Assemble the governance record a facility already owes: the engineer of record file, readings set against their triggers, the review cycle and the deviations — then hold it for the people who sign.
An instrument reports, and the reading is pulled from supported piezometer, survey, inspection and SCADA sources.
02
A reading is set against the trigger level current on the day it was taken, not the level current today.
Reason
03
A review falls due, and the interval is the stricter of the cycles that apply to that facility, not one global number.
04
A raise is completed, and the record is rebuilt against the as-built survey rather than the design geometry.
05
A change is approved, and it joins the deviation record the deviance accountability report is drawn from.
Decide
06
An OMS review date passes, and the assumptions inside the EPRP are checked as well as the date on its cover.
07
A disclosure round opens, and each per-facility field is traced back to the engineer of record file behind it.
Out
08
A pack is retained as a dated version, beside the readings behind it and what each named signer was shown.
09
A write action runs only inside the approval boundaries agreed during implementation.
→Product statement
The agent assembles and keeps the record current; the engineer of record reviews and signs, and the accountable executive approves the design criteria.
Example workflow
One facility, reading to review
AgentHuman
1Readings receivedPiezometers, survey, inspection reports and SCADA history
2Record assembledTriggers, review dates, deviations and document currency, each with its named source
3Pack draftedSurveillance record, deviation log, open items and confidence
4Controls appliedTrigger tests, review-cycle checks, deviation completeness and confidence threshold
No human action required
Stages 1 to 4 run unaided, and nothing is certified at any of them — the agent is assembling a record, and the engineer lane opens at the confidence gate.
5DecisionBranches at the confidence threshold
High confidence
Goes to the engineer of record.
Low confidence
Adds a site read first.
Engineer review
The pack is held with its readings, its open items and the confidence.
Approve · Amend · Send to site review
Approved — released to the signers▼
6Governance record updatedOnly where write access and approval policy allow it
7Outcome evaluatedAmendment distance, open-item outcomes, review findings and post-disclosure corrections
Amendments
Every engineer amendment is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Certifying dam safety — the engineer of record.
Setting or revising a trigger level.
Clearing a TARP alarm, or standing one down.
Approving design criteria — the accountable executive.
Automation boundaryAgent acts unaided
✓Assemble the surveillance record against the triggers on file.
✓Track the review cycle the consequence classification sets.
✓Name deviations from the design basis report, and date them.
✓Check the OMS manual and the EPRP for currency, and hold the pack.
Writes run only inside the boundaries agreed at implementation, and never ahead of a signature.
Determining the consequence classification.
Predicting whether a facility will fail.
Notifying a regulator or a chief inspector.
Changes to trigger, review or approval rules.
Example output
One governance item, annotated
Everything the agent assembles is attached to the document it was drawn from.
Governance record output · single itemIllustrative example
Facility
Governance item
Time since review
Source of record
Confidence
Signer of record
Very high consequence
OMS manual annual review, read against its own date
11 months
OMS manual on file
86%
Engineer of record, named on the file
As receivedTaken from the OMS manual and the review log — nothing on this side is written by the agent.
Source facts usedOMS manual, datedAnnual review logCurrent DSR record
Why this is openThe annual review under GISTM 2020 Requirement 6.4 has a date, and this one has passed it.
ActionApproveAmendSend to site review
What the score decidesBelow the configured threshold the item picks up a site read before the engineer sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every facilityFrom the surveillance record
03Assembly
Read the data against the triggers
Readings are set beside the trigger levels already on file; the response stays with the TARP owner named in it.
01Approved path
The engineer of record signs
Design responsibility sits with the engineer of record — GISTM 2020, Requirement 10.4. Assembling evidence is not the review.
02Human review
Independence is the instrument
A dam safety review is independent by design — GISTM 2020, Requirement 10.5. The agent prepares what a reviewer reads and replaces neither.
04Build an evidence trail
The reading, the trigger it crossed and the engineer who reviewed stay on the surveillance file.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
A clean portfolio total can hide one facility class
A portfolio-wide trigger-response rate can read as healthy while a few facility classes carry most of the returned items. Nestack reports the return rate by facility class, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Extreme-consequence facilities
9.6%
3.7×
Review
Facilities raised in the year
7.4%
2.8×
Review
Facilities moving to closure
4.3%
1.7×
Watch
Stable, unraised facilities
1.9%
0.7×
Normal
Bar: return-rate lift vs. stable-facility baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
No cycle closes without a new test
A cycle closes when the missed trigger is a regression case. That suite is what the next surveillance pack assembled is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Return rate rises for one facility class.
02Diagnose
The reading that crossed a trigger on a Friday and was reviewed on a Tuesday is read back until the cause narrows to one.
03Improve
The change ships with a number, and the triggers that forced it travel beside it.
04Verify
Nothing releases while one touched surveillance case is still red.
05Learn
It is kept for good, and the trigger rules are amended in the same commit.
Learn → DetectThe return edge. The next cycle runs against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, governance workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Governance workflow discovery and boundary mapping.
02Instrumentation and document assessment.
03Trigger, review-cycle and deviation rule mapping.
04Reading ingestion and reconciliation.
05Pack assembly and source binding.
06Confidence scoring and exception routing.
07Engineer review workflow.
08Instrumentation and document integration.
09Trigger and surveillance cases.
10Guardrails and review controls.
11Surveillance-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne facility, one cycleProductionProduction monitoring systemsAdvancedMultiple sites / jurisdictions
Introduced at Pilot
Governance record and reconciliation✓✓✓
Engineer-of-record approval✓✓✓
Trigger-coverage baseline✓✓✓
Introduced at Production
Reporting by facility—✓✓
Exception workflow in your systems—✓✓
Approved write-back—✓✓
Instrumentation integration—✓✓
Introduced at Advanced
Multi-jurisdiction cycle rules——✓
Multi-stage governance approvals——✓
High facility count——✓
Multi-facility review controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, facility count, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your facility list and consequence classes→Trigger, review-cycle and deviation rule mappingWeek 1
02Representative prior annual packs→Reading ingestion, reconciliation and the assembly baselineWeek 2
03Your design basis reports and OMS manuals→Governance-record mapping and automation-boundary definitionWeek 1
04Access to relevant APIs, feeds or exports→Instrumentation and document assessment, then integration setupWeek 2
05Surveillance packs you would not want read back→Trigger cases and failure-mode testingWeek 4
06What no dam-safety review may omit→Confidence scoring, exception routing, guardrails and review controlsWeek 3
07Named engineers of record to review the pack→Engineer review workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The bands sit on the weeks each phase genuinely fills, which is why the fifth of them carries two.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Governance workflow discovery, rule mapping and the automation boundaryW2Source integration and the reconciliation baselineW3Assembly workflow, confidence logic and review controlsW4Evaluation suite, trigger checks and failure-mode testingW5Instrumentation integration, a pilot facility and targeted correctionsW6One surveillance cycle run under the engineer of record, then Agent Care handover
Reading the bandA bar spans only the weeks its own work is named in. The week 5 overlap is real, not padding.
At the end of W6Validation closes on live facilities, and Agent Care picks up the monitoring.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Mining AI agent
Build the governance record before the next review falls due.
Show us your facilities, your trigger levels and who signs. If your evidence was built to carry a self-assessment, then it has not yet been asked the question a third-party assessor asks at every criterion — which record shows this.