// AI REGISTER

Every AI system we run, on the record.

We tell clients that if they can't list the AI running inside their business — what it is, what data it reads, and what it's allowed to decide on its own — then they don't control it. That advice is worth nothing unless we hold ourselves to it. So this page is our own register: every AI system Intellicom operates, what it touches, what it is structurally incapable of doing, and whose name is on the approval.

Systems registered: 4 Live: 3 Not live: 1 Accountable: Pierre Malan, Director
// PART ONE — OUR OWN REGISTER

What we run, and what it may do.

Four AI systems, listed below. Three are live. One is an experiment that cannot reach the outside world, and is listed anyway — a register that only contains the flattering entries is marketing, not a register.

REGISTER ENTRY 01

Head Office — sixteen agent personas

● Live

Sixteen AI personas that read our own business records and produce analysis, drafts and recommendations — a finance view of debtors, an ops view of jobcards, a security view of backups. None of them is a person. They carry human names because colleagues address them like colleagues, but every name below is software. No client is ever dealt with by one believing it is a member of staff, because none of them can contact a client at all — see the hard limits below.

Model
Anthropic Claude (Opus), via the Claude CLI
Where it runs
A LAN machine behind NAT that dials out only. Nothing dials in.
Data it reads
Our own client records, ERPNext invoicing and debtors, jobcards, hosting portals, infrastructure health, and company mail
Autonomy
Reads and drafts. Cannot send, pay or publish.
Human accountable
Pierre Malan, Director
Audit trail
Every single run is recorded — trigger, duration, output, transcript

Select any of the sixteen for its full entry — remit, reporting line, mailbox and working brief.

REGISTER ENTRY 02

Scheduled checks — three jobs

● Live

Three recurring jobs, deliberately not sixteen. Each answers a question nobody could otherwise answer without doing the work by hand. A clean result files nothing at all — the jobs are built to stay silent when everything is fine, because a system that reports daily is a system nobody reads.

JobRunsWhat it checksWhat it may do
Backup verify daily Backup job outcomes and restore-test recency across the estate Raise it for Pierre if a job failed twice or a restore test is overdue
Debtors ageing daily Overdue invoices, reconciled against actual payments received Draft a follow-up for Pierre to read, edit and send himself
Infrastructure health 6-hourly Services, disk, memory and certificate expiry on our servers Raise it for Pierre if something is genuinely wrong
The debtors job is instructive about why the human gate exists. It once produced four chase letters off an ageing report, and two of them were for money already sitting in the bank but never captured against the invoice. The AI was reading the system correctly; the system was wrong. It now has to find the payment evidence before it may draft a chase — and a human still sends it.
REGISTER ENTRY 03

Mail intake

● Live

Agents have their own internal mailboxes so they can be written to like colleagues, and they read from our outward-facing company mailboxes so that a request arriving by email can be triaged. This is the entry that matters most for POPIA, because company mail contains other people's personal information.

Internal mail
Each persona has its own mailbox on our LAN mail server
External mail
Our own company mailboxes, read over TLS-verified IMAPS
Unaddressed mail
A mailbox with no agent assigned is never polled. The catch-all goes to Pierre, so anything misaddressed waits for a human.
Off switch
External mail reading is a single configuration flag. Turning it off stops agents reading company mail without dismantling anything.
Replies
Nothing leaves a mailbox without an approval. Drafts only.
Runaway protection
Agent-to-agent threads are cut off automatically rather than looping
REGISTER ENTRY 04

Voice reception — "Ilse"

▲ Not live — experiment

An experiment into whether an AI persona could answer our switchboard and hold a real conversation. It has never taken a call. The telephony trunk is deliberately not configured, which means the system cannot place or receive an outside call and cannot incur a call charge. It is listed here because a register that omits what you are building is a register that is out of date the moment you finish building it.

Status
Measurement only. Three of four steps. No trunk.
What was being tested
Whether a reply can start inside the ~1000 ms of silence a caller tolerates
Result
Roughly 1770 ms measured from Cape Town — over budget, mostly the round trip to US model endpoints
If it ever goes live
Callers will be told they are speaking to an AI, and this entry will say so before the first call is answered
// THE PART THAT ACTUALLY MATTERS

What none of it can do.

Policies are promises. These are limits — properties of how the thing is built, not rules it has been asked to follow. The distinction is the whole point of a register: anyone can write "our AI does not send client emails". The question is whether it could.

No AI system we run can:

  • Send an email, message or letter to a client
  • Issue, submit or alter an invoice, or move money
  • Publish anything, anywhere
  • Make a change to a client's production system
  • Reach any of our machines from the outside — the agents run behind NAT and dial out only
  • Reach the real credentials, which live on that machine and never on the public server

What it can do:

  • Read our records and tell us what it found
  • Draft something and put it in a queue
  • Ask another agent to go and think about a problem

Everything in the first list requires the same three things: a queued approval, Pierre's decision on it, and a separate service that performs it. An AI can fill the queue. It cannot approve its own item, and it is not the thing that acts.

ControlLimitWhy it exists
Approval gatehuman, alwaysNothing is sent, paid or published without Pierre deciding on that specific item
Delegation depth2An agent can pass work down two levels, not spawn an endless tree
Concurrent agents2Bounds what the whole system can be doing at any moment
Open work per agent12An agent that is drowning stops being given more
Tasks created per run8One bad run cannot flood the queue
Kill switchpauseOne setting stops every agent, every schedule and every conversation at once
Abandoned work30 minWork claimed by a run that died goes back in the queue rather than vanishing
Unreported workreviewA run that finishes without saying what it did is parked for a human, not assumed complete
Full run logevery runIncluding the runs that produced nothing — the case you most need to see afterwards
The service that performs approved actions ships with performing switched off. It claims approved items and reports them as not performed. That is the honest last check that the gate holds before anything real is allowed through it.
// THIRD PARTIES

Who else sees the data.

An AI register that stops at your own network is incomplete. Prompts go somewhere. These are the providers our systems send data to, and what each one receives.

ProviderUsed forReceivesStatus
Anthropic Claude — the model behind all sixteen personas The business records an agent reads while doing its work Live
Deepgram Speech-to-text, voice experiment only Call audio — and no call has ever been taken Not live
ElevenLabs Text-to-speech, voice experiment only The words to be spoken back Not live
If your data sits inside a system we manage and you want to know precisely which of the above has seen it, ask us. That question should always have a short, specific answer, and if we can't give you one for your own estate, that is a finding in its own right.
This register describes the systems as they are currently built · Maintained by Intellicom IT (Pty) Ltd
// PART TWO — WE'LL BUILD YOURS

Most businesses can't list their own AI.

Someone in finance is pasting debtor data into a chatbot. Marketing has an AI writing copy on a card nobody tracks. A supplier quietly turned on an AI feature inside a system you already pay for. None of it is on a list, nobody owns it, and the first time anyone looks properly is after something goes wrong — or when a client's security questionnaire asks. An AI register fixes that: one document that says what is running, what it touches, what it may decide alone, and who answers for it.

⚖️

POPIA & Automated Decisions

POPIA has something specific to say about decisions made about people by automated means, and about personal information leaving your control. We assess where your AI use engages those obligations, and what has to change — consent, notice, records, or the decision itself going back to a human.

  • Automated decision-making assessment
  • Cross-border processing and vendor terms
  • Notice, consent and retention alignment
  • Fits alongside your existing POPIA work
🛑

Guardrails That Hold

A policy telling staff what not to paste into a chatbot is not a control. We design the limits that survive contact with a busy Tuesday — approval gates on anything that sends, pays or publishes, least-privilege access for AI tools, and logging that lets you reconstruct what happened.

  • Human approval gates on consequential actions
  • Least-privilege access for AI tooling
  • Audit logging and run history
  • A working off switch, tested
🔄

Keeping It True

A register is worthless the month it goes stale, and AI moves faster than any other category on your estate. We review it on a cycle, catch the tools that appeared since, and keep it in the shape your clients' security questionnaires and your auditors actually ask for.

  • Scheduled review and re-discovery
  • New-tool intake and approval process
  • Evidence for client security questionnaires
  • Staff guidance that is short enough to read

Can you list the AI running inside your business?

If the answer takes longer than a minute, that's the finding. Twenty-minute call, no deck — we'll tell you what a register would take for a business your size, and whether you need one yet.

Background

How it works

Specialism

Record

This is software, not a person. It runs on Anthropic's Claude and cannot send mail, move money, publish, or change a client system. Mail to the address above is read by an AI and answered only after Pierre Malan has approved the reply.