An agentic application is a full-stack business application in which people and agents work over the same pages, data, knowledge, and outputs, under one identity, one authorization model, and one audit record. The platform is built once. An application is configuration on top of it.
Pyrana Capital Finance / Monthly analysis / PMW · June 2026
Entities
PMW
MWM
GLH
TSS
APL
PMW · June 2026
Monthly pack · published v2 by the copilot on behalf of J. Okafor
Published v2Add to chat
Revenue
$12.4M
-$2.5M year over year
Materials
-$188K
PPV breach, Mar and Apr
Labor
31.2%
of revenue · plan 30.0%
Findings
4
1 needs approval
Executive summary
Revenue · Materials · Labor agents, rolled up
Revenue is down 2.47M year over year, led by Greenfield Agriculture, which fell 37.5K month over month. Materials carry a 188K unfavorable purchase price variance concentrated in March and April. Labor at 31.2% of revenue sits above plan. The top five accounts are 45% of revenue this year, below the 60% concentration threshold, so no qualifying window applies. cxu 1220…f843
Revenue by month
USD millions, 2026
JanFebMarAprMayJun
The monthly run published the pack. The controller asks the copilot about one account and revises the summary in place.
Illustrative. Pyrana Capital is a synthetic portfolio.
Runs ina dedicated private tenant (SaaS)·or the client's own infrastructure·the client's model keys·the client's identity provider
01/One monthly run
Tuesday, 7:40 a.m. The close App has already run.
At 2:00 a.m. a schedule admitted the finance close App at version 14. The monthly-close workflow fanned out to specialized agents, one per entity. Each reconciled intercompany balances, flagged variances, and drafted commentary through the tools it was given. The App posted 212 entries inside its authority. One adjustment exceeded the approval threshold, so the call was frozen and queued to the controller-approval lane.
The controller works in the App's own pages: the review queue shows what the policy routed to her, with the evidence attached. She approves two items and returns one with a note. The copilot sits beside the page for auxiliary analysis, a question about one account, and for personal pages; it is not the primary interface. The audit record holds who asked, what ran, which policy fired, which Context Units were cited, and who approved, for every call.
Approve, return, or edit what the policy routed to you.
Role: Reviewer
Journal entry · PMW intercompany adjustment
38,400 USD · proposed by the reconciliation workflow
6 of 6 policy checks passlane pmw-approvers
ApproveReturn
Accrual reversal · MWM materials
12,900 USD · proposed by the close workflow
6 of 6 policy checks passlane mwm-approvers
Approved · posted once
Journal entry · GLH freight reclass
4,150 USD · proposed by the close workflow
5 of 6 checks pass · missing supportlane glh-approvers
Returned with a note
A queued request is visibly different from a posted entry. Nothing here has run.
Illustrative. Pyrana Capital is a synthetic portfolio.
02/The problem
Pilots are easy. Production is the problem.
Enterprises can buy three things today. A framework: an agent, with security, authorization, and storage still to build and to maintain as agents multiply. Vertical applications: each solves one job and brings its own identity, permissions, and data, with nothing between them. A platform: identity, authorization, storage, orchestration, approvals, and audit built once, with every application composed on it and people inside the loop.
The first two are what is usually demoed. The demo is the part above the waterline.
0%+
of agentic AI projects will be canceled by the end of 2027, citing cost, unclear value, and inadequate risk controls
Source / Gartner, June 2025
0%
of enterprise AI agents operate in isolation: no shared data, no coordination, no handoffs
Source / Salesforce, 2026
0%
of organizations have a mature governance model for agentic AI
Source / Deloitte, April 2026
the agent, as demoed
what is below the line
a model
a prompt
a few tools
a chat window
waterline
identity, authorization, and audit shared by people and agents
tenant boundary with fine-grained access
durable workflows that fan out, wait, retry, and finish
tool approval policies with named lanes
idempotency on every external effect
audit record written before dispatch
versioned resources; stale publish refused
immutable App versions with activation and rollback
Security-critical, expensive, and in a framework build, still the enterprise's to build and maintain.
03/The platform
Built once. Configured per application.
Seven layers on one foundation of identity, authorization, and audit: the harness, the orchestration layer, tool sources, tool approval policies, durable storage, the context engine, and the surface layer. Every application shares them. An App is one configuration, the App configuration, that names what already exists: its surfaces, targets, agents, workflows, tool sources, resources, access, and knowledge.
Every call, from any door, passes one gate: eight steps, fail closed, the execution row and audit record written before dispatch. Unauthorized things read as absent, not denied.
the gate
eight steps · fail closed · audited before dispatch
An application is one App configuration on a platform that already exists. With clean data available, a first application typically stands up in about a week, and the frontend experience is the main effort. The foundational engineering is already done and lives in the platform, so the team's effort goes to the solution and time to value is measured in weeks, not quarters.
Identity, authorization, and audit are built once and applied to every call, whether a person or an agent makes it, through every door. Consequential actions queue for the right people before they execute.
Enforced byaccess profiles·scope entitlements·approval lanes·audit before dispatch
Compounding
Knowledge, rules, and published resources are shared across applications. Each new App starts with the context engine, the authorization model, and the extensions the previous ones already use.
EBITA gains from scaling agentic and single-task AI
Source / Bain, 2025
0 to 50%
acceleration in business processes
Source / BCG, 2025
0 to 80%
lower cost per transaction in labor-heavy processes
Source / McKinsey, 2025
05/Speed to value
The basics are already built. Value arrives sooner.
The enterprise-ready engineering every application needs is done and lives in the platform: identity, authorization, audit, durable storage, orchestration, approval policies, and the context engine. None of it is rebuilt per application, so a team's work goes to the process, the pages, and the knowledge, and the time from decision to a governed application in production is measured in weeks.
About a week
to stand up the App configuration, with clean data available
About six weeks
from decision to a first App in production with real identities and approvals; confirmed per engagement
Less each time
for every App after: the basics are inherited, never redone
Already in the platform
Identity: SSO, per-agent identity, actor chains
Authorization in layers: tenant, App membership, access profiles, scope entitlements
The gate: eight steps, fail closed, audit before dispatch
Tool approval policies with named lanes
Durable execution and orchestration: lanes, fan-out, checkpoint and resume
Tool sources: REST, ODBC, MCP, warehouses, drives
Versioned resources and durable storage
The context engine: typed, classified, cited knowledge
A person acts on a page. The call passes one gate. The lane the policy names decides, the entry posts once, and one execution record holds the whole story. The same three moves apply to a call from the copilot, the API, another agent over MCP, or a schedule.
1
A person acts in the App
Reconciliation · PMW · June 2026page
Proposed adjusting entry
Intercompany PMW / MWM · 38,400 USD
Duplicate posting found by the reconciliation workflow
Submit for postingEvidence
On the App's own page. The same target is reachable from the copilot, the API, MCP, or a schedule, and takes the same path.
2
The gate checks the call
Gate · journal.post_adjusting_entryexec_01J9…
Identityj.okafor · SSO
App versionfinance@v14 · active
Authorizedcontroller · entity PMW
Recordwritten before dispatch
Approvalabove 25,000 USD → lane pmw-approvers
Eight steps, fail closed: who is calling, which App version, is it allowed, does policy require a person. The record is written before anything runs.
3
Approved, then recorded
Execution recordposted once
Approved byK. Osei · pmw-approvers · 09:14
Policyapproval.journal.amount @v7
EffectJE-88213 · receipt kept
Publishedrecon_summary v2 · 2 units cited
The lane the policy names decides. The entry posts once. One execution record holds who asked, what ran, which policy fired, and who approved.
Illustrative. Pyrana Capital is a synthetic portfolio.
One App configuration. One immutable version.
An App is one configuration compiled into an immutable, content-digested version. Push compiles and registers the App identity. Activate moves one pointer, is audited, and requires an App owner. Rollback is an activation of a prior version. Which version ran is always exact.
Pathssolutions·platform·security·how it works·harness·cortIQ
09/Questions
Frequently asked
What is an agentic application?+
A full-stack business application in which people and agents work over the same pages, data, knowledge, and outputs, under one identity, one authorization model, and one audit record. On Pyrana the platform is built once; an application is one App configuration (configuration) plus its frontend experience. Agents are a mechanism inside the application, dispatched by its workflows and bound to its tools, not a separate product.
How portable is an application, and what is the lock-in?+
An application is one YAML document plus the agents, workflows, and tool sources it binds. Agent configuration is plain language. Workflows are declarative. Context Units are the client's data and can be exported. Tools built for the platform can in many cases be called from outside it. There is no industry-standard interchange format, so there is no export button; translating an App to another runtime is a reading exercise, not a rebuild. The platform runs in the client's own cloud subscription.
How is Pyrana different from a low-code builder such as n8n, Flowise, or Copilot Studio?+
A flow builder produces a flow. Pyrana is a runtime and a system of record: identity, authorization, and audit on every call; durable storage and versioned resources; tool approval policies with named lanes; and extensions for custom durable backends, such as a project portfolio tracker with its own business logic or a governed browser capability for SaaS compliance checks. Outputs can be delivered to any deployment target the client accepts: Drive, OneDrive, or a system of record.
What does the gate do before a call runs?+
Every call into an App, from its own pages, the copilot, the API, another agent over MCP, a schedule, or an external event, passes the same eight steps: identity and idempotency key; active App version; target exists and caller allowed; page and resource references resolved to exact versions; one authorization check on membership, profile, and entitlement; idempotency claimed and the execution row and audit record written in one transaction; dispatch to the native host; outcome recorded. The gate fails closed. Unauthorized things read as absent, not denied.
Does Pyrana replace existing systems?+
No. Pyrana does not need to store source data. Agents query live through tool sources: ODBC, REST, MCP, Databricks, Snowflake, Google Drive, OneDrive. Each call is authorized. Custom business logic runs as an extension, a client-owned durable backend service in the same cluster, built with the platform library and reachable only through the platform.
Which models can an application use?+
A model is assigned per agent through provider adapters for Azure OpenAI, OpenAI, Anthropic, Fireworks, Google Gemini, and others, with the client's own keys. Models are not switched mid-run. Company knowledge lives in the context engine rather than in model weights, so an application can change models without changing its document. Small, medium, and large routing for platform jobs such as summarization is on the roadmap.
How is it deployed, and how does it scale?+
Pyrana is hosted as SaaS on a dedicated private tenant, or deployed into the client's own infrastructure for large enterprises. Temporal workers provide durability and horizontal scaling; separate worker pools handle data fetching, file extraction, and the code interpreter.
Who can see the data?+
The platform runs on a dedicated private tenant, or in the client's own infrastructure. Client data is never used to train external models. The tenant is a hard boundary enforced with row-level security. All authorization is decided on the backend; nothing unauthorized reaches the frontend, and anything a caller may not see is absent from results rather than shown as denied.
How is Pyrana different from LangChain, CrewAI, or an agent builder?+
A framework produces an agent. Security, authorization, storage, approvals, and audit are still the enterprise's to build, and to maintain as agents multiply. Pyrana builds that layer once. Every application composes on it as configuration, with people inside the loop. Teams build the solution, not the basics, and value arrives sooner.
The platform is built once. The application is configuration.
Identity, authorization, audit, and context exist before the first application and are shared by every one after it. Value arrives in weeks, not quarters.