Policy over prompt
What an agent may do is decided by a versioned policy before execution. Prompts can explain rules, but they cannot grant capabilities. Unknown actions fail closed.
AI & Agents
Assistant systems, agents and MCP integrations for companies that want more than a demo: traceable decisions, explicit approvals and, where needed, fully local, with no data leaving the building.
No slide-deck consulting. I build and run these systems myself, every day, on my own data.
Think first, prompt second
The fastest way to burn money with AI: unleash an agent armada on a problem a clean workflow would have solved. The second fastest: do nothing out of scepticism. I work with a simple escalation ladder where every step has to prove itself against the simpler one.
Complexity is not a feature. It has to be earned. And with the right requirements, it is.
The false analogy
Human companies are organised hierarchically because humans have human limits: nobody can know everything, attention is scarce, responsibility has to be distributed. An LLM does not have these problems. It has different ones: limited context, errors that compound, no state of its own between steps. Rebuild a company out of agents anyway and you solve problems that do not exist while creating ones that did not exist before.
01
CEO agent, managers, departments: the structure feels familiar, so it feels right.
02
Every line is a handover in prose. Context gets lost, errors travel along, and every station costs tokens and latency.
03
Away with the role-played hierarchy. An LLM does not need colleagues, it needs clear conditions.
04
Deterministic code orchestrates. Specialists work in parallel, each with its own context, without a shared group chat.
05
Tests, schemas and policies verify the result. What passes is adopted, with a receipt.
coordination without information gain
Humans need hierarchy because knowledge and responsibility have to be distributed. An agent system needs the opposite: few, sharply cut tasks, explicit state and checks that are not negotiable. Parallel specialists have their place, but as tools with an assignment, not as colleagues with a calendar.
Control is the feature
The question is never whether a model can do impressive things. The question is what happens when it gets it wrong. That is why I build agent systems on principles enforced in code, not in prompts:
What an agent may do is decided by a versioned policy before execution. Prompts can explain rules, but they cannot grant capabilities. Unknown actions fail closed.
Every action leaves a receipt. Reversible work stays undoable for days; deletions go through quarantine with a waiting period and a restore point.
Sending mail, moving money, changing infrastructure: an agent can propose such actions but never trigger them itself. Approval stays with a human.
What a model may see is decided before the prompt exists. Deny by default: unapproved data never reaches the LLM in the first place.
How serious is that? In my own agent system an entire LLM integration is disabled until it can be sandboxed as provably as the others. Switching a feature off because the sandbox is not tight enough yet is inconvenient. It is also exactly why you can trust the system.
What I offer
Assistance, classification, content generation and vision inside your product or internal system, with cost control, fallbacks and guardrails.
Agents that work with your real systems: custom MCP servers for your data and tools, orchestration, approval workflows and an audit trail.
When data must not leave the building: local models on your own hardware, local vector search, local speech processing. Cloud only where you decide.
In production
Warning rules, decision logic and AI assistance in the production CRM of an international brand, embedded in existing processes, not next to them.
Seating-plan recognition from photo or PDF, image generation, SEO copy and translations into seven languages, a shop assistant with guardrails. With an included quota instead of bring-your-own-key.
From the lab
An assistant with full access to mail, projects, calendar and knowledge. Possible because everything runs on my own hardware and nothing leaves the machine. Not a product but my lab: this is where the patterns are born that go into client systems after proving themselves in daily use.
Code review · QA · Security · Architecture · Debugging · Requirements · Documentation · Root-cause analysis
Runs daily on real client and project data, precisely because it stays local.

Sharing the knowledge
60 minutes of fundamentals for teams without ML background: what AI can do, where it fails, and a checklist for responsible use.
Why more agents rarely mean more results: the minimum reliable agent loop and the escalation ladder before adding roles.
A live demo of what agentic work actually looks like in day-to-day development: verification instead of circus.
New guide
An EU-wide practical guide for businesses, with fictional image examples, checklist, AI literacy and official sources.
The entry point
We walk through your processes and you get a prioritised list of concrete AI use cases: with an honest assessment of where AI is the wrong tool, a cloud-versus-local recommendation including GDPR implications, and an implementation plan with estimates. Fixed price, clear deliverable, no subscription.
If nothing is worth it, the report will say exactly that.