Nestack Agent Care
Industries / Travel & Hospitality / Aviation SMS agent

Travel & Hospitality AI agent · Aviation SMS

Aviation SMS Declaration AI Agent

Match every hazard to the control raised against it, track which of the four retention clocks in 14 CFR 5.97 governs each artefact, and hold the declaration package for the accountable executive.

4–6 weeksTypical delivery
Your stackDeployment
One signatureNamed executive
Agent CareAfter launch

What this agent does

Assembles the package, never the signature

In
01

A hazard is reported, and subpart C of 14 CFR part 5 decides what risk control it earns.

02

A control is raised, and 14 CFR 5.97(a) keeps its output while that control stays relevant.

Reason
03

An assurance output is filed, and 14 CFR 5.97(b) holds it a minimum of five years.

04

A safety message goes out, and 14 CFR 5.97(d) holds it twenty-four calendar months.

05

A person is trained, and 14 CFR 5.97(c) keeps that record for the term of employment.

Decide
06

A control loses relevance, and the output behind it stops carrying the declaration.

07

A declaration falls due, and 14 CFR 5.9 sets 28 May 2027 for part 135 and 91.147 operators.

Out
08

A safety policy is signed, and 14 CFR 5.21(b) reserves that act to the accountable executive.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent assembles the package and tracks the clocks. The accountable executive designated under 14 CFR 5.25(a) signs the safety policy, and that act cannot be delegated.

Example workflow

One hazard, evidence to signature

AgentHuman
1Hazard evidence receivedOccurrence reports, risk assessments, assurance outputs or training records
2Hazard context assembledThe hazard, the control raised against it, the subpart it answers to and the clock it runs on
3Declaration evidence draftedThe hazards, the controls behind them, the gaps and completeness
4Controls appliedRelevance checks, retention-clock checks, subpart-coverage checks and completeness confidence
No human action required

Stages 1 to 4 run unaided, and nothing is signed at any of them — the agent is assembling, and the safety lane opens at the completeness gate.

5DecisionSplits at the completeness gate
Evidence sufficient

Goes to the accountable executive to sign.

Anything thin

Adds a safety manager read first.

Safety review

The package is held with its hazards, its controls and the outputs behind them.

Sign · Append evidence · Send to safety review
Signed — by the accountable executive
6Hazard and control records updatedOnly where write access and records policy allow it
7Outcome evaluatedControl currency, retention coverage, reviewer corrections and what the read found
Corrections

Each safety correction is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Signing the safety policy under 14 CFR 5.21(b).
Submitting the declaration of compliance to the FAA.
Deciding that a risk control is no longer relevant.
Judging safety performance substandard under 14 CFR 5.75.
Automation boundaryAgent acts unaided
Hold each hazard against the risk control raised.
Track which of the four retention clocks governs every artefact.
Mark the control whose relevance lapsed, and why.
Flag the missing record that the declaration package still needs.
Nothing is signed or submitted except by a named person, inside the agreed boundaries.
Judging whether an SMS meets part 5.
Telling the FAA the operator is compliant.
Setting the safety objectives the policy states.
Changes to hazards, controls or retention records.

Example output

One hazard, annotated

The declaration of compliance falls due on 28 May 2027; this record is what one hazard carried into the package.

Declaration evidence · single hazardIllustrative example
Hazard
Recorded as
Subpart
Evidence of record
Confidence
Held for
Runway excursion risk, subpart C
Control raised, relevance confirmed
Subpart C output
Risk assessment, 3 August 2026
Held unsigned
The accountable executive, by name
As receivedTaken from the occurrence report and the risk assessment — it reaches as far as those sources do.
What the record holds Occurrence report Risk assessment Control relevance note
Why no signature hereSigning the safety policy is reserved to the accountable executive.
ActionSignAppend evidenceSend to safety review
What the score decidesBelow the configured threshold the package takes a safety read before the executive sees it.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every hazardFrom the system that reported it
03Evidence

Where the evidence is used

Nothing else in the corpus answers to a named accountable executive who carries a whole certificate, so this page collides with no other agent we ship.

01Approved path

One signature, four clocks

14 CFR 5.21(b) leaves no room to spread it: "The safety policy must be signed by the accountable executive described in § 5.25." One human, personally, for the certificate entire.

02Human review

What was checked, and not found

The part 21 compliance dates, the DATES paragraph of 89 FR 33068 word for word, the signer of that rule and an eCFR stamp reading last amended 17 August 2026 were each checked and none was confirmed; no delay or withdrawal of the rule was found either.

04Build an evidence trail

The hazard, the control raised against it and the executive who signed stay on the policy.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Safety reportingOccurrence reports · portal
Confidential hazard reports
Risk and assuranceRisk registers
Audit and assurance outputs
Training and personnelTraining records · HR feed
Per-individual employment

Agent

Aviation SMS declaration

Reads the hazards
Assembles the package
Holds for the executive

Flight data and operationsFDM · maintenance systems
Safety communications
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six barriers between the model and the executive

Six barriers, and one hazard must clear every one of them. What gets past is named in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to evidence assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and part 5 rules; as of 24 August 2026 no delay, extension or withdrawal of the 2024 SMS rule was found, and 28 May 2027 stands.Track
L4TraceabilityRecord each hazard, the control raised against it, the clock it runs on and every read of the package.Record
L3Executive releaseHold the package for the accountable executive of 14 CFR 5.25(a); the hold governs release, not whether the system beneath it conforms.Gate
L2Scope guardrailsTest the evidence against subparts B to E of 14 CFR part 5 as configured, and against the four clocks in 5.97.Restrict
L1Confidence thresholdsRoute a thin package to a safety read first; part 21 compliance dates went unverified in research and are not worked here.Require review
Model coreEvidence assembled — the hazards, the controls, the clocks and completeness
L1 – L2Test whether a package may stand
L3Puts the signature in a person's hands
L4 – L5Keep the hazard and the control behind it
L6Retreats to record assembly when signals degrade

How Nestack evaluates it

Evaluate the whole assembly — not only the declaration package that comes out.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the package an inspector reads
Depth of coverage ▼
E1Final-output evaluationDid the package record what each hazard actually raised?
E2Step-level evaluationDid the agent read the right hazard, the right control and the live retention clock?
E3Tool evaluationDid it read and write the correct hazard and the correct control?
E4Confidence calibrationDo low-confidence packages actually attract more safety corrections?
E5Slice evaluationHow does performance change across specific hazard classes?
E6Business outcomeHow many packages needed a correction before the executive signed?
Floor — the certificate the operator answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, each pinned to the stage where it surfaces first.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
JY-03

Stale hazard read

The risk register read is not the one now in force.

Stage gathersThe hazards, the controls, the clocks and the dates
02 · Reasoning2 modes
JY-04

Control asserted, not shown

A control is called current without its output.

JY-06

Lapsed control read as live

A control past relevance still carries the package.

Stage proposesThe hazards, their controls and completeness
03 · Tool / write2 modes
JY-02

Thin package passed forward

A package moves on without the safety read.

JY-05

Bound to the wrong control

An output is filed against the wrong hazard.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
JY-01

Signed, evidence unrecorded

The package shows a signature but not what supported it.

Stage returnsThe package an executive signs and the FAA reads
05 · Change / Version1 mode
JY-07

Silent clock regression

A configuration change moves the clock, not the record.

Stage tracksModel, prompt, part 5 rules and package fields
Sev-1 · a policy signed on no evidence Sev-2 · wrong evidence reaches the package Sev-3 · source degrades, package unsigned

Affected slices

Flight operations hazards absorb the corrections

A control-level currency figure can read clean while flight operations hazards carry most of the rework. Nestack reports the correction rate by hazard class, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Flight operations hazards10.0%3.6× Review
Maintenance and airworthiness7.2%2.6× Review
Ground and ramp operations4.5%1.6× Watch
Training and communication records1.9%0.7× Normal
Bar: correction-rate lift vs. training-record baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

What a lapsed control costs

A loop ends when the stale control has become a case the next release must pass. That suite is what the next declaration built is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Correction rate rises on flight operations hazards.

02Diagnose

The safety policy signed once, for a hazard register that has moved on since, is read back until one cause remains.

03Improve

Number the change; the hazards that drove it are filed underneath it.

04Verify

Each touched hazard case is run once more, and one red holds it back.

05Learn

It stays on as a standing test, and the retention rules move alongside it.

Learn → DetectThe return edge. The next assurance year is measured against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, package assembly, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Hazard-register and automation-boundary discovery.
02Occurrence, risk and training sources.
03Hazard-to-control and retention-clock mapping.
04Hazard and control ingestion.
05Hazard, control and clock binding.
06Completeness scoring and review routing.
07Accountable executive signing workflow.
08Safety and training-system integration.
09Assurance and retention cases.
10Guardrails and executive controls.
11Policy-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne certificate, one year ProductionProduction assurance workflow AdvancedMultiple certificates / entities
Introduced at Pilot
Package assembly to your hazards
Accountable executive release
Hazard-register baseline
Introduced at Production
Reporting by control
Signing workflow in your systems
Approved write-back
Occurrence-report integration
Introduced at Advanced
Multi-certificate groups
Cross-subpart evidence packs
Large hazard registers
Multi-clock retention controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, reporting volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your certificates and the operations under each Hazard-register mapping and evidence captureWeek 1
02Representative occurrence, risk and training records Record binding, clock logic and the package baselineWeek 2
03Your risk acceptance criteria under subpart C Hazard mapping, control binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports Reporting, risk and training-source assessment, then integration setupWeek 2
05Declarations you would not want audited Retention cases and the evaluation runWeek 4
06What no safety policy may prove Completeness scoring, review routing, guardrails and release controlsWeek 3
07An accountable executive designated under 14 CFR 5.25(a) Signing workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

Each width is the time a phase truly takes and not a layout choice, so week five holds two of them.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1SMS workflow discovery, hazard mapping and the automation boundary W2Source integration and the control-currency baseline W3Package assembly, retention logic and release controls W4Evaluation suite, relevance cases and failure-mode testing W5Records integration, pilot packages and targeted corrections W6One assurance year run under the accountable executive, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for. Week five takes a pair because the work does.
At the end of W6When the safety record validates, Agent Care takes the agent on.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Travel & Hospitality AI agent

Build an SMS agent around the policy your accountable executive has to sign.

Show us one hazard and the control raised against it. The accountable executive of 14 CFR 5.25(b)(2) develops and signs the safety policy, and may hand that to nobody. Part 135 and 91.147 operators declare compliance by 28 May 2027; part 121 fell due on 28 May 2025.

Nestack Agents · Aviation SMSAGT-TH-16 · Agent Care available after launch