There is a process in your company that runs on a spreadsheet, a mail thread, and one person who chases everybody for updates. Ask what state it is in right now and nobody can answer without asking a person. That is not a discipline problem. It is a structural one, and it has a name: the plan lives in one place and the work lives in another, so the two drift apart, and somebody's real job becomes keeping the two of them in agreement.
The drift is quiet. A document is updated and the task that implements it is not. A decision is taken in a call, written into a deck, and never reaches the person who has to act on it. None of these throws an error. The cost appears as re-work, as meetings to agree on status, and as decisions taken twice because nobody could find the record of the first one.
Documents live in one product, tasks in another, decisions in a third, and each boundary is a seam where the plan and the work come apart. A person can carry a broken link in their head for a while. AI cannot: a link that does not exist in the data does not exist at all.
ML LABS builds and operates TopDo, its own system for work that people and AI do together. Its architecture answers one question in the smallest way the problem allows: how many kinds of thing does the system model? That answer decides who can see what, what the record proves, and what an AI agent may do without a person watching.

Collapse The Types Into One
TopDo's model is three levels deep and one type wide. A workspace contains products; a product contains nodes; a node is the only content type in the system. Each node carries a kind (item or doc) and a state that is open, closed, or blocked.
Work and knowledge stop being two systems joined by an integration and become one graph. The specification and the task that implements it are the same shape of object with different kinds, and the relationship between them is a real edge in the data, not a link pasted into a description field that rots when somebody renames a page.
- One type means one permission model, one audit path, and one interface for an agent to learn. The surface an agent can be wrong about shrinks with the type count.
- Isolation between companies lives under the application, not inside it: Postgres row-level security keyed on the workspace, so a query that forgets which company it belongs to returns an empty result rather than another company's records.
Agents Are Actors, Not Macros
The second decision was refusing to treat AI as an automation layer bolted onto a human tool. An agent in TopDo is an actor instead: it holds an identity, a permission set, and a history, and in the data it is indistinguishable from a person performing the same action.
The same rules, history and reversal then apply to its work as to anyone else's. The framework for managing AI risk through accountability and traceability (NIST, 2023) reaches the same requirement: an actor you did not model as an actor is an actor you cannot govern.
Identity decides whether an action can be attributed and revoked. A separate decision decides which actions an agent may take at all without a person in the path. The pattern that keeps consequential execution deterministic is the other half of this: the model proposes, and a rules engine, not the model, commits anything that you cannot undo.
Every Change Writes Its Proof
Once anything other than a person can change the record, the audit trail stops being a compliance artifact and becomes the safety mechanism. Every change in TopDo, person or agent, routes through a single layer that writes a hash-chained audit row in the same database transaction as the change itself. Each row carries the hash of the one before it, so a row cannot be quietly rewritten or removed without breaking every hash after it.
An audit written afterwards, in a queue or a background job, can fail while the change succeeds. The record and the reality disagree, and the disagreement is undetectable because the thing that would have reported it is the thing that failed. Written in the same transaction, the two cannot diverge: either both landed or neither did.
An audit trail written after the fact is a story. One written inside the transaction is evidence.
What happened, who did it, and in what order becomes a query, not a reconstruction, and something to hand over to an auditor, an insurer, or a board member.
When Reconciling Costs More Than Doing
The seams become the dominant cost when more effort goes into keeping the plan and the work in agreement than into doing the work. A cost spread across everyone appears on nobody's budget, so look in the second-order places: hours agreeing about status, work done twice, decisions relitigated because the record of the first one could not be found. Adding AI multiplies it, because a tireless actor writes state across every seam at once.
What To Check This Week
- Count the places where your plan and work live separately, and estimate hours spent keeping them in agreement. That is your seam cost, and adding AI multiplies it.
- Route every change through one recorded path before anything automated can write. Each action is then attributable and reversible by construction.
- Give each agent an identity and a permission set. If you cannot revoke one the way you would a departing employee's access, you have not modelled it as an actor.
Design The Record Before The Automation
The durable order is data model first, automation second: one type, one state machine, one recorded path for every change, one layer where separation between companies is enforced beneath the application. Built that way, an arriving agent inherits a system that is legible and safe to operate. Built the other way, it inherits every seam and a write token.
With those in place, letting software act on its own becomes an engineering decision with a known blast radius; the companion piece on the context an agent needs is the operational half. Without them, it is a bet on nothing surprising ever happening.
Every ML LABS engagement runs in TopDo, and the workspace stays yours after the engagement ends. Turning this approach into a concrete design for your own broken process is what the first call is for, before any build budget has been committed.
References
- National Institute of Standards and Technology. AI Risk Management Framework. NIST, 2023.



