We tell clients that if they can't list the AI running inside their business — what it
is, what data it reads, and what it's allowed to decide on its own — then they don't
control it. That advice is worth nothing unless we hold ourselves to it. So this page is
our own register: every AI system Intellicom operates, what it touches, what it is
structurally incapable of doing, and whose name is on the approval.
Systems registered: 4Live: 3Not live: 1Accountable: Pierre Malan, Director
// PART ONE — OUR OWN REGISTER
What we run, and what it may do.
Four AI systems, listed below. Three are live. One is an experiment that cannot reach
the outside world, and is listed anyway — a register that only contains the flattering
entries is marketing, not a register.
REGISTER ENTRY 01
Head Office — sixteen agent personas
● Live
Sixteen AI personas that read our own business records and produce analysis, drafts and
recommendations — a finance view of debtors, an ops view of jobcards, a security view of
backups. None of them is a person. They carry human names because
colleagues address them like colleagues, but every name below is software.
No client is ever dealt with by one believing it is a member of staff, because none of
them can contact a client at all — see the hard limits below.
Model
Anthropic Claude (Opus), via the Claude CLI
Where it runs
A LAN machine behind NAT that dials out only. Nothing dials in.
Data it reads
Our own client records, ERPNext invoicing and debtors, jobcards, hosting portals, infrastructure health, and company mail
Autonomy
Reads and drafts. Cannot send, pay or publish.
Human accountable
Pierre Malan, Director
Audit trail
Every single run is recorded — trigger, duration, output, transcript
Select any of the sixteen for its full entry — remit, reporting line, mailbox and working brief.
REGISTER ENTRY 02
Scheduled checks — three jobs
● Live
Three recurring jobs, deliberately not sixteen. Each answers a question nobody could
otherwise answer without doing the work by hand. A clean result files nothing at all —
the jobs are built to stay silent when everything is fine, because a system that reports
daily is a system nobody reads.
Job
Runs
What it checks
What it may do
Backup verify
daily
Backup job outcomes and restore-test recency across the estate
Raise it for Pierre if a job failed twice or a restore test is overdue
Debtors ageing
daily
Overdue invoices, reconciled against actual payments received
Draft a follow-up for Pierre to read, edit and send himself
Infrastructure health
6-hourly
Services, disk, memory and certificate expiry on our servers
Raise it for Pierre if something is genuinely wrong
The debtors job is instructive about why the human gate exists. It once produced four
chase letters off an ageing report, and two of them were for money already sitting in
the bank but never captured against the invoice. The AI was reading the system
correctly; the system was wrong. It now has to find the payment evidence before it may
draft a chase — and a human still sends it.
REGISTER ENTRY 03
Mail intake
● Live
Agents have their own internal mailboxes so they can be written to like colleagues, and
they read from our outward-facing company mailboxes so that a request arriving by email
can be triaged. This is the entry that matters most for POPIA, because company mail
contains other people's personal information.
Internal mail
Each persona has its own mailbox on our LAN mail server
External mail
Our own company mailboxes, read over TLS-verified IMAPS
Unaddressed mail
A mailbox with no agent assigned is never polled. The catch-all goes to Pierre, so anything misaddressed waits for a human.
Off switch
External mail reading is a single configuration flag. Turning it off stops agents reading company mail without dismantling anything.
Replies
Nothing leaves a mailbox without an approval. Drafts only.
Runaway protection
Agent-to-agent threads are cut off automatically rather than looping
REGISTER ENTRY 04
Voice reception — "Ilse"
▲ Not live — experiment
An experiment into whether an AI persona could answer our switchboard and hold a real
conversation. It has never taken a call. The telephony trunk is
deliberately not configured, which means the system cannot place or receive an outside
call and cannot incur a call charge. It is listed here because a register that omits
what you are building is a register that is out of date the moment you finish building
it.
Status
Measurement only. Three of four steps. No trunk.
What was being tested
Whether a reply can start inside the ~1000 ms of silence a caller tolerates
Result
Roughly 1770 ms measured from Cape Town — over budget, mostly the round trip to US model endpoints
If it ever goes live
Callers will be told they are speaking to an AI, and this entry will say so before the first call is answered
// THE PART THAT ACTUALLY MATTERS
What none of it can do.
Policies are promises. These are limits — properties of how the thing is built, not rules
it has been asked to follow. The distinction is the whole point of a register: anyone can
write "our AI does not send client emails". The question is whether it could.
No AI system we run can:
Send an email, message or letter to a client
Issue, submit or alter an invoice, or move money
Publish anything, anywhere
Make a change to a client's production system
Reach any of our machines from the outside — the agents run behind NAT and dial out only
Reach the real credentials, which live on that machine and never on the public server
What it can do:
Read our records and tell us what it found
Draft something and put it in a queue
Ask another agent to go and think about a problem
Everything in the first list requires the same three things: a queued approval, Pierre's
decision on it, and a separate service that performs it. An AI can fill the queue. It
cannot approve its own item, and it is not the thing that acts.
Control
Limit
Why it exists
Approval gate
human, always
Nothing is sent, paid or published without Pierre deciding on that specific item
Delegation depth
2
An agent can pass work down two levels, not spawn an endless tree
Concurrent agents
2
Bounds what the whole system can be doing at any moment
Open work per agent
12
An agent that is drowning stops being given more
Tasks created per run
8
One bad run cannot flood the queue
Kill switch
pause
One setting stops every agent, every schedule and every conversation at once
Abandoned work
30 min
Work claimed by a run that died goes back in the queue rather than vanishing
Unreported work
review
A run that finishes without saying what it did is parked for a human, not assumed complete
Full run log
every run
Including the runs that produced nothing — the case you most need to see afterwards
The service that performs approved actions ships with performing switched off. It claims
approved items and reports them as not performed. That is the honest last check
that the gate holds before anything real is allowed through it.
// THIRD PARTIES
Who else sees the data.
An AI register that stops at your own network is incomplete. Prompts go somewhere. These
are the providers our systems send data to, and what each one receives.
Provider
Used for
Receives
Status
Anthropic
Claude — the model behind all sixteen personas
The business records an agent reads while doing its work
Live
Deepgram
Speech-to-text, voice experiment only
Call audio — and no call has ever been taken
Not live
ElevenLabs
Text-to-speech, voice experiment only
The words to be spoken back
Not live
If your data sits inside a system we manage and you want to know precisely which of the
above has seen it, ask us. That question should always have a short, specific answer, and
if we can't give you one for your own estate, that is a finding in its own right.
This register describes the systems as they are currently built · Maintained by Intellicom IT (Pty) Ltd
// PART TWO — WE'LL BUILD YOURS
Most businesses can't list their own AI.
Someone in finance is pasting debtor data into a chatbot. Marketing has an AI writing copy
on a card nobody tracks. A supplier quietly turned on an AI feature inside a system you
already pay for. None of it is on a list, nobody owns it, and the first time anyone looks
properly is after something goes wrong — or when a client's security questionnaire asks.
An AI register fixes that: one document that says what is running, what it touches, what
it may decide alone, and who answers for it.
🗂️
AI Discovery & Register
We find what's actually in use — including the tools nobody declared and the AI features switched on inside software you already own — and build the register: every system, its purpose, its data, its owner, and its risk rating. You end up with the document, not a dependency on us.
Discovery across departments and shadow AI
AI features already active in existing vendors
Data-flow mapping per system
Risk rating and system ownership
⚖️
POPIA & Automated Decisions
POPIA has something specific to say about decisions made about people by automated means, and about personal information leaving your control. We assess where your AI use engages those obligations, and what has to change — consent, notice, records, or the decision itself going back to a human.
Automated decision-making assessment
Cross-border processing and vendor terms
Notice, consent and retention alignment
Fits alongside your existing POPIA work
🛑
Guardrails That Hold
A policy telling staff what not to paste into a chatbot is not a control. We design the limits that survive contact with a busy Tuesday — approval gates on anything that sends, pays or publishes, least-privilege access for AI tools, and logging that lets you reconstruct what happened.
Human approval gates on consequential actions
Least-privilege access for AI tooling
Audit logging and run history
A working off switch, tested
🔄
Keeping It True
A register is worthless the month it goes stale, and AI moves faster than any other category on your estate. We review it on a cycle, catch the tools that appeared since, and keep it in the shape your clients' security questionnaires and your auditors actually ask for.
If the answer takes longer than a minute, that's the finding. Twenty-minute call, no deck — we'll tell you what a register would take for a business your size, and whether you need one yet.