# AI Agent Development UK

Source: https://dijituldevelopments.co.uk/ai-agent-development/
Updated: 2026-10-10

> dijitul developments builds AI agents for UK businesses: software where a language model plans a multi-step task and carries it out by calling tools you control, such as looking up records, drafting documents or updating your CRM. Agents run with tight permissions, human approval for risky steps and audit logs. Every project is a fixed-price quote after a free chat.

## Problems this solves

- A task needs someone to check five systems, compare the results and write it up
- Simple automation rules break whenever the input is slightly different
- You have seen agent demos but worry about one acting on your live data unchecked
- Staff spend hours on research and preparation before the actual decision
- An off-the-shelf agent platform cannot reach your in-house systems
- Nobody can explain what an AI tool did or why when something goes wrong

## Key facts

- An agent is a model calling tools in a loop until a task is done, under rules your code enforces
- Each tool has its own permission scope, input validation and rate limit
- Actions with real-world effects need human approval by default
- Every step, tool call and result is written to an audit log you can replay
- Agents get step limits, time limits and spend caps so they cannot loop forever
- Tools can be exposed through the Model Context Protocol (MCP) where that suits your setup
- Model-neutral: OpenAI, Anthropic Claude, Google Gemini or open-weight models

## What an AI agent is, in plain terms

An AI agent is a language model given a goal, a set of tools and permission to use them in a loop. It reads the task, decides which tool to call, looks at the result, and repeats until it has an answer or needs help. A tool is just a function in your software, for example `search_customers`, `get_invoice`, `draft_email` or `create_purchase_order`.

That sounds powerful, and it is. It also means the agent's safety depends entirely on what those tools are allowed to do. We think about agents the way we think about giving a new member of staff system access: start with read-only, add write access one function at a time, and keep a record of everything.

Not every job needs an agent. If the steps are always the same, a fixed workflow with one model call is cheaper, faster and easier to test. We will tell you when that is the better option; see AI automation.

## Good jobs for an agent

Agents earn their place when the path through a task varies each time and involves several systems. Examples we would build:

- **Account review preparation**: pull a customer's orders, invoices, open tickets and recent emails, then write a one-page brief for the account manager.
- **Supplier query handling**: read a supplier email, find the matching purchase order and delivery, spot the discrepancy and draft a reply for approval.
- **Exception handling**: when an order fails to sync between your shop and ERP, investigate the cause from logs and records and propose the fix.
- **Research and comparison**: gather product or compliance information from approved sources and fill in a structured comparison.

In each case the agent does the gathering and drafting, and a person makes the call.

## Guardrails that live in code, not in the prompt

Telling a model "do not delete anything" is not a control. The OWASP Top 10 for LLM Applications (2025) lists both prompt injection (LLM01) and excessive agency (LLM06) as risks, and agents are where the two meet: an email or web page the agent reads might contain instructions trying to make it misuse its tools. Our controls sit outside the model:

- **Least privilege**: each tool has its own credentials and scope. A tool that reads invoices cannot write them.
- **Validation**: tool arguments are checked against a schema and business rules before they run.
- **Approval gates**: payments, deletions, customer emails and anything else irreversible go to an approval queue.
- **Budgets**: maximum steps, maximum run time and a spend cap per task.
- **Untrusted content flagged**: text from emails, uploads and websites is marked as data, never as instructions.

## Tools, APIs and the Model Context Protocol

Most of an agent project is integration work: wrapping your APIs, database and third-party services in well-defined tools with clear descriptions and strict inputs. That is familiar ground for us; we have been building integrations since the KashFlow and OpenCart days.

Where it helps, we expose those tools through the Model Context Protocol (MCP), an open standard for connecting AI applications to tools and data. An MCP server lets approved AI clients use your tools with the same permissions and logging, rather than each client needing its own custom connection. For agents that only run inside your application, plain tool calling through the provider's API is usually simpler.

## Rolling out in stages

We rarely switch an agent straight on with write access. A typical rollout has three stages. First, **shadow mode**: the agent runs on real tasks but only produces a report, which staff compare with what they actually did. Second, **propose and approve**: the agent prepares actions and a person accepts, edits or rejects each one. Third, **limited autonomy**: low-risk, well-tested actions run automatically within set limits, while everything else still needs approval. Each stage has its own success measures, agreed with you up front, and you decide when to move on.

## Testing and observing agents

Because agents take different paths each time, we test them with scenarios rather than single inputs. Each scenario has a starting situation, the data the tools will return, and what a good outcome looks like. We include awkward ones: missing records, contradictory data, and documents containing injected instructions. The suite runs on every change.

In production, every run is traced step by step, so when someone asks why the agent proposed a credit note you can see exactly what it looked at. Approval rates and edit rates show where it is helping and where it needs work.

Every agent build is a fixed-price quote after a free chat and a scoping stage.

## What we deliver

- A written task definition with success criteria and a list of allowed tools
- Tool functions wrapping your APIs and database with least-privilege credentials
- An agent runtime with step limits, timeouts, retries and spend caps
- An approval queue where staff accept, edit or reject proposed actions
- A full audit trail of prompts, tool calls, results and approvals
- An evaluation suite of realistic scenarios, including adversarial ones
- An optional MCP server exposing your tools to approved AI clients

Technologies: Tool calling, Model Context Protocol, OpenAI API, Anthropic Claude API, Google Gemini API, TypeScript, Python, Laravel

## FAQs

### What is the difference between an AI agent and a chatbot?

A chatbot answers questions in a conversation. An AI agent works towards a goal by calling tools in several steps, such as looking up records, comparing them and drafting an action. Many projects combine both. dijitul developments builds agents with permissions and approval steps enforced in code.

### Can an AI agent act on our live systems safely?

It can, with the right controls. dijitul developments gives each tool least-privilege access, validates every tool call, caps steps and spend, and routes anything irreversible, such as payments, deletions or customer emails, to a person for approval. Every step is logged so you can review what happened.

### What is the Model Context Protocol?

The Model Context Protocol, or MCP, is an open standard for connecting AI applications to tools and data sources. We can build an MCP server that exposes your tools, with the same permissions and audit logging, so approved AI clients can use them without a custom integration each time.

### Do we need an agent or just automation?

If the steps are the same every time, a fixed workflow with a single model call is cheaper, faster and easier to test. Agents suit tasks where the path varies and several systems are involved. dijitul developments will recommend the simpler option during scoping when it fits.

### How do you stop an agent running up a big bill?

Each agent run has a maximum number of steps, a time limit and a spend cap, and there is a monthly cap across all runs with alerts. Smaller, cheaper models handle simple steps. Cost per run is shown in the admin dashboard so you can see exactly where spend goes.

### How is an AI agent project priced?

dijitul developments quotes a fixed price after a free chat and a scoping stage that defines the task, the tools and the approval rules. Larger programmes are phased, usually starting read-only, with each phase quoted separately. Model usage is billed by the provider and estimated in advance.

## Pricing and contact

Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data. Book a free chat: https://dijituldevelopments.co.uk/contact/ · 01623 650333 · info@dijitul.uk
