Secure agents
An AI agent over your project records, without the risk
Your project history already contains the answer to most questions your team asks. It is spread across SharePoint, a CDE, twelve email chains and somebody’s folder. An agent can find it in seconds. The reason most contractors have not built one is not capability, it is that nobody has explained how it stays safe.
So that is what this page is about, and the capability comes second.
The five rules it is built on
It inherits your permissions, it does not replace them
The agent can only surface what the person asking is already allowed to see. Permissions are enforced at the source, in your tenant, not reimplemented in a layer we wrote. If somebody cannot open a folder today, the agent cannot read it to them tomorrow.
Every answer cites the document it came from
An answer without a source is an opinion. Each response links the file, the version and the location, so the reader can open the original and check. On anything contractual that is not a nicety, it is the difference between a useful tool and a liability.
It says when it does not know
Configured to return nothing rather than something plausible. The failure mode that matters in construction is not a missing answer, it is a confident wrong one that reaches a valuation or a notice.
It reads. It does not act
By default it answers questions and drafts. It does not send, issue, approve or file. Where a client wants an agent that acts, that becomes a separate, deliberate conversation with named authority and an audit trail, not a default setting.
It runs in your tenant
Built inside your Microsoft 365 and SharePoint. Your records do not move, we hold no copy, and your administrators can revoke access without asking us.
The full data, access and governance position is in the trust centre, including what we do not hold.
What people actually ask it
| The question | What it does |
|---|---|
| “What did we agree about the drainage on plot 14?” | Finds the instruction, the email chain and the revised drawing, with dates. |
| “Pull everything on the delay to the roof package.” | Assembles the correspondence, minutes and diary entries into one chronology. |
| “Which RAMS have expired on this project?” | Reads the document library and reports what is out of date and who owns it. |
| “What is our exposure on this variation?” | Gathers the instruction, the quote, the correspondence and the current status, and stops there, because the judgement is yours. |
What it will not do
- Decide anything. It assembles evidence. The commercial or contractual judgement is made by a person who can be held to it.
- Fix a document estate nobody maintains. An agent reading a chaotic SharePoint returns chaos faster. Where the underlying structure is the problem we say so, and that is a different job which comes first.
- Replace the record itself. It reads what exists. If the day-to-day was never captured, there is nothing to read, which is a capture problem, not a retrieval one.
Common questions
Where does our data go?
Nowhere. For bespoke work we build inside your Microsoft 365 tenant, so the records stay where they are and we do not take a copy. Your content is not used to train any model, ours or a provider’s. The trust centre sets out the full position including sub-processors and access practice.
Can it see things people should not see?
No. It inherits the permissions already set in your tenant and enforces them at the source rather than reimplementing them. A user gets answers drawn only from what they could already open themselves. This is the single most common concern and it is the first thing we design.
How is this different to Microsoft 365 Copilot?
Copilot is broad and general. It is a good product and for many firms it is the right starting point, which we have written about separately. An agent built for you is narrow: it knows your project structure, your naming, your contract forms and the specific questions your team actually asks, and it can be pointed at a CDE or a records system Copilot does not reach. If Copilot already answers your questions well, use Copilot.
What does it cost and how long does it take?
This is not usually a first project. It works best once there is a clean enough document estate to read and some measured experience of what your team asks. Most businesses should start with one workflow instead, prove the approach, and come to this second.
Who is accountable for what it produces?
A named person in your business, always. Under CDM and the Building Safety Act duties attach to identified people and cannot be delegated to a system. The agent produces drafts and citations; a competent person decides. Anything that obscured who approved what would be actively harmful to you.
Most people should not start here
An agent is a second or third project for most businesses. If you have not yet proved the approach on something small, do one workflow first. If you already have a clean document estate and a clear question, this is the conversation.