The situation
A European energy supplier had two AI agents working in production and a backlog of ideas for more. Each had been built as a one-off: its own deployment, its own credentials, its own monitoring. The third agent was about to repeat all of that work.
The problem
- Every new agent re-solved identity, deployment, tool access, cost control and monitoring from scratch.
- Agents held their own keys, and tool permissions lived in prompts: a polite request, not a rule.
- Nothing stopped a broken change from reaching production, and nobody could see what each agent cost to run.
What I did
- Designed one path to production: a team writes a one-page remit, one file of logic, a tool list, a register entry and a set of real test cases. Five files, two pull requests, and no one touches Kubernetes.
- Gave every agent its own identity, created before it first runs. A gateway checks that identity on every call and refuses any tool not on the agent's list, so the rule is enforced in infrastructure rather than requested in a prompt.
- Routed every model call through a single gate with per-team budgets and data masking. No agent holds a provider key, and only masked data leaves the network.
- Made each agent's real past cases a release gate: the build is published only if they all still pass, so a broken change cannot reach production.
- Phased the roadmap so value lands early: move one live agent onto the path first, then automate delivery, then guardrails and per-agent cost dashboards, then scale.
- Set the test that proves the platform works: a second agent moved onto it by someone other than its author, using only the written guide.
One good agent is a win. A way of building agents is a capability.