Case study · Engineer · AI platforms & engineering
A governed business agent, in production at a Swiss services SME
How a Swiss services SME replaced back-office overload with a governed agent layer on top of its existing systems — architecture, controls, measured results.
Anonymised case — representative example from real Numezis engagements
Starting situation
The back office was absorbing most of the growth: every new client file added data entry, document filing, reminders and cross-checks across three entities. Process knowledge was concentrated in two key people, and invoices consistently went out late.
Management had received several vendor offers promising turnkey “AI automation”. None answered the concrete questions: where does our clients’ data travel, who approves an accounting entry before it exists, what happens when the model gets it wrong?
The decision on the table
Buy yet another line-of-business software suite — or build a governed agent layer on top of the systems already in place?
Real constraints
Sensitive fiduciary data
Financial and personal data of ~450 end clients, subject to the Swiss nFADP and professional secrecy. No data could be used to train third-party models.
No in-house IT team
Operations had to run without an engineer on site: simple procedures, explicit alerts, documented recovery playbooks.
SME budget
An investment the partners could defend, committed in tranches against proof milestones — not a multi-year programme signed blindly.
FR/DE bilingualism
Client documents and correspondence in both languages, with frequent switching within a single file.
What we built
We built an agent layer on top of the existing systems rather than replacing them. The agent reads context (incoming email, documents, accounting entries), prepares actions, and executes them only within explicit boundaries: role-based permissions, a human approval queue and an immutable audit log.
System components
Delivery sequence
Scoping & baseline 3 weeks
Mapping of actual workflows, measurement of processing times and invoicing delays, data classification, selection of the first scope.
Foundations 6 weeks
Identities and permissions, read-only MCP connectors, evaluation environment with anonymised test files, audit log.
Supervised pilot 8 weeks
Agent in production on one entity, 100% of actions approved by a human, weekly error reviews and threshold tuning.
Rollout 6 weeks
Deployment across all three entities, switch to sample-based approval for low-risk actions, team training.
Hardening & handover 3 weeks
Operating procedures, alerting, security review, monthly governance handed over to management.
Measured results
The three-week baseline made it possible to measure the real gap — not a gut feeling. The figures below compare the 90 days before the pilot with the last 90 days of the engagement, on the same scope.
Figures are rounded, measured on the pilot and then the rollout scope. Anonymised case: a representative example drawn from real Numezis engagements and product development work, not a nameable reference.
What we would do differently
This section is part of our editorial standard: no case study without its lessons.
- 01
Instrument the baseline from week one. We consolidated it during scoping, but six weeks of finer-grained reference data would have strengthened the final value measurement.
- 02
Involve the external auditor from the foundations phase. Their review of the audit log during the pilot validated the approach — doing it earlier would have saved two iterations on the trace format.
- 03
Build fewer connectors upfront. Four MCP connectors were delivered; two were enough for the pilot. The other two should have waited for proof of use.