Marshal the vulnerability assessment behind each actionable process step under § 121.130, run the § 121.157 reanalysis clock, and hold the plan for the owner, operator or agent in charge who signs it.
A step is assessed, and § 121.130 wants the inside attacker weighed, not the stranger alone.
02
A step turns actionable, and § 121.135 wants a written explanation of how a strategy prevents it.
Reason
03
A strategy is monitored, and § 121.140 wants the written procedure and its frequency on file.
04
A strategy fails, and § 121.145 wants the problem corrected and recurrence made less likely.
05
A record is verified, and § 121.150 wants monitoring and corrective-action entries read in time.
Decide
06
A plan is reanalysed, and § 121.157 sets the three-year interval plus four forced triggers.
07
A change is planned, and § 121.157 wants reanalysis before it is operative, or inside ninety days.
Out
08
A plan is modified, and § 121.310 brings the owner, operator or agent in charge back to sign.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
The agent assembles evidence and tracks the reanalysis clocks. The owner, operator or agent in charge signs and dates the written plan under § 121.310.
2Step context assembledThe step, its public-health impact, the physical access it allows and the strategy on it
3Assessment evidence draftedThe steps assessed, the explanations written, the gaps and completeness
4Controls appliedReanalysis-clock checks, strategy-coverage checks, record-currency checks and completeness confidence
No human action required
Stages 1 to 4 run unaided, and nothing is signed at any of them — the agent is assembling, and the defence lane opens at the completeness gate.
5DecisionSplits at the completeness gate
Evidence sufficient
Goes to the owner, operator or agent in charge to sign.
Anything thin
Adds a food defence read first.
Food defence review
The plan is held with its steps, its strategies and the explanations behind them.
Sign · Append evidence · Send to food defence review
Signed and dated — under § 121.310▼
6Plan and training records updatedOnly where write access and records policy allow it
7Outcome evaluatedStrategy coverage, reanalysis timing, reviewer corrections and what the read found
Corrections
Each food defence correction is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Signing and dating the plan under § 121.310.
Preparing the food defence plan under § 121.126.
Conducting the vulnerability assessment, § 121.130.
Identifying mitigation strategies under § 121.135.
Automation boundaryAgent acts unaided
✓Assemble the evidence behind every actionable step.
✓Track the three-year clock and its forced triggers.
✓Chase the written explanation a mitigation strategy still lacks.
✓Flag the process step whose strategy coverage cannot be shown.
Nothing is signed or reanalysed except by a named person, inside agreed boundaries.
Reanalysing the plan as a whole under § 121.157.
Concluding that no revision to the plan is needed.
Writing the justification for a longer timeframe.
Changes to plan, training or monitoring records.
Example output
One process step, annotated
Staggered compliance closed on 26 July 2019, 27 July 2020 and 26 July 2021; this record is what one actionable process step carried afterwards.
Plan evidence · single process stepIllustrative example
Process step
Recorded as
Step class
Evidence of record
Confidence
Held for
Bulk liquid receiving, § 121.130
Assessed actionable, inside attacker weighed
Actionable step
Vulnerability assessment, 3 August 2026
Held unsigned
The owner, operator or agent in charge
As receivedTaken from the plant's own process maps and access records — it reaches as far as those sources do.
What the record holdsAccess recordStrategy explanationMonitoring entry
Why no signature hereWhether the plan may be signed is a § 121.310 act reserved to a person.
ActionSignAppend evidenceSend to food defence review
What the score decidesBelow the configured threshold the plan picks up a defence read before the signer sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every process stepFrom the map that names it
03Evidence
Where the evidence is used
Our QA and HACCP assistant works the same facility, the same signer phrase and the same plan, monitor, verify and reanalyse skeleton on a different threat model — Part 121 is the inside attacker at an actionable process step, not a food-safety hazard.
01Approved path
Two signings, one plan
§ 121.310 fires on initial completion and on any modification, and § 121.301 holds that signature to the written plan alone.
02Human review
What was checked, and not found
Food defense qualified individual could not be verified as codified CFR text, and § 121.3 was not retrieved verbatim; the operative construct is the qualified individual plus § 121.4(c) training at least equivalent to an FDA-recognised curriculum, with § 121.4(b) awareness training and § 121.4(e) records.
04Build an evidence trail
The step, the strategy guarding it and the officer who dated the plan stay together.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Process maps and plant accessSite layout · badge logs Actionable process steps
Monitoring and corrective actionsQuality systems · e-forms Deviation and correction logs
Training and personnelLMS · HR records § 121.4(e) training records
Agent
Food defence plan evidence
Reads the steps Assembles the evidence Holds for the signer
Verification and records reviewRecords review · audits Reanalysis triggers and dates
Integration availability depends on the client's existing systems and API access.
Agent controls
Six screens between the model and the signature
Six screens, and the last of them is the tightest. What still gets through is drawn in the map below.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to evidence assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and plan rules; no change to Part 121 was located for 2025 or 2026, and 90 FR 46610 of 29 September 2025 is a paperwork notice only.Track
L4TraceabilityRecord each step, its strategy and every read of the set; § 121.305 wants entries made concurrently and initialled by whoever performed the activity.Record
L3Officer releaseHold the plan for the owner, operator or agent in charge; the hold governs release, not whether the assessment behind it was right.Gate
L2Scope guardrailsTest the evidence against §§ 121.126, 121.130, 121.135 and 121.157; the enforcement discretion of 14 March 2022 still covers reanalysis after a single corrected failure.Restrict
L1Confidence thresholdsRoute a thin evidence set to a defence read first; the industry guidance is still three draft instalments from 13 February 2020.Require review
Model coreEvidence assembled — the step, the strategy, the explanation and completeness
L1 – L2Test whether a plan may stand
L3Puts the signature in a person's hands
L4 – L5Keep the step and the strategy behind it
L6Holds the plan unsigned when signals degrade
How Nestack evaluates it
Evaluate the whole assembly — not only the plan evidence that comes out.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the plan an inspector reads
Depth of coverage ▼
E1Final-output evaluationDid the evidence record what each process step actually carried?
E2Step-level evaluationDid the agent read the right step, the right strategy and the plan version in force?
E3Tool evaluationDid it read and write the correct step record and the correct strategy?
E4Confidence calibrationDo low-confidence evidence sets actually attract more defence corrections?
E5Slice evaluationHow does performance change across specific process steps?
E6Business outcomeHow many sets needed a correction before the officer signed?
Floor — the plan the facility answers for
Failure modes
Where each failure originates in the agent
Seven failure modes, each set at the stage where it first surfaces.
Agent lifecycleDirection of processing →
01 · Retrieval1 mode
JM-03
Stale process map read
The layout read is not the one now on the floor.
Stage gathersThe steps, the strategy, the record and the date
02 · Reasoning2 modes
JM-04
Step asserted, not shown
A step is called covered without its explanation.
JM-06
Draft guidance read as final
The draft instalments are worked as binding.
Stage proposesThe steps, their strategies and completeness
03 · Tool / write2 modes
JM-02
Thin set passed forward
A set moves on without the defence read.
JM-05
Evidence bound to wrong step
A record is filed against the wrong step.
Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
JM-01
Signed, evidence unrecorded
The plan shows a signature but not what supported it.
Stage returnsThe plan an officer signs and an inspector reads
05 · Change / Version1 mode
JM-07
Silent trigger regression
A configuration change moves the trigger, not the plan.
Stage tracksModel, prompt, plan rules and evidence fields
Sev-1 · a plan signed on no evidenceSev-2 · wrong evidence reaches the planSev-3 · source degrades, plan holds unsigned
A step-level mitigation-coverage figure can read clean while bulk liquid receiving carries most of the rework. Nestack reports the correction rate by process step, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Bulk liquid receiving and holding
10.6%
3.7×
Review
Steps worked by temporary personnel
7.5%
2.6×
Review
Secondary ingredient handling
4.7%
1.6×
Watch
Steps under continuous supervision
2.2%
0.8×
Normal
Bar: correction-rate lift vs. supervised-step baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What an unreanalysed change costs
A cycle shuts when the unreanalysed change is a regression case. That suite is what the next plan assembled is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Correction rate rises on bulk liquid receiving.
02Diagnose
The step where a stranger could reach the batch, and the plan that never named it, are read back until one cause remains.
03Improve
The change ships numbered, and the steps that forced it ride with it.
04Verify
Nothing releases while one touched step case is still red.
05Learn
It is retained for good, and the plan rules are amended in that same commit.
Learn → DetectThe return edge. The next plan is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, evidence assembly, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Process-step discovery and automation-boundary work.
02Access, monitoring and training sources.
03Step-to-strategy and reanalysis-trigger mapping.
04Step and strategy evidence ingestion.
05Step, strategy and record binding.
06Completeness scoring and review routing.
07Owner and operator signing workflow.
08Training and quality-system integration.
09Vulnerability and reanalysis cases.
10Guardrails and signing controls.
11Plan-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne facility, one planProductionProduction defence workflowAdvancedMultiple facilities / plans
Introduced at Pilot
Evidence assembly to your steps✓✓✓
Owner, operator or agent release✓✓✓
Process-step inventory baseline✓✓✓
Introduced at Production
Reporting by process step—✓✓
Signing workflow in your systems—✓✓
Approved write-back—✓✓
Training-record integration—✓✓
Introduced at Advanced
Multi-site plan sets——✓
Cross-step evidence packs——✓
Large step registers——✓
Multi-trigger reanalysis controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, step register size, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your registered facilities and their process steps→Step inventory mapping and evidence captureWeek 1
02Representative access, monitoring and training records→Record binding, trigger logic and the evidence baselineWeek 2
03Your vulnerability assessment under § 121.130→Step mapping, strategy binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Access, monitoring and training-source assessment, then integration setupWeek 2
05Plans you would not want inspected→Reanalysis cases and failure-mode testingWeek 4
06What no defence plan may establish→Completeness scoring, review routing, guardrails and release controlsWeek 3
07An owner, operator or agent in charge to sign→Signing workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Every band below is real working time and not layout, which is why the fifth of them has to hold two.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Defence plan discovery, step mapping and the automation boundaryW2Source integration and the strategy-coverage baselineW3Evidence assembly, trigger logic and release controlsW4Evaluation suite, reanalysis cases and failure-mode testingW5Record integration, pilot plans and targeted correctionsW6One reanalysis cycle run under the plant manager, then Agent Care handover
Reading the bandEach bar spans only the weeks its own work is named for. The fifth carries a pair because the work does.
At the end of W6Validation closes on live plans, and Agent Care picks up the watch.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Food & Beverage AI agent
Build a food defence agent around the plan your officer has to sign and date.
Show us one actionable process step and the explanation behind its strategy. If a change went operative before the plan was reanalysed, then § 121.157 ran unmet and § 121.401 makes that a prohibited act. Preventive-controls monitoring is a different agent.