Nestack Agent Care
Industries / Travel & Hospitality / ATOL protection agent

Travel & Hospitality AI agent · ATOL protection

ATOL Financial Protection AI Agent

Sift every booking for whether it is licensable under SI 2012/1017, tie each protection contribution to the booking that raised it, and hold the return for the ATOL Reporting Accountant who signs it.

4–6 weeksTypical delivery
Your stackDeployment
One signatureNamed ARA
Agent CareAfter launch

What this agent does

Assembles the schedules, never the signature

In
01

A booking is taken, and reg 9 of SI 2012/1017 decides whether flight accommodation was made available.

02

A booking is licensable, and the per-passenger protection contribution attaches to it, not to the traveller.

Reason
03

A reporting period closes, and the contribution reaches the Air Travel Trust inside six weeks.

04

A remittance is made, and the Contributions to the Air Travel Trust Regulations 2007 govern it.

05

A renewal date falls, and the application and the accountants report are due 1 August or 1 February.

Decide
06

A licence expires ungranted, and the CAA publishes your name and licensable business must stop.

07

A package is sold, and SI 2018/634 runs beside the ATOL licence rather than in place of it.

Out
08

A schedule is requested, and only an individually registered reporting accountant may sign for it.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent classifies bookings and tracks the clocks. A registered ATOL Reporting Accountant signs the Annual Accountants Report; the licence holder remits.

Example workflow

One booking, evidence to signature

AgentHuman
1Booking evidence receivedReservation exports, trust-account entries, contribution returns or trading projections
2Booking context assembledThe booking, whether it is licensable, the licence it sits under and the period it falls in
3Return evidence draftedThe bookings classified, the contributions tied to them, the gaps and completeness
4Controls appliedRenewal-clock checks, remittance-clock checks, classification checks and completeness confidence
No human action required

Stages 1 to 4 run unaided, and nothing is signed at any of them — the agent is assembling, and the finance lane opens at the completeness gate.

5DecisionSplits at the completeness gate
Evidence sufficient

Goes to the ATOL Reporting Accountant to sign.

Anything thin

Adds a finance read first.

Finance review

The return is held with its bookings, its contributions and the schedules behind them.

Sign · Append evidence · Send to finance review
Signed — by a registered ARA
6Booking and contribution records updatedOnly where write access and records policy allow it
7Outcome evaluatedClassification accuracy, contribution coverage, reviewer corrections and what the read found
Corrections

Each finance correction is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Signing the Annual Accountants Report.
Certifying a renewal application to the CAA.
Remitting the contribution to the Trust.
Deciding that a booking is not licensable.
Automation boundaryAgent acts unaided
Assemble the schedules a reporting accountant is going to request.
Track the renewal clock and the remittance clock.
Tie every protection contribution to its own booking.
Flag the booking whose licensable status the records cannot settle.
Nothing is signed or remitted except by a named person, inside the agreed boundaries.
Judging whether a return may be signed.
Telling the CAA that a licence is in order.
Setting the licence type a holder trades under.
Changes to bookings, returns or trust records.

Example output

One booking, annotated

The renewal peaks fall on 1 August and 1 February; this record is what a single booking carried into the return.

Return evidence · single bookingIllustrative example
Booking
Recorded as
Licence class
Evidence of record
Confidence
Held for
Flight-inclusive package, reg 9
Classified licensable, contribution attached
Standard ATOL
Booking record, 3 August 2026
Held unsigned
A registered ATOL Reporting Accountant
As receivedTaken from the reservation export and the trust-account entry — it reaches as far as those sources do.
What the record holds Booking record Contribution return Trust-account entry
Why no signature hereWhether the return may be signed is an act reserved to a registered ARA.
ActionSignAppend evidenceSend to finance review
What the score decidesBelow the configured threshold the return picks up a finance read before the ARA sees it.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every bookingFrom the system that sold it
03Evidence

Where the evidence is used

Our group sales agent signs a contractual response to a planner from an approved rate library; this is a licence condition enforced by a regulator that can stop you trading.

01Approved path

The accountant must be named

A firm cannot stand in for the person: "All ATOL reporting needs to be signed by an ARA," and the ARA registers individually with ACCA, AIA, ICAEW, ICAI, ICAS or IFA.

02Human review

What was checked, and not found

The timing wording of reg 17, the accountants report deadline expressed in months after the accounting reference date, and which ATOL Standard Term governs that report were all checked and none was confirmed.

04Build an evidence trail

The booking, the contribution it attracted and the accountant who signed stay on the return.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Reservation and bookingBooking engine · PMS
Tour operator systems
Finance and ledgerManagement accounts
Revenue and passenger splits
Trust and bondingTrust-account statements
Bond and insurance evidence

Agent

ATOL financial protection

Reads the bookings
Assembles the return
Holds for the accountant

Contributions and returnsPortal exports · returns
Air Travel Trust remittances
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six sifts between the model and the accountant

Six sifts over the same file, each one finer than the last. Whatever remains is set out in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to evidence assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and licence rules; as of 24 August 2026 the scheme stands unchanged, and ATIPAC reports that the preferred-options consultation on reform has not yet happened.Track
L4TraceabilityRecord each booking, the contribution it attracted, the schedule it feeds and every read of the return.Record
L3Accountant releaseHold the return for a registered ATOL Reporting Accountant; the hold governs release, not whether the figures beneath it are right.Gate
L2Scope guardrailsTest the evidence against SI 2012/1017 and the Contributions to the Air Travel Trust Regulations 2007 as configured.Restrict
L1Confidence thresholdsRoute a thin return to a finance read first; reg 19 leaves the form and content of an ATOL Certificate to CAA publication, so the binding spec moves.Require review
Model coreEvidence assembled — the bookings, the contributions, the schedules and completeness
L1 – L2Test whether a return may stand
L3Puts the signature in a person's hands
L4 – L5Keep the booking and the contribution behind it
L6Holds the return unsigned when signals degrade

How Nestack evaluates it

Evaluate the whole assembly — not only the return evidence that comes out.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the return the CAA reads
Depth of coverage ▼
E1Final-output evaluationDid the evidence record what each booking actually attracted?
E2Step-level evaluationDid the agent read the right licence, the right period and the live booking record?
E3Tool evaluationDid it read and write the correct booking and the correct contribution?
E4Confidence calibrationDo low-confidence returns actually attract more finance corrections?
E5Slice evaluationHow does performance change across specific booking classes?
E6Business outcomeHow many returns needed a correction before the accountant signed?
Floor — the licence the holder answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, each set at the stage where it first appears.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
JW-03

Stale booking read

The reservation read is not the one now on the licence.

Stage gathersThe bookings, the licence, the periods and the dates
02 · Reasoning2 modes
JW-04

Booking asserted, not shown

A booking is called licensable without its record.

JW-06

Stalled reform read as live

Reform proposals are worked as though in force.

Stage proposesBookings, their contributions and completeness
03 · Tool / write2 modes
JW-02

Thin return passed forward

A return moves on without the finance read.

JW-05

Bound to the wrong booking

A remittance is filed against the wrong booking.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
JW-01

Signed, evidence unrecorded

The return shows a signature but not what supported it.

Stage returnsThe return an accountant signs and the CAA reads
05 · Change / Version1 mode
JW-07

Silent clock regression

A configuration change moves the deadline, not the return.

Stage tracksModel, prompt, licence rules and return fields
Sev-1 · a return signed on no evidence Sev-2 · wrong evidence reaches the return Sev-3 · source degrades, return holds unsigned

Affected slices

Flight-inclusive packages absorb the corrections

A licence-level contribution-completeness figure can read clean while flight-inclusive packages carry most of the rework. Nestack reports the correction rate by booking class, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Flight-inclusive packages10.9%3.7× Review
Agency sales for another holder7.8%2.6× Review
Dynamic and split-contract sales4.8%1.6× Watch
Seat-only sales outside the licence2.3%0.8× Normal
Bar: correction-rate lift vs. seat-only baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

What a missed renewal costs

A cycle shuts when the unremitted contribution is a regression case. That suite is what the next return assembled is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Correction rate rises on flight-inclusive packages.

02Diagnose

The renewal date that arrived while the accountant was still waiting on a schedule is read back until one cause remains.

03Improve

The change ships numbered, and the bookings that forced it ride with it.

04Verify

Nothing releases while one touched booking case is still red.

05Learn

It is retained for good, and the return rules are amended in that same commit.

Learn → DetectThe return edge. The next licence year is measured against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, return assembly, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Licensable-booking discovery and boundary work.
02Booking, ledger and trust sources.
03Booking-to-contribution and renewal-clock mapping.
04Booking and contribution ingestion.
05Booking, licence and record binding.
06Completeness scoring and review routing.
07Reporting accountant signing workflow.
08Booking and ledger-system integration.
09Contribution and certificate cases.
10Guardrails and signing controls.
11Return-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne licence, one year ProductionProduction renewal workflow AdvancedMultiple licences / entities
Introduced at Pilot
Return assembly to your bookings
Reporting accountant release
Licensable-booking baseline
Introduced at Production
Reporting by licence
Signing workflow in your systems
Approved write-back
Booking-system integration
Introduced at Advanced
Multi-licence groups
Cross-period evidence packs
Large booking registers
Multi-deadline renewal controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, booking volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your licences and the bookings sold under each Booking inventory mapping and evidence captureWeek 1
02Representative booking, ledger and trust records Record binding, contribution logic and the return baselineWeek 2
03Your classification rules under reg 9 and reg 10 Booking mapping, contribution binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports Booking, ledger and trust-source assessment, then integration setupWeek 2
05Returns you would not want reviewed Contribution cases and failure-mode testingWeek 4
06What no accountants report may establish Completeness scoring, review routing, guardrails and release controlsWeek 3
07A registered ATOL Reporting Accountant to sign Signing workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

The bands below are weeks of genuine effort rather than spacing, so one of them must carry a pair.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Licence workflow discovery, booking mapping and the automation boundary W2Source integration and the contribution-completeness baseline W3Return assembly, contribution logic and release controls W4Evaluation suite, classification cases and failure-mode testing W5Ledger integration, pilot returns and targeted corrections W6One licence year run under the accountable director, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for. The fifth holds two because the work does.
At the end of W6Validation closes on live returns, and Agent Care picks up the watch.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Travel & Hospitality AI agent

Build an ATOL agent around the return a registered accountant has to sign.

Show us one booking and the contribution it attracted. If your licence expires on 30 September, then the renewal application and the accountants report fall due by 1 August, and an ungranted licence puts your name on a published list. Package travel duties are a different lane.

Nestack Agents · ATOL protectionAGT-TH-15 · Agent Care available after launch