George Kavuma
Enterprise AI · Agent governance

How I made a complex AI workflow easier for non-technical operators to understand, trust, and use.

Founding product hire on an enterprise AI platform. The product lets companies build AI agents: software workers that map a business process and then run it on the company's behalf. I set the product direction and the rules for how agents are governed, then designed the screens that let a non-technical operator run them safely. The sharp decision: you must never be able to mistake a draft agent for a live one, because in enterprise AI that confusion is the failure mode.

Founding product hire on an enterprise AI platform. The sharp call: you must never mistake a draft agent for a live one, because in enterprise AI that confusion is the failure mode.

Leadership AI Enterprise Governance UI Design system
Role
Founding product hire and Product Experience Lead.
Timeline
January 2026 to present.
Organization
NextGen AI Technologies.
Focus
Agent governance: draft vs production, the wizard, promotion gates.

At a glance

The user and the situation

User. A non-technical operator who inherits the AI agents and has to run them day to day.

What they were trying to do. Stand up, run, and change AI agents safely, without calling engineering.

Why it was risky. Draft agents and live agents looked alike, and a wrong automated action has financial and operational consequences.

What I changed, and what it proves

What I changed. I made agent state legible: a hard draft-versus-production boundary, a gated setup wizard, and promotion as an explicit, auditable action.

What this proves. Lead-level product design with my hands on the work: I led the product direction and governance model for a founding-stage AI platform, and designed the surfaces that scope was built on.

01  Business context

Sales was moving faster than product clarity.

Sales and client demand were moving ahead of product clarity. Agent demos alone were not enough for enterprise buyers, and deals stalled in security and procurement review, because a demo cannot carry procurement-grade trust.

Enterprise buyers cannot procure a demo. They procure governance, escalation, audit posture, and a workflow they can hand to their own operators. The business needed an artifact stronger than a live demo: something a buyer could review, trust, and operate. That requirement set the brief for the product. I built these workflow diagrams alongside the sales team, and client sign-off on them became the commitment a demo could never carry. That sign-off opened a $1M+ expansion pipeline and led to a white-label version of the platform designed for a global electronics manufacturer, now in that client's internal review.

02  The product problem

The interface did not make agent state legible.

Draft agents and production agents looked alike. Escalation paths and failure modes were ambiguous. In enterprise AI, that ambiguity is the failure mode, because a wrong automated action carries real financial and operational consequences.

The question the design had to answer

Could a non-technical operator always tell, at a glance, whether an agent was a draft or running in production, what it was allowed to do, and what would happen if it failed? If not, the platform was not safe to hand over, no matter how good the demo looked.

Why this was a design problem, not a settings problem

State could not be a label buried in a settings panel. It had to be a property of the whole interface, so the product made the unsafe action hard and made a no the easy default.

03  Discovery

Map the operation before designing the screen.

I run a double diamond process: widen first to understand how the business actually works, then narrow to the solution. With NDS Logistics I turned discovery calls, operational workflows, and failure modes into journey maps and workflow diagrams, then designed agents that compress those steps, making the work faster without breaking the company's core goals or opening security gaps. The principle: an operator does not adopt an agent, they adopt a workflow, so the workflow had to be a shared artifact before any screen existed.

Sanitized macro ecosystem diagram for NDS Logistics workflow.
NDS Logistics · Macro ecosystem (sanitized)The system landscape the workflow has to live inside. Used in discovery to align finance, operations, and the AI workforce on what the system connects, not what it does in isolation.
Sanitized macro cash application workflow for NDS Logistics.
NDS Logistics · Cash application macro (sanitized)The cash-application workflow rendered as a macro process so accounting, ops, and engineering review the same artifact. Boundary conditions become a shared object instead of a private assumption.
04  The design

Make agent state impossible to misread.

Three governance decisions carry the case. Each is documented as a mechanic, the operational reason behind it, and the tradeoff it accepts, so the design is reviewable by engineering, QA, sales, and clients.

MechanicOperational whyTradeoff
Draft and production are different places, not a status flag An operator must never act on a draft believing it is live, or treat a live agent as a sandbox. Confusing the two is the failure mode in enterprise AI. More deliberate movement between states. The cost of a wrong action is far higher than the cost of an extra step.
The agent wizard is a gated sequence, not a blank form Standing up an agent is an architecture decision. A guided, gated sequence lets a non-technical operator make it without involving engineering. Less raw flexibility per step. The operator cannot skip a decision that downstream safety depends on.
Promotion to production is an explicit, auditable action Procurement and security need to see that an agent passed evaluation, policy, and human-in-the-loop checks before it went live. Promotion takes longer. The interface makes a no the easy default.
Decision 01

Draft versus production as a hard interface boundary

Lifecycle controls treat draft and production as two distinct places with distinct affordances, not one screen with a toggle. Promotion, rollback, and retirement are explicit operations with gates. The interface refuses to confuse a draft agent with a production agent, because that confusion is the failure mode in enterprise AI.

Lifecycle controls for promoting, rolling back, and retiring an agent.
NextGen AI · Lifecycle controlsDraft and production are separated at the level of the interface, so an operator always knows which one they are looking at and what an action will affect.
Decision 02

The agent wizard collapses an architecture decision into a guided sequence

Standing up an agent is an architecture decision in disguise. The wizard turns it into a guided sequence where each step is an explicit gate, not a free-form field, so a non-technical operator can stand up an agent without involving engineering, and cannot skip a decision that downstream safety depends on.

Agent creation wizard, first step, naming the agent.
NextGen AI · Agent wizard, step oneEach step is a gate. The operator makes one decision at a time, in an order that keeps the resulting agent safe to run.
Decision 03

Promotion is an explicit, auditable action

An agent cannot move to production until evaluation, policy, and human-in-the-loop checks pass. The gates encode the operational why directly into the UI, so promotion is a decision a buyer can audit, not a side effect. The screen exists to make a no the easy default.

Promotion gates passing checks before agent release.
NextGen AI · Promotion gatesPromotion is blocked until the checks pass. The action is explicit, logged, and reviewable by procurement and security.
Decision 04 · the substrate

A WCAG AA design system that enforces state and accessibility at the token level

An agent's status is a reusable rule, not a one-off colour choice. Status colours, contrast pairings, and interaction standards are defined once in the design system and used everywhere, so legibility and accessibility hold across every screen instead of being patched in screen by screen. This could stand on its own as a separate IC craft case.

NextGen · Glass design system · Token sheetThe production token system rendered as a technical artifact: brand and neutral ramps, agent lifecycle status colours, chart palette, type scale, glass surface, and radius. Components consume these tokens directly, so accessibility and state semantics are enforced at the system level, not per screen.
More screens from the platform

Supporting surfaces from the same platform. They are not part of the core story above, but they show the breadth of the build.

Template gallery for selecting an AI agent starting point.
NextGen AI · Template galleryHow an operator picks a starting point. Templates encode workflow shape, governance posture, and escalation rules so the first agent is not assembled from a blank canvas.
Plugin gallery for extending agent capability.
NextGen AI · Plugin galleryPlugins are scoped capabilities a client admin can review, install, and govern. Capability discovery is separated from runtime so procurement and security can audit before activation.
Billing dashboard with quota and usage visibility.
NextGen AI · Billing dashboardUsage and quota against contract, so the buyer sees commercial commitments against live operational signal rather than waiting on a quarterly export.
Enterprise field-service Service Call Agent workflow diagram showing a swimlane decision tree for move requests, address changes, and call type routing.
Enterprise field-service · Service Call Agent workflow architecture (sanitized)Discovery output rendered as a swimlane operators can read. Move Request, Address Change, and call-type routing each get their own lane with explicit decision points. Client identifiers paraphrased.
MMR Reporting Agent macro client-safe workflow showing Finance Lead requesting via Microsoft Teams, Prime Agent Manager dispatching the MMR Reporting Agent, secure fetch from the client reporting tool and an Excel template, compile to Excel and PowerPoint, delivery via Email and Teams.
Enterprise finance · MMR Reporting Agent macro workflow (client-safe)Client-safe macro tier of an MMR Reporting Agent. Each box is an explicit handoff, not an assumption, from request through secure fetch, compile, and delivery.
Walkthrough · Vertical solution
Vertical solution walkthrough for a named enterprise client in active expansion. Same platform, same governance, lifecycle gates, and design system underneath. Video not loading? Open in Loom ↗
05  Outcomes

A live deployment, a governance layer, and 48-hour workflow turnaround.

The outcomes that belong to this design. Commercial and leadership outcomes from the engagement are kept on the home page, where the strategy and leadership proof lives.

Closed NDS Logistics deployed and generating revenue. Cash application, vendor payments, and driver data workflows live on the platform.
Verified Client ask to documented workflow architecture in 48 hours. Client directive on a Saturday; full decision-recorded workflow package published Monday; live client demo that same week. Verified against calendar and file records.
Shipped WCAG AA glass design system shipped from zero. Navigation patterns, component library, accessibility tokens, and developer handoff.
In delivery Governance layer designed and ticket-linked for the next release. Draft versus production boundary, the gated agent wizard, promotion gates, rollback, and retirement. Every surface designed, screenshot-documented, and tied to its engineering ticket.

Closed revenue, expansion pipeline, team leadership, and the Series A product narrative from this engagement are consolidated in strategy and leadership proof on the home page.

What this shows
  • Senior judgment on the hardest enterprise-AI UX problem: designing for trust, governance, and consequence.
  • State made legible, so a non-technical operator cannot take an unsafe action by accident.
  • A design system that enforces accessibility and state semantics at the token level.
  • Production delivery from discovery through shipped product, with Claude and Cursor in the workflow.
Confidentiality NDS Logistics is named with permission. Other client workflows, opportunity maps, and revenue figures are sanitized or paraphrased to respect client confidentiality.
06  Why this matters

For hiring managers.

This is hands-on product design work. The business and leadership context explains why the decisions mattered, but the proof is the craft: flows, states, and an interface that makes the safe path the obvious one. It is not a claim that I can do everything. It is evidence that I can take a complex product environment and create clarity for a specific user.

A rippling glass residential tower rising against a washed white sky in New York.
Field note 04 · 8 Spruce Street, New York