Nestack Agent Care
Industries / Telecom / Provisioning agent

Telecom AI agent · Provisioning & eSIM

Provisioning, Activation & eSIM AI Agent

Assemble an activation or an eSIM profile transfer from the identity evidence your market requires, run the configured checks, and hold — a provisioning person decides whether the profile moves.

4–6 weeksTypical delivery
Your stackDeployment
Evidence-boundDesk approval
Agent CareAfter launch

What this agent does

Does the activation work, not the identity call

In
01

Ingest the activation request and the market rules from supported ordering or CRM sources.

02

Normalise the identifiers the activation turns on and carry each forward with its record.

Reason
03

Assemble the identity evidence the market configuration requires, and name what is missing.

04

Apply the carrier's configured authentication, eligibility and registration rules for that market.

05

Bind each check to the evidence it ran against, and mark what the account leaves unresolved.

Decide
06

Recognise that a code sent to the number being changed cannot authenticate the change to it.

07

Route any transfer that would move a number to a different device to the provisioning desk.

Out
08

Retain the request, the evidence, the checks, the timestamps and the approval.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent assembles and checks; a provisioning person decides whether a profile moves, and the carrier stays the party the CPNI rules bind.

Example workflow

One activation, request to approval

AgentHuman
1Activation request receivedRetail counter, app self-service, care system or a device-initiated profile transfer
2Evidence assembledAccount record, the identity evidence that market requires, device and eUICC identifiers
3Activation preparedProfile, evidence, checks and confidence
4Controls appliedAuthentication checks, market registration rules, transfer checks and confidence threshold
No human action required

Stages 1 to 4 run unaided and no profile moves at any of them — the agent is preparing, and the desk's lane opens at the confidence gate.

5DecisionBranches at the confidence threshold
High confidence

Goes to the provisioning desk to approve.

Low confidence

Adds an identity check first.

Provisioning approval

The activation is held with its evidence, its flags and the confidence.

Approve · Correct · Send to identity review
Approved — profile released
6Provisioning systems updatedOnly where write access and approval policy allow it
7Outcome evaluatedEvidence completeness, desk corrections, customers left without service and later reversals
Corrections

Every desk correction is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Completing a transfer without the configured evidence.
Using a code sent to the number being changed alone.
Changing the authentication rules an officer certifies.
Lifting an identity hold another team has placed.
Automation boundaryAgent acts unaided
Assemble the activation from the configured identity evidence.
Carry each piece of evidence forward with the record it came from.
Run the identity and eligibility checks configured.
Flag what a person must decide, hold there, and show.
Any write happens inside the boundaries agreed at implementation, never ahead of an approval.
Deciding which identity documents a market requires.
Treating eUICC certification as proof of key custody.
Barring, suspending or restoring a line in service.
Changes to identity, market or approval rules.

Example output

One activation, annotated

Everything the agent proposes is attached to the evidence it was read from.

Activation output · single subscriptionIllustrative example
Request
Action
Market
Evidence set
Confidence
Authentication
eSIM transfer
Profile moved from the registered device to a new handset
US · no ID mandate
Configured for this market
93%
Not a code sent to this number
As receivedTaken from the account record and the evidence captured with the request.
Evidence used Account record match Photo ID seen in store Registered device identifiers
Why this evidenceThe carrier's configuration sets it — the federal SIM-change rules carry no compliance date.
ActionApproveCorrectSend to identity review
What the score decidesBelow the configured threshold the activation picks up an identity check before.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every activation requestFrom the request and the record
03Preparation

Build from the evidence

Use the account record, the identity evidence that market requires and the carrier's configured authentication rules.

01Approved path

Provision what was authorised

Routine activations arrive assembled, checked and ready to approve.

02Human review

Send the desk to what needs deciding

Flagged transfers and low-confidence requests are marked, so the desk's time goes where a decision is actually owed.

04Build an evidence trail

The activation, the identity evidence behind it and the person who released it stay on the subscription.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Provisioning and OSSHSS / UDM · HLR
Provisioning gateway · activation APIs
eSIM platformSM-DP+ · SM-DS
LPA · eUICC estate · IoT eIM
CRM and careSalesforce · Dynamics 365
Zendesk · ServiceNow

Agent

Provisioning & activation

Reads the evidence
Prepares the activation
Stops for approval

Identity and registrationDocument capture · ID checks
Market registration systems
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers between the model and the profile

Each layer contains the next. What gets past the set is listed in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to preparing and reporting when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt, identity-rule and market-configuration changes.Track
L4TraceabilityRecord the request, the evidence, the checks, the flags and the approval.Record
L3Provisioning approvalA person decides whether a profile moves; it governs who decides, not whether the evidence was sound.Gate
L2Identity guardrailsTest the request against the configured evidence rules; a failure returns it to the desk.Restrict
L1Confidence thresholdsRoute low-confidence activations to an identity check; confidence is not a reading of intent.Require review
Model coreActivation prepared — profile, evidence, checks and confidence
L1 – L2Test whether an activation may stand
L3Puts the release in a person's hands
L4 – L5Keep the activation and the evidence behind it
L6Reduces to status lookup when signals degrade

How Nestack evaluates it

Evaluate the whole activation workflow — not only the profile that installed.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the activation the customer gets
Depth of coverage ▼
E1Final-output evaluationDid the activation carry the evidence that market requires?
E2Step-level evaluationDid the agent read the right account, market rules and identity configuration?
E3Tool evaluationDid it read and write the correct subscription and the correct profile?
E4Confidence calibrationDo low-confidence activations actually attract more desk corrections?
E5Slice evaluationHow does performance change across specific request types?
E6Business outcomeHow many activations needed a desk correction, and how many customers lost service they should have kept?
Floor — whether the right person got the line

Failure modes

Where each failure originates in the agent

Seven failure modes, placed at the stage each one originates.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
WZ-03

Stale identity evidence

Evidence read from a superseded account record.

Stage gathersAccount record, identity evidence
02 · Reasoning2 modes
WZ-04

Circular authentication

A code sent over the number being changed is accepted as the factor.

WZ-06

Wrongful lockout

A legitimate customer is left without their own number.

Stage proposesThe activation, its evidence and the confidence
03 · Tool / write2 modes
WZ-02

Transfer without evidence

A profile moves while required identity evidence is missing.

WZ-05

Duplicate profile issued

The same subscription is provisioned onto two profiles.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
WZ-01

Certification read as assurance

Certified hardware is treated as proof of key custody.

Stage returnsThe activation the desk approves and
05 · Change / Version1 mode
WZ-07

Silent identity regression

A model or rule change loosens what evidence the agent accepts.

Stage tracksModel, prompt, identity rules and market config
Sev-1 · moves outside the boundary Sev-2 · a customer is locked out Sev-3 · evidence degrades, activation routes to the desk

Affected slices

Overall accuracy can hide one bad cohort

The slice an aggregate hides is the customer locked out of their own number: they cannot receive the code that would prove who they are The cohorts that carry it are named, not averaged away..

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Transfers that locked a customer out7.2%3.2× Review
Device-to-device profile transfers5.2%2.3× Review
Activations in registration markets3.1%1.4× Watch
Standard in-store activations1.8%0.8× Normal
Bar: desk-correction-rate lift vs. the all-activations baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

The cycle ends in a case, not a note

Nothing closes because it was understood. It closes when the next release has to pass a case, and that suite is what the next activation is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Desk-correction rate rises in an activation slice.

02Diagnose

Which evidence did the agent accept? The desk reads the activations behind the rise until the cause narrows to one.

03Improve

Changes ship against a version with the activations that caused them.

04Verify

A failing case blocks release until it clears.

05Learn

The case is permanent, and the identity rules move with it.

Learn → DetectThe return edge. The next cycle is measured against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, activation workflow, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Activation workflow discovery and automation-boundary definition.
02Provisioning and eSIM source assessment.
03Per-market identity-evidence and authentication mapping.
04Request ingestion and normalisation.
05Evidence assembly and check logic.
06Confidence scoring and desk routing.
07Provisioning approval workflow.
08Provisioning and eSIM platform integration.
09Profile-transfer regression cases.
10Guardrails and identity controls.
11Activation-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne market, one activation path ProductionProduction provisioning systems AdvancedMultiple markets / brands
Introduced at Pilot
Activation prepared on your rules
Provisioning approval
Activation-accuracy baseline
Introduced at Production
Reporting by activation channel
Desk workflow in your systems
Approved write-back
Provisioning-stack integration
Introduced at Advanced
Multi-market activation rules
Multi-stage provisioning approvals
High activation volume
Multi-market identity controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your activation paths and account record structure Request ingestion and identifier mappingWeek 1
02Representative completed activations and transfers Check baseline, evidence extraction and record bindingWeek 2
03Your per-market identity and authentication rules Per-market identity and authentication rule mappingWeek 1
04Access to relevant APIs, feeds or exports Provisioning and eSIM assessment, then integration setupWeek 2
05Activations you would not want completed Transfer cases and failure-mode testingWeek 4
06What must reach a person before a profile moves Confidence scoring, desk routing, guardrails and identity controlsWeek 3
07Named provisioning staff to approve activations Provisioning approval workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

Each band covers the weeks it genuinely occupies, so the fifth week holds two kinds of work.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Activation workflow discovery, identity mapping and the automation boundary W2Provisioning and eSIM integration and the check baseline W3Activation workflow, confidence logic and approval controls W4Evaluation suite, lockout cases and failure-mode testing W5Provisioning integration, pilot activations and targeted corrections W6One activation cycle run under the provisioning desk, then handover
Reading the bandEach band spans only the weeks its work is named in. The fifth week genuinely carries two kinds of work.
At the end of W6Live activations close the validation and monitoring moves to Agent Care.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Telecom AI agent

Build a provisioning agent around the evidence your markets require.

Show us your activation paths, your market identity rules and who approves a transfer. An officer of your company signs your authentication procedures every year, so the agent works inside that configuration and never changes it.

Nestack Agents · Provisioning & activationAGT-TL-07 · Agent Care available after launch