01
The workforce

Agents that hold a role, not a chat.

Operations, finance, support, sales, people, IT, security, compliance. Each Khelion agent is designed around a job your team already does — with a name, a scope, and a warrant. They are not features in a tool you learn: they are workers you direct. Deploy one, or a collective.

operations

Intake Manager

Reads whatever arrives — forty formats, forty senders — and returns one checked file.

operations

Report Builder

Builds the recurring report from the work itself, not from a quarter-end scramble.

finance

Reconciliation

Matches what arrived against contracts and ledgers; discrepancies are named, never guessed.

finance

Collections

Chases what is owed in your wording — and halts the second a dispute appears.

customer

Ticket Triage

Reads, sorts and answers the routine — escalates the rest with the context attached.

customer

Inbound Mail

Sorts mail by what it actually asks, attaches it to the right file, stops on the sensitive.

revenue

Pipeline Chaser

Follows every open deal, drafts the next message, names the ones going quiet.

revenue

Bid Response

Assembles a tender answer from what you have already written and already approved.

people

Onboarding Files

Checks required documents off, requests what is missing with the right reference.

knowledge

Deep Search

Answers from your systems and the public record, citations attached, gaps admitted.

knowledge

Policy Answer

Answers “are we allowed to…?” from your own policies, with the paragraph cited.

security

Access Review

Watches who can reach what, and flags the account nobody closed.

it

Alert Triage

Correlates the night’s alerts and wakes a human only for what deserves one.

compliance

Regulation Watch

Reads each new text against your own procedures, clause by clause, and drafts the amendment.

compliance

Evidence Builder

Keeps the inspection pack current, findings tracked to closure, every claim sourced.

documents

Drafting Agent

Writes the file to the structure the reader expects — a claim without a source is removed.

And the one that is in no catalog

Most deployments pair two or three of the above with an agent built entirely around a process only your company runs. That one is usually why the project pays for itself — and it is the part nobody can sell you off the shelf.

Describe your process →
02
What the agents actually do

This is not automation with a new name.

A fair question when someone says “AI agents”: what is the model actually for? Here is the honest breakdown of where the intelligence sits — and where, deliberately, it does not.

01 — Read

Understand a document, not just search it

A supplier contract, a 200-clause implementing regulation, an internal procedure nobody has reopened in three years. The agents read the text against your own rules, clause by clause, and return what changed, who owns it, and the draft amendment. Keyword search cannot do this: the same obligation is worded differently in every document.

Why a model and not a script: the mapping between a clause and your internal procedure is semantic, and it is different in every company.
02 — Judge

Classify what arrives, with the reasoning attached

A complaint, an incoming claim letter, a broker statement in an unseen format. The agents decide what it is, what it requires, whether it crosses a threshold, and what is missing — and record why they decided that, so a reviewer can disagree with a specific step rather than the whole output.

Why a model and not a script: there is no fixed schema. Forty senders means forty formats, and next month there is a forty-first.
03 — Detect

Find the signal in data nobody reads end to end

Payment flows, complaint streams, access logs, device telemetry. The agents run change-point detection against a threshold written in advance, separate a real shift from a sales campaign or a seasonal effect, and produce the statistical justification a notified body will ask to see.

Why a model and not a script: the statistics are classical; deciding which series, which denominator and which confounder matter is not.
04 — Draft

Write the file, with every claim sourced

A safety report, an incident write-up, a corrective action plan, a query to a partner office. Written to the structure the reader expects, in your register, with each sentence linked to the record behind it. A claim that cannot be traced is removed rather than softened.

Why a model and not a script: this is generation under citation discipline — the only part of the job an LLM is unambiguously better at than a template.
05 — Refuse

Stop at the line, in writing

Every agent runs under a warrant that the runtime enforces. An action outside it is refused, and the refusal is recorded like any other step. This is the part that is not AI at all — it is a hard control around the AI, and that is exactly why it works.

Why this matters commercially: it is what makes obligations like the AI Act's answerable, and what lets a regulated buyer say yes.

The engine is general — read the rules, do the work, prove it, stop at the boundary. See it applied in the field →

Already running agents?

Manifest also runs over agents you built yourself, or a vendor’s — the warrant, the log and the answer apply to them too. That is often the fastest first deployment.

Inside Manifest →