Nestack Agent Care
Industries / Biotechnology / Oversight agent

Biotechnology AI agent · Research oversight

Research-Oversight & Attestation Evidence AI Agent

Track which projects belong to which review body, build the evidence pack behind a required attestation, and hold it for the named principal investigator — who determines the classification and signs it.

4–6 weeksTypical delivery
Your stackDeployment
Portfolio-widePI attestation
Agent CareAfter launch

What this agent does

Builds the record, never the determination

In
01

A proposal is drafted, and the agent sweeps it in — Executive Order 14292 (2025) does not stop at federal awards.

02

A sponsor deadline approaches, and the agent shows whether the attestation it needs exists and who owes it.

Reason
03

A project changes shape, and the agent reopens scope against the review body it was first scoped to.

04

A registration approaches the three-year limit in 42 CFR 73.7(l), and the agent shows the work behind it.

05

An amendment is filed, and the agent holds it as a blocking gate until approval returns — not as submitted.

Decide
06

A person is approved for access, and the agent starts the training clock on the earlier of the two dates.

07

A drill or plan review falls due, and the agent counts the security, biosafety and incident plans separately.

Out
08

A project closes, and its pack, its open items and the register it sat in are retained against the award.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent assembles the record and runs the clocks; a named principal investigator attests and a named institutional official certifies.

Example workflow

One proposal, scope to attestation

AgentHuman
1Proposal receivedGrants system, contract record, philanthropic gift or internal project registration
2Record assembledFunding source, sites, agents in use, registrations and training, each with its named source
3Evidence pack draftedScope questions, the review body, open items and confidence
4Controls appliedScope-sweep checks, registration and training currency, blocking amendments and confidence threshold
No human action required

Stages 1 to 4 run unaided, and nothing is attested or certified at any of them — the agent is assembling, and the investigator's lane opens at the confidence gate.

5DecisionBranches at the confidence threshold
High confidence

Goes to the principal investigator to read.

Low confidence

Adds a biosafety officer read first.

Investigator review

The pack is held with its sources, its open items and the confidence.

Approve · Edit · Send to the biosafety officer
Approved — released for attestation
6Oversight registers updatedOnly where write access and approval policy allow it
7Outcome evaluatedPack completeness, open-item outcomes, review-body turnaround and post-award corrections
Edits

Every investigator edit is counted, and so is every correction made after the award.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Determining whether a project is dangerous gain-of-function research.
Pre-filling, scoring or ranking a DGOF or IROC field.
Summarising, drafting or completing experimental methodology.
Attesting in writing to a classification.
Automation boundaryAgent acts unaided
Sweep the portfolio for projects that may be in scope.
Assemble the registration, training and inventory.
Run the registration, access, training, drill and reporting clocks.
Flag what needs review, and hold the pack for the named investigator.
Any write happens inside the boundaries agreed at implementation, never ahead of an attestation.
Certifying that an application is accurate and truthful.
Recording that a project does not need review.
Notifying CDC or APHIS of a theft, loss or release.
Changes to scope, registration or attestation rules.

Example output

One evidence pack, annotated

The pack is what the investigator reads before signing, and what is read back afterwards.

Evidence-pack output · single proposalIllustrative example
Project
Flag raised
Review body
Source of record
Confidence
Attribution
Non-federally funded study
The performance site changed after the review this project was scoped against
IBC · IRE
Subaward amendment
93%
Named investigator and role
As receivedTaken from the proposal record and the registration file — nothing on this side is written by the agent.
Evidence used Registration amendment Subaward site record IBC approval on file
Why this was flaggedIt flags a project for review and never clears one; a person decides.
ActionApproveEditSend to the biosafety officer
What the score decidesBelow the configured threshold the pack picks up a biosafety officer read first.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every projectFrom the proposal record
03Assembly

Assemble from the record

Draw on registrations, approvals, training records and inventories — never on protocols, a corpus that is dual-use in itself.

01Approved path

Flag it, never clear it

Registration, training and inventory evidence arrives gathered, with the clocks that expire it.

02Human review

Aim the review at what was missed

Projects that may be in scope are flagged for the review body; the agent never records that one does not need review.

04Build an evidence trail

The project, the review body it belongs to and the official who certified stay on the record.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Grants & proposalsCayuse · InfoEd
Huron · Kuali Research
Committee systemsIBC and IRE modules
Key Solutions · iRIS
Training & accessCITI Program records
Badge and access logs

Agent

Research oversight & attestation

Reads the record
Assembles the pack
Holds for the PI

Registration & inventorySelect-agent inventory
eFSAP registration file
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers between the model and the attestation

Six controls in sequence, widest first. What clears them all is drawn in the map beneath this.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to register assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and scope-rule changes, and the currency date of every rule read.Track
L4TraceabilityRecord the sources, the pack, the open items and the time it was released.Record
L3Investigator reviewHold packs for the named investigator; it governs release of the pack, not whether the attestation signed after it is right.Gate
L2Policy guardrailsTest packs against the configured scope, currency and record rules; a failure returns the pack.Restrict
L1Confidence thresholdsRoute low-confidence packs to a biosafety officer read before the investigator sees them.Require review
Model corePack assembled — scope questions, review body, open items and confidence
L1 – L2Test whether a pack may stand
L3Leaves the signature with the investigator
L4 – L5Keep the project and the body behind it
L6Narrows to register assembly when signals degrade

How Nestack evaluates it

Evaluate the oversight workflow — not only the finished pack.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the pack the investigator reads
Depth of coverage ▼
E1Final-output evaluationDid every item in the pack trace back to the record it came from?
E2Step-level evaluationDid the agent use the right project, review body and the rules in force that day?
E3Tool evaluationDid it read and write the correct project and the correct field?
E4Confidence calibrationDo low-confidence packs actually attract more investigator edits?
E5Slice evaluationHow does performance change across specific project types?
E6Business outcomeHow many packs needed an investigator edit or a correction after the award?
Floor — the outcome the institution answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, each placed at the stage where it originates.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
EJ-03

Superseded framework

Scope read from a policy that was replaced in 2025.

Stage gathersProposals, registrations, training records and rules
02 · Reasoning2 modes
EJ-04

Scope sweep too narrow

Privately funded work never enters the portfolio.

EJ-06

Amendment read as approved

Submitted is shown as cleared and the work starts.

Stage proposesScope questions, the review body and confidence
03 · Tool / write2 modes
EJ-02

Attestation never collected

The proposal goes out on the sponsor deadline.

EJ-05

Person-level clock missed

Access expires between two registration renewals.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
EJ-01

Flag ages in a queue

A flagged project waits and no review body convenes.

Stage returnsThe pack the investigator reads before signing
05 · Change / Version1 mode
EJ-07

Silent scope drift

A rule change narrows what the agent will flag.

Stage tracksModel, prompt, scope rules and review-body config
Sev-1 · a project ships without review Sev-2 · a wrong item reaches the pack Sev-3 · records degrade, pack goes to review

Affected slices

A whole-institution figure can hide one review body

An institution-wide scope-coverage figure can look acceptable while a few project cohorts absorb most of the rework behind it. Nestack reports the pack-rework rate by slice, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Non-federally funded projects7.8%3.6× Review
Foreign subaward sites5.6%2.6× Review
Select-agent registered work3.5%1.6× Watch
Single-site IBC projects1.4%0.7× Normal
Bar: pack-rework-rate lift vs. the single-site IBC baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

Each cycle leaves one more standing case

A cycle is done when the unreviewed project has become a case the next release must pass. That suite is what the next attestation prepared is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Pack-rework rate rises in a project slice.

02Diagnose

The project that changed shape after the review it was scoped against is read back until the cause narrows to one.

03Improve

Number the change; the projects that drove it are filed under it.

04Verify

Each touched register case is run once more, and one red holds it back.

05Learn

It stays as a standing test, and the scope rules move with it.

Learn → DetectThe return edge. The next proposal is worked against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, oversight workflow, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Oversight workflow and scope-boundary definition.
02Grants and committee source assessment.
03Scope-rule, registration and currency-clock mapping.
04Project-record ingestion and mapping.
05Register logic and record binding.
06Confidence scoring and pack routing.
07Investigator review workflow.
08Proposal and committee-system integration.
09Scope and currency cases.
10Guardrails and attestation controls.
11Register-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne programme, one committee ProductionProduction oversight systems AdvancedMultiple programmes / sites
Introduced at Pilot
Scope sweeps to your rules
Investigator review
Scope-coverage baseline
Introduced at Production
Reporting by review body
Review workflow in your systems
Approved write-back
Proposal-system integration
Introduced at Advanced
Multi-agency oversight rules
Multi-stage committee approvals
High proposal volume
Multi-programme oversight controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, proposal volume, review controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your project list and funding sources Project-record ingestion and mappingWeek 1
02Representative past proposals and packs Register baseline, scope extraction and record bindingWeek 2
03Your scope, registration and currency rule sources Scope-rule, registration and currency-clock mappingWeek 1
04Access to relevant APIs, feeds or exports Grants, committee and training assessment, then integration setupWeek 2
05Registers you would not want audited Scope cases and failure-mode testingWeek 4
06What no attestation may assume Confidence scoring, pack routing, guardrails and attestation controlsWeek 3
07Named investigators to read packs Investigator review workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

The plan sits on elapsed weeks rather than on slide space, so the overlap in week five is real.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Oversight workflow discovery, rule mapping and the scope boundary W2Grants, committee and training integration and the register baseline W3Oversight workflow, confidence logic and investigator-review controls W4Evaluation suite, scope-rule checks and failure-mode testing W5Registration-system integration, pilot projects and targeted corrections W6One award cycle run under the institutional official, then Agent Care handover
Reading the bandA bar covers the weeks its work is named in, and nothing else. The week 5 overlap is real, not padding.
At the end of W6When the register validates, Agent Care takes the agent on.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Biotechnology AI agent

Build an oversight agent that points at the project nobody sent to review.

The framework most institutions were scoped against was superseded on 5 May 2025 and not replaced until 28 July 2026, with agency implementation guidance still unissued as at 20 August 2026 — so we build on 42 CFR Part 73 and the NIH Guidelines and re-point the rest as it lands. Show us your proposal pipeline, your registrations and who signs, and we will map the scope sweep, the attestation register and the clocks. This sits before an experiment is designed: it governs whether work needs review and by whom, not how an approved campaign is planned or run.

Nestack Agents · Research oversightAGT-BT-15 · Agent Care available after launch