: defining the task, questioning the evidence, choosing the trade-off and learning from the result.
The business must decide what happens after access is granted.
A valid login cannot rescue a badly designed job. Identity tells us who is acting. The operating model determines why they are acting, what they need to know and which decisions belong to someone else.
McKinsey’s description of agents as digital insiders is useful.[12] An insider needs a place in the team, a defined remit and checks on conflicting powers. The risk is not limited to a rogue agent. A helpful agent pursuing a poorly framed objective can also carry a small mistake across several departments.
Distinct agent identities and constrained delegation support accountability. Shared credentials obscure it.[1]
The software connecting models to information and tools is a critical place to enforce business controls.[2]
Accountable people, bounded risk and practical oversight belong across the lifecycle.[4]
Current joint ASD guidance recommends agentic use only for low-risk, non-sensitive tasks.[3] The cyber examples here keep agent research within that scope. Sensitive evidence and consequential decisions remain in approved human-controlled processes. Removing names does not automatically make information non-sensitive. Human approval alone does not make a deployment suitable.
Anthropic’s insider-risk research used deliberately constructed simulations; its authors did not report those behaviours in real deployments.[7] Use such studies to design failure tests, not to invent a probability of an agent going rogue.
Six connected disciplines. One shared business outcome.
The CiBRAI Agentic Business Framework designs the mixed team through six connected disciplines. Each produces something a manager can inspect. If the framework cannot describe Monday morning’s work, it needs more work.
A shared outcome and role charters
Information and disclosure boundaries
Handover rules and feedback routes
Named people, roles and deputies
Delegations and independent approvals
Evidence, tests and rehearsed recovery
Figure 1CiBRAI’s framework puts collaboration at the centre. Each discipline applies to the people, agents and services contributing to the outcome.
Judgement, context and challenge need an explicit place in the team.
A human-agent team needs more than a supervisor at the end of a queue. People frame the problem, contribute domain knowledge, challenge weak evidence and remain answerable to those affected. Give that work time, authority and a place in the design.
Use the smallest team that does the job well, with role-specific procedures, worked examples and supervised practice. Different prompts or model names do not establish separation of duties. Permissions, evidence and control ownership must support the distinction.[8]
Define success, prohibited shortcuts and handovers.
Test ambiguity, misleading sources and refusal.
Assess the complete workflow and review effort.
Re-test after material changes. Expand only on evidence.
Figure 2Clear contributions, followed by shared practice. Qualify the deployed workflow, not just the model.
People and agents need clear requests, useful evidence and a route back.
A handover is where one role’s work becomes another role’s decision. Make it a working agreement: what is being requested, what evidence travels with it, what remains uncertain and who must respond. A confident paragraph is not a complete decision brief.
Insufficient evidence returns to preparation.
What decision or task needs help?
Original sources and contradictory findings.
The proposed action and alternatives.
What is missing or could change the answer?
Affected people, assets and commitments.
Named recipient, exact scope and expiry.
When evidence is weak, return to preparation. When the proposed action changes, return for approval. When the responsible person is unavailable, pause or follow the pre-authorised fallback. Feedback improves the procedure through approved change; it does not let an agent promote itself.
Figure 3The shared work loop. Consequential actions still require the independent approvals and enforced limits described under Who holds the second key?
A completed team charter for public threat-research support.
Use these fields before a pilot. The filled example is a public threat-research support team for a security operations centre. Replace the role titles with named people and deputies when applying it.
| Charter field | Worked cyber operations example |
|---|---|
| Shared outcome | An evidence-linked threat brief that saves analyst research time without reducing decision quality. |
| People and agents | SOC manager owns; duty analyst directs and challenges; incident commander decides response. Research and challenge agents prepare the brief. |
| Permitted knowledge | Approved public advisories and assessed non-sensitive questions. Raw case records, credentials and production telemetry stay outside this role. |
| Permitted work | Retrieve approved sources, compare findings and draft in the designated workspace. No production changes, external contact or case closure. |
| Handover | Question, findings, original links, contradictions, unresolved issues and named human recipient. The analyst accepts, returns or rejects the brief. |
| Decision rights | Agents cannot authorise response. The incident commander and any required separate authority decide through the established process. |
| Operating limits | Approved tools and recipients; explicit time, query and cost caps; only pre-approved worker roles. Delegation cannot widen authority. |
| Stop and fallback | The duty supervisor can suspend all workers and pending work. Any analyst can request a stop. Human research continues through the documented procedure. |
| Qualification | Rehearse poisoned sources, missing evidence, unavailable approvers and failed services. Reassess material model, tool or role changes. |
| Evidence of value | Baseline analyst time; measure accepted briefs, source accuracy, rework and supervision. Protect activity and approval records under the agreed retention rules. |
Use the same fields for another workflow. The example illustrates a role design; it is not a specification of product configuration.
Useful collaboration does not require universal visibility.
The secret sauce can stay in the kitchen. The team still gets lunch out. Sales needs a permitted offer, operations confirms feasible delivery and finance checks that the deal meets policy. Each specialist can contribute without emptying the filing cabinet onto the meeting table.
Design controlled answers, not universal visibility. A coordinator should know where work belongs and whether it is progressing. It does not need every department’s raw information or credentials. Consider what repeated questions can reveal when their answers are combined.
An authorised person or service protects the underlying records.
Purpose, recipient and disclosure are checked before release.
Receives only the permitted answer, then prepares bounded work.
Restrictions must follow information into prompts, summaries and memory. Moving it into another format must not quietly widen who can see it, what they may use it for or where it may go. External material is evidence to assess, not permission to change the task. NCSC’s prompt-injection guidance reinforces the need for controls outside the model.[6]
Release only approved, purpose-limited information.
Check recipient, permitted use and what the answer reveals.
Control retention, access and removal of tainted material.
Figure 4Boundaries follow information through retrieval, handover and memory. Any answer released to an agent must meet the approved use-case scope.
Independent authority must have the practical power to refuse.
The second key must belong to an independent authority with enough information, time and power to refuse. For material operations, separate proposing, approving and executing. Where policy requires dual authorisation, show both people and the different responsibility each carries.
An execution gate is a control, not a second business decision-maker. It verifies that the required people approved this exact action within its scope and expiry. The agent cannot supply, alter or bypass those approvals. A changed target or materially changed plan goes back for review.
Figure 5A dual-human-authority pattern for consequential work where policy requires it. The gate enforces the decision; it does not replace either person. Refusal, missing approval or expiry blocks execution.
Two agents can usefully challenge a proposal. Their agreement does not establish independent authority, particularly when they share the same powers or rely on the same flawed evidence. A human relying entirely on the proposing agent’s summary can fail in the same way. Independent access to original evidence is part of the job.
Agents accelerate research. People own the consequences.
Security operations is where the team model becomes tangible. An agent prepares a public threat brief. A human analyst tests its relevance against authorised case evidence. The incident commander weighs business impact. A controlled response process executes the approved action. Independent review checks what actually happened.
The collaboration is the capability. Each participant contributes something different, and the handovers preserve the boundaries between investigation, decision, action and review. Keep the research role within the deployment scope described above.
Now give the team a malicious document that asks the research agent to disable monitoring. Does that request reach an operator as an instruction, or does the next boundary reject it? OWASP’s agentic threat guidance covers goal hijacking, tool misuse, poisoned memory and cascading failures.[5] Test the whole team, not just each agent.
A public-research support pattern with human-controlled response.
Read down through five stages. The lanes show who contributes, who decides and who preserves evidence independently of the actor.
| Stage | Human team | Agent team | Execution controls | Independent evidence |
|---|---|---|---|---|
| 1 Brief | Analyst defines the approved question; retains sensitive evidence. | Coordinator assigns permitted research tasks. | Tools, sources and delegation are bounded. | Record task, owner and configuration. |
| 2 Investigate | Analyst checks original evidence and challenges relevance. | Researcher and challenger return sources, findings and gaps. | Handover checks preserve information limits. | Retain source references and observable actions. |
| 3 Decide | Commander selects response; separate service authority approves where required. | Supplies the approved public research brief; cannot authorise response. | Bind approval to action, target, limits and expiry. | Record authorities and the approved action version. |
| 4 Execute | Authorised operator initiates the exact approved action. | No production privileges in this example. | Validate authority. Block missing or changed approvals. | Capture actual changes outside the actor’s control. |
| 5 Verify | Reviewer confirms outcome; owner approves lessons and changes. | Drafts lessons from approved non-sensitive feedback. | Support containment, restoration and manual fallback. | Reconcile intended and actual outcomes before closure. |
Figure 6Stop or escalate at any stage. The agent role has no production privileges and no authority to approve its own response or close the incident.
A coordinated offer does not need one all-powerful coordinator.
Ask an agent to win a sale and it may be very good at finding ways to win the sale. The business still needs someone to decide which concessions, promises and disclosures it can afford.
A mixed team can move faster without giving the coordinator the combined powers of sales, finance and operations. Let the agent prepare public research and organise requests. Let each department return a bounded contribution through its authorised people or services. The account owner owns the final commitment.
Controls customer context and the offer being proposed.
Confirms the delivery commitment the business can meet.
Checks the proposal against commercial policy.
Figure 7Each department contributes a bounded answer through its authorised people or services. The agent does not inherit departmental data or decision rights.
Sensitive commercial information stays within the authorised human workflow. Any result returned to an agent must itself be assessed as non-sensitive. For supplier payments, separate research, beneficiary verification, master-data change and payment release. A persuasive message does not verify a bank account. Use independently trusted evidence and the existing finance controls.
Measure useful work, constructive challenge and the ability to recover.
| Measure | Practical indicator |
|---|---|
| Useful work | Accepted outputs without material rework / outputs reviewed. |
| Human effort | Minutes per accepted outcome, including checking and correction, against the baseline. |
| Handover quality | Required fields present, with sampled checks of source accuracy. |
| Challenge quality | Seeded defective recommendations rejected; track false rejections separately. |
| Control response | Time to stop all workers and pending actions; correct pause and escalation in drills. |
Figure 8Feedback can improve the team without letting agents rewrite their own remit, controls or memory policy.
Protect the evidence independently of the actor. A stop must reach workers, credentials, queues and retries. Preserve evidence, contain harm and reconcile unfinished work before restarting. Some disclosures cannot be undone; recovery also means correction and consequence management.
Choose a useful workflow. Prove the operating model before expanding it.
Choose one useful, low-risk workflow. Name the people and agent roles. Complete the charter and establish the value baseline.
Test the shared workflow, handovers, refusals and fallback. Train supervisors to challenge evidence and manage exceptions.
Run an approved, observed pilot. Measure value and human effort. Practise stopping and restoring the whole operation.
Ninety days is a planning horizon, not a readiness promise. Expansion requires a fresh decision. Ask suppliers to demonstrate refusal, revoked access and recovery using your workflow. A successful task demonstration is only the beginning of the conversation.
Which decisions and consequences will we delegate?
Can the design work across our applications and suppliers?
Will one compromised role remain contained and leave reliable evidence?
Figure 9Joint decisions for the CEO, CIO and CISO. Progress on evidence; a decision to narrow or retire a use case is a valid result.
Start with a real workflow and the people responsible for it.
The competitive advantage is a team that can combine speed with judgement. Agents can reduce the effort spent on preparation and coordination. People supply context, relationships and responsibility. Good architecture gives both room to contribute while keeping authority clear.
Before adding another agent, draw the team it will join. Show the people, the handovers, the information boundaries and the decisions nobody should make alone. If you cannot point to who owns the outcome, the design is unfinished.
CiBRAI implements the CiBRAI Agentic Business Framework as a core part of its cybersecurity operating platform and the way we design human-agent security operations.
Bring one real workflow to the table. Include the business owner, the people doing the work, technology and security. Use the team charter to find the gaps together. If a second perspective would help, CiBRAI welcomes a practical conversation about applying the framework to your business or security operation.
Prefer to read offline? Download the whitepaper (PDF, 1.2 MB)
The next great organisation chart will include software.
The responsibility at the top will still be human.
Selected guidance, research and executive commentary. Reviewed 24 September 2026.
References distinguish external evidence from CiBRAI’s framework and illustrative workflows. The diagrams express a proposed operating design, not a certification scheme or proof that every deployment is suitable.
Andrew Curtis is a CISO and the founder of CiBRAI, with more than 20 years of experience across enterprise and government cyber security, architecture, governance and uplift programs. Meet the CiBRAI leadership team.
The examples are reference workflows. Live use requires approved scope, risk assessment, tested controls and compliance with the organisation’s obligations. The framework does not replace that decision. Current deployment guidance is stated under Why the operating model matters.
Original framework and editorial content: Andrew Curtis / CiBRAI. Conceptual artwork was created with OpenAI image generation using two briefs: a mixed business team collaborating around a shared task; and a human-led security team reviewing evidence with agent support. The artwork is illustrative, not a product screenshot. Control diagrams are separately authored.
© 2026 CiBRAI. Enhanced edition, version 1.1. Quotations may be attributed to Andrew Curtis, CISO, CiBRAI.