Djtal

For your IT department

What guarantees should you ask for before connecting an AI agent to your IT systems?

You are responsible for what runs on your IT systems. An AI agent that reads your data and writes into your systems deserves the same treatment as any new software, with a defined scope, access rights, logs and a clean exit. This page answers those requirements point by point, in your terms.

This page is written for the head of IT. If you are a business leader or project manager, forward it to your IT team as it stands. It contains the answers your agent project owes them.

In brief

What does Djtal guarantee an IT department?

Before any AI agent is connected, Djtal, the operational AI specialist for Swiss companies, gives your IT team a written scope to approve, access limited to the OAuth scopes your IT team grants, a complete action log and demonstrated reversibility: instructions in an open format, switch-off within minutes. The set-up is mapped to the OWASP Top 10 for LLM Applications.

The starting point

Your standard of requirement is the right one.

On 5 October 2026, the head of IT at a large infrastructure site in French-speaking Switzerland described the site's standard to us. A new management system is tested for a year before it goes into production, because a single flaw would stop the whole site.

We treat that reasoning as the right starting point. When an IT department says no to an AI agent project, it is protecting the company from a deployment whose scope, access and traceability it cannot see. The useful answer is to provide those three things in writing before anything is built. The refusal then becomes a list of requirements, and we answer each item on it.

Eight verifiable guarantees

AI agent security checklist: what your IT requires, what Djtal sets up, how you verify it.

Every row can be checked on your side, in a document, a console or a log, with no need to take our word for it.

Djtal's eight guarantees to the IT department for an AI agent deployment
Your requirementWhat Djtal sets upHow you verify it
Controlled scopeEach agent has one written document: its role, the systems it touches, the actions it may take and those that need human approval.Your team reads and approves the scope document before anything is built. It remains the reference document throughout operation.
Controlled accessConnection through the official APIs of your systems, using OAuth, with only the permissions (scopes) your IT department grants.The list of scopes sits in your admin console. You can revoke them at any time, without us.
Graduated autonomyFour levels, from observation to audited autonomous action. Each step up waits for your approval.The agent starts read-only. You review the logs of the current level before each step up.
Complete audit trailA timestamped, versioned log of what the agent read, wrote and submitted for approval.The log is handed over to you. You read it like a git history, action by action.
Security frameworkA risk assessment mapped to the OWASP Top 10 for LLM Applications (2025 edition), starting with ‘Excessive Agency’.The written scope addresses each OWASP risk in turn. You compare the scope document with the framework.
Data residencyYour data stays in your business systems and the agent reaches it through APIs. Sensitive components are preferably hosted in Europe, with a no-training clause for the AI models.The clause is written into the contract. You read it before signing, and it is checked on every project.
Reversibility and rollbackThe agent's instructions and knowledge are kept in plain-text files (Markdown), versioned in a repository you own.Revoking access switches the agent off within minutes. The switch-off test is part of your acceptance testing, before go-live.
Zero shadow ITYour team receives an inventory of access and scopes, log locations, the named human supervisor and the deactivation procedure.You find the agent in your application register like any other software, with a designated owner.

The four autonomy levels and oversight by design are set out in detail on the AI agents page. This graduated approach follows the recommendation of OWASP (Top 10 for LLM Applications, 2025 edition, ‘Excessive Agency’ risk).

The proof, in our own IT

Our nine in-house agents run under this regime.

Djtal has run nine AI agents in its own workflows since May 2026, across sales, accounting, communications and knowledge management. Each one runs under a version-controlled permissions configuration, and the deny lists (secrets, destructive commands) are enforced by that configuration, whatever the agent decides. Every working session leaves commits attributed to its agent in a git log. An automatic check verifies, before each entry goes into the log, that no password or access key slips in.

On 2 September 2026, we changed the AI model of these nine agents in a single night, in production. That night is the reversibility row of the table, exercised on our own systems.

Simplified extract of a real scope (Émile, our finance agent)

Agent:      Émile · Finance
Role:       Zoho Books accounting, preparing journal entries
Access:     Zoho Books API (read + drafts), nothing else
Prohibited: sending email without approval, payment, deletion
Approval:   every general ledger entry waits for human sign-off
Log:        every session committed to the repository, reviewed by the supervisor

The scope of an agent delivered to you has the same format, adapted to your systems and approved by your IT department.

Six steps

How a Djtal agent goes through your approval process.

The sequence follows the logic of your own application approvals (document, grant, observe, review, extend), and your team stays in control at every stage.

  1. 1

    Scope submitted

    Before anything is built, the scope document goes to your IT department. It sets out the role, the systems, the permitted actions and the approvals required.

  2. 2

    Access review

    Your team creates the accounts and grants the OAuth scopes. Djtal works with the rights you give it, through the official APIs.

  3. 3

    Observation mode

    The agent reads, analyses and reports back. Throughout this phase, it has read-only access to your systems.

  4. 4

    Log review

    Your team reads the action log from the trial period, to see what the agent saw and what it would have proposed.

  5. 5

    Stepping up level by level

    Each extra level of autonomy rests on logs you have reviewed and on your written approval.

  6. 6

    Supervised operation

    Periodic usage reviews, the log handed over continuously, and a shutdown procedure that is tested and documented on your side.

Swiss FADP and EU AI Act

The legal framework, with verified dates.

In Switzerland, the Swiss Federal Act on Data Protection (FADP) has applied since 2023 to all processing of personal data, AI agents included, with a register of processing activities, a duty to inform data subjects and control over transfers abroad. On the EU side, the EU AI Act's transparency obligations (Article 50) and its penalty regime have applied since 2 August 2026. The ‘high-risk’ requirements have been postponed to 2 December 2027 (Annex III) and then 2 August 2028 (Annex I). Switzerland is preparing its own framework, with a preliminary draft expected at the end of 2026.

For an IT department, what matters comes down to three practices that hold whatever the regulatory timetable: an inventory of AI systems, documentation of scopes and logging of actions. All three already appear in the table of guarantees above. A deployment that meets your IT requirements also prepares you for regulatory compliance.

Frequently asked questions

The questions IT teams ask.

Can an AI agent act outside the scope approved by our IT department?

At Djtal, an agent's scope is a written document submitted to your IT department before go-live. The agent reaches only the systems you have listed, through their official APIs, with the OAuth scopes your team has granted, so anything not on the list is technically out of its reach. Any extension of scope goes through the same approval, and the action log lets you check afterwards that the agent stayed within its limits.

What data does the agent see, and where is it hosted?

A Djtal agent reads data from the systems your IT department has given it access to, through APIs and with no copy of the database. Your data stays in your business tools (ERP, CRM, email). Sensitive components are preferably hosted in Europe, and the AI models Djtal uses are covered by a no-reuse clause, which keeps your data out of public model training. The clause is checked on every project.

What should an AI agent security checklist require so that we can audit what the agent has done?

Every action of a Djtal agent goes into a timestamped, versioned log that records what it read, what it wrote and what it submitted for human approval. The log is handed over to your team and reads like a git history. Djtal has applied this system to its nine in-house agents since May 2026: each working session leaves a record attributed to its agent and reviewed by a human supervisor.

Does an AI agent create shadow IT?

Shadow IT is the use of tools in a company without the IT department's knowledge. A Djtal deployment does the opposite, and everything is declared before go-live. Your IT department receives the full inventory (written scope, list of access and scopes, location of the logs, named human supervisor). The agent is then added to your application register like any other software, with an owner and a documented deactivation procedure.

What is left if we switch the agent off?

Everything. In a Djtal deployment, the scope, the instructions and the agent's knowledge live in plain-text files (Markdown), versioned in a repository you own, and your data stays in your business tools. Revoking OAuth access switches the agent off within minutes. On 2 September 2026, Djtal changed the AI model of its nine in-house agents in a single night, in production, which shows the set-up survives a change of AI provider.

What does the EU AI Act change for deploying an agent in Switzerland?

Since 2 August 2026, the EU AI Act's transparency obligations (Article 50) and its penalty regime have applied in the EU. The ‘high-risk’ requirements have been postponed to 2 December 2027 (Annex III) and then 2 August 2028 (Annex I). Switzerland is preparing its own framework, with a preliminary draft expected at the end of 2026. For a company agent, the practical preparation is three practices that hold whatever the timetable: an inventory of AI systems, documentation of scopes and logging of actions. A Djtal deployment provides all three as standard.

Put your requirements to us. We'll answer them point by point.

A one-hour technical review between your IT team and ours. We go through your context, your approval rules and the way an agent's scope meets them, with documents to hand, starting with a real scope like Émile's above.

This page complements the AI agents page (services and prices) and the IT security audit (your IT systems as a whole).

Further reading: Switching AI models in one night · Why AI projects fail

Last updated: