Inventory the OT estate without probing it, triage each advisory against the models actually installed and actually reachable, and hold every proposed change for a named controls engineer.
A plant-wide patch percentage can look acceptable while a small number of cells carry most of the untriaged exposure. Nestack reports the amendment rate by slice, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Legacy cells with no capture
9.6%
3.7×
Review
Remote-access endpoints
6.8%
2.6×
Review
Vendor-managed skids
4.4%
1.7×
Watch
Standard monitored cells
2.4%
0.9×
Normal
Bar: amendment-rate lift vs. standard-cell baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
Nothing closes until a test exists
The loop shuts when the missed exposure is a regression case, not when it has been explained. That suite is what the next advisory triaged is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Amendment rate rises in a cell slice.
02Diagnose
The advisory that named a controller nobody could find is traced through records, never the wire, to one cause.
03Improve
Any change goes out numbered, and the advisories that caused it are attached.
04Verify
The release waits on the touched advisory cases clearing a second run.
05Learn
One case added to the suite, one line added to the asset record.
Learn → DetectThe return edge. The next advisory is triaged against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, triage workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01OT asset discovery and monitoring boundary definition.
02Passive-source and feed assessment.
03Zone, conduit and escalation-criteria mapping work.
04Asset-record ingestion and normalisation.
05Advisory matching and exposure logic.
06Confidence scoring and case routing.
07Engineer disposition workflow.
08Monitoring and ticketing integration.
09Advisory and exposure cases.
10Guardrails and escalation controls.
11Asset-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne cell, one siteProductionProduction OT monitoringAdvancedMultiple sites / estates
Introduced at Pilot
Triage to your assets and zones✓✓✓
Engineer disposition✓✓✓
Inventory-coverage baseline✓✓✓
Introduced at Production
Reporting by cell—✓✓
Disposition workflow in your systems—✓✓
Approved ticket write-back—✓✓
Passive-collector integration—✓✓
Introduced at Advanced
Multi-zone segmentation rules——✓
Multi-stage change approvals——✓
High advisory volume——✓
Multi-site segmentation controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your asset register and zone drawings→Asset-record ingestion and zone mappingWeek 1
03Your written escalation criteria→Zone, conduit and escalation-rule mappingWeek 1
04Access to relevant APIs, feeds or exports→Passive-source and feed assessment, then integration setupWeek 2
05Exposures you would not want dismissed→Incident cases and failure-mode testingWeek 4
06What no triage may assume→Confidence scoring, case routing, guardrails and escalation controlsWeek 3
07A named controls engineer to rule on cases→Engineer disposition workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The chart follows the plant rather than the slide, so evaluation and pilot both land in week 5.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1OT discovery, zone mapping and the automation boundaryW2Passive-source integration and the triage baselineW3Triage workflow, confidence logic and disposition controlsW4Evaluation suite, exposure checks and failure-mode testingW5Ticketing integration, pilot advisories and targeted correctionsW6One patch window run under the controls engineer, then Agent Care handover
Reading the bandEach band covers only the weeks its work is named in. The week 5 overlap is real, not padding.
At the end of W6Once the window validates, Agent Care owns the running agent.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Manufacturing AI agent
Build an OT triage agent around your controls engineer's authority.
In OT, looking can stop the line, so nothing here touches a device. Show us your cells, your advisory backlog and the engineer who signs a change, and we'll set the boundary.