AI Agents in Business Processes
How a Low-Code Platform Ensures Control and Security
IT Alliance Solutions
How to integrate artificial intelligence into corporate processes without compromising governance, transparency, or security requirements.
Processes
BPMNAccess
RBAC · ABACAuthentication
KeycloakIT Alliance Solutions
01 / 07The Challenge: AI Without Control Is a Risk
Banks and financial institutions are actively exploring the potential of large language models (LLMs). However, the transition from pilot projects to production deployment presents a systemic challenge: an autonomous AI agent can be unpredictable.
In a critical business process, an AI agent may generate a hallucination, access data directly while bypassing established access-control policies, or make a decision that cannot be adequately explained to a regulator.
01Risk
generate a hallucination
02Risk
access data directly while bypassing established access-control policies
03Risk
make a decision that cannot be adequately explained to a regulator
In the financial sector, this is unacceptable. The answer is not to abandon AI, but to embed it within a governed orchestration framework, where every step taken by the agent is controlled, validated, and auditable. This is the approach implemented in the ITA-FORMS low-code platform (Russian Register of Domestic Software No. 6468).
ITA-FORMS is not about “AI for AI’s sake.” Instead, it offers three practical scenarios in which an AI agent becomes an integral part of a proven BPMN-based orchestration framework with enterprise-grade controls.
- controlled
- validated
- auditable
IT Alliance Solutions
02 / 07Approach: Three Scenarios for Integrating AI Agents
IT Alliance Solutions
03 / 071. Agent as a Process Step (Agent as a Service)
Within a BPMN diagram, the AI agent is represented as a specialized Service Task.
Scheme
Service Task · BPMNAgent as a Service
1Step
Service Task
The process pauses, passes the agent the relevant context—including process variables and available documents—and waits for a structured response.
2Step
ReAct
The agent uses the ReAct (Reasoning + Acting) loop to achieve a specific local objective, such as reconciling discrepancies in a contract, classifying a customer inquiry, or generating an analytical brief.
3Step
The key principle is deterministic output.
The agent’s response is strictly validated against a predefined JSON schema.
4Step
Human-in-the-Loop
If validation fails or the iteration limit is reached, the process automatically follows an Error Boundary Event to a manual-processing branch. This ensures a Human-in-the-Loop approach: no agent-generated decision can enter production without human review.
Business
For business teams, this means predictability: the agent operates within the process, not instead of it.
IT
For IT teams, it means a standard BPMN model that can be monitored, analyzed, and enhanced using familiar tools.
IT Alliance Solutions
04 / 072. Platform as a Tool Registry
In this scenario, the AI agent acts as a coordinator, while the platform exposes its existing system integrations through a standardized protocol, such as OpenAPI or the Model Context Protocol (MCP).
Connectors to ERP and CRM systems, payment gateways, and databases that are already configured in the Low-Code Designer are automatically exposed as a set of functions available to the agent through Tool Calling. There is no need to build separate integrations for AI—the platform makes its existing connectors available to the agent.
The key principle is no direct access. The agent never accesses a database or external API directly. All calls are routed through the platform’s integration bus and subject to:
RBAC/ABAC
Access control (RBAC/ABAC) — the same policies used by other system components;
Logging
Logging of every request for audit purposes;
Rate limiting
Rate limiting to protect backend systems from overload.
Scheme
Platform as a Tool Registry
Principle
Integrating AI does not introduce new access paths:
the agent operates under the same access-control policies as any other platform component, while existing integrations can be reused without duplication.
IT Alliance Solutions
05 / 073. Platform Metadata Generation (Agentic Co-Pilot)
The third scenario operates not during process execution (run-time), but at the design stage (design-time).
Based on a textual description of a business requirement or a set of procedural rules, the agent generates artifacts for the Low-Code environment, including form JSON schemas, BPMN process structures, validation scripts, and SQL projections.
Agentic Co-Pilot · design-time
Low-Code environment artifactshuman verification
The developer receives a ready-to-review model and verifies it before committing it to the platform repository.
The final decision always remains with a human
This accelerates the development of standardized processes and lowers the barrier to entry for new specialists: instead of manually constructing metadata, developers can describe the requirements in natural language. At the same time, the final decision always remains with a human — the agent proposes, the developer approves.
IT Alliance Solutions
06 / 07Security and Deployment
All three scenarios are built on the core architectural principles of ITA-FORMS:
On-premises deployment.
AI agents operate within the customer’s environment. Data remains within the organization’s security perimeter, which is critical for financial institutions and regulatory compliance requirements.
Unified IAM infrastructure.
Existing authentication and authorization mechanisms, including Keycloak, ABAC, and RBAC, are used. There is no need to establish a separate identity and access management system for AI.
End-to-end traceability.
Every agent action is recorded in the audit log alongside other process steps, providing a complete and auditable trail of AI activity.
Microservice architecture.
AI components are isolated from the platform core. Updating or replacing an AI model does not affect running business processes.
IT Alliance Solutions
07 / 07The Result: AI Under Governance, Not Instead of Governance
Integrating AI agents into ITA-FORMS is not about replacing people or deploying fully autonomous AI. It is about augmenting existing processes in a controlled and governed way:
| Scenario | Business Value | IT Value |
|---|---|---|
| Agent as a ServiceScenario 1 | Predictable outputs with a guaranteed Human-in-the-Loop | Standard BPMN model, monitoring, and fallback mechanisms |
| Platform as a Tool RegistryScenario 2 | Secure agent access to enterprise systems | Reuse of existing integrations and unified audit trail |
| Agentic Co-PilotScenario 3 | Faster development and a lower barrier to entry | Automated generation of artifacts with human verification |
The platform does not become an “AI platform.” It remains an enterprise-grade Low-Code process management platform that can now safely integrate AI capabilities wherever they deliver real value.