The 11 agents

Each agent owns one job. Together they take a SOW from intake to signed-off delivery.

A run, end to end

This is one delivery, drawn on a time axis. Each bar is an agent doing its single job, and the whole thing plays out left to right: intake becomes a plan, the plan becomes infrastructure, and the infrastructure moves toward a signed-off handover. Press play, or drag the timeline to move through the run and watch each stage settle.

run_updpCompleted
2s4s6s8s10s
  1. succeeded
    2.60s
  2. succeeded
    400ms
  3. succeeded
    1.60s
  4. succeeded
    4.20s
  5. succeeded
    1.40s
  6. succeeded
    1.80s
  7. served from cache
    1.20s
  8. succeeded
    1.80s
  9. succeeded
    1.60s

Bars in the brand color are agents doing reasoning work; the lighter bars are the deterministic engines and integrations they hand off to. The Compliance check retries until it passes, Zoho is served from cache when the project already exists, and everything downstream stays queued until its input is ready. Read it once and the rest of this page is just naming what you already saw move.

The orchestrator

Every agent is a specialist that does exactly one thing. What turns eleven specialists into a delivery pipeline is the orchestrator: a LangGraph state machine that sequences the agents, checkpoints run state, pauses at the human approval gates, and streams progress to the run canvas. The orchestrator owns the order of work and the shared state, so each agent can stay focused on its own task without knowing about the others.

The orchestrator treats a run as a sequence of nodes with saved state at each step. If a critical node fails, the run halts rather than pushing forward on bad output, and it can be retried without re-running the steps that already completed. Non-critical nodes such as IPM are allowed to warn and continue.

Agent groups

The eleven agents cluster into five stages that mirror the shape of a delivery. Reading them as groups is the fastest way to understand what the platform does before looking at any single agent.

Initiation

The initiation group prepares the ground before any analysis runs. IPM sets up scoped, temporary access into the target AWS account, and the Zoho Agent creates the delivery project shell. This group turns an approved request into a working environment with credentials and a project to track against.

Analysis

The analysis group turns the document into a plan. The SOW Analyzer reads the SOW, extracts structured requirements, and builds the infrastructure query and work breakdown. The Routing Engine then decides, deterministically, which services are handled by templates and which need generated Terraform. The output is a concrete plan of what to build and how.

Generation

The generation group produces the infrastructure code. OneClick provisions the base, template-covered services at no AI cost, while TerraFormGen writes everything else as additional Terraform. A Compliance validator checks the combined output against the Workmates rule set and applies safe auto-fixes, so what reaches review is already consistent and tagged.

Deploy

The deploy group moves reviewed code into a running system. The GitHub Agent opens a pull request that carries the plan and a CI workflow, and the Ansible Agent configures the instances after they are provisioned. Nothing in this group applies changes until a Tech Lead has approved at the gate.

Handover

The handover group closes the loop with the customer. The Documentation agent assembles a branded runbook, and the Signoff agent produces the signoff document and routes it for dual signature before the project is closed. Both agents are planned and not yet deployed, so this group is documented ahead of general availability.

Agent reference

The table below lists all eleven agents and the single job each one owns. Agents marked as planned are designed but not yet deployed.

AgentResponsibility
SOW AnalyzerParses the uploaded SOW, extracts structured requirements, and builds the infrastructure query plus the work breakdown structure, checklist, and questionnaire. Reuses learning from past SOWs.
TerraformTerraFormGenGenerates, modifies, and self-validates the per-service Terraform using the standard Workmates CWM module library, retrying validation until it passes.
Platform BackendThe API router that the other services call through, and the surface that runs the deterministic service-routing decision.
ZohoZoho AgentCreates the delivery project, syncs the work breakdown as milestones, tasklists, and tasks, advances the deal stage, and drives digital signatures for signoff.
AnsibleAnsible AgentRuns post-deployment configuration playbooks on the provisioned instances through AWS SSM, with no direct SSH access.
IPMIdentity and Privilege Management. Sets up scoped, temporary cross-account AWS access before analysis. Non-critical: the pipeline warns and continues if it fails.
OneClickTemplate engine that provisions base infrastructure such as VPC, EC2, RDS, ALB, S3, and KMS at zero AI cost, and doubles as a standalone provisioning catalog.
GitHubGitHub AgentCreates the repository, pushes the Terraform and modules, generates the CI workflow, and opens a pull request with the plan attached. Connects to AWS with keyless OIDC.
AuditPlanned lightweight security scan over the generated Terraform. Today it is a transparent pass-through so the pipeline continues; deploy-time gating is handled by the CI security scan and the Compliance check.
DocumentationPlanned runbook generator that will extract resources from Terraform state, capture console screenshots, and assemble a branded runbook. Designed, not yet deployed.
SignoffPlanned agent that builds the branded signoff document, routes dual digital signatures, and stores the signed artifact for handover.

Supporting engines

Two helpers appear in the product but are not counted among the eleven agents: the deterministic Routing Engine, which splits work between OneClick and TerraFormGen, and the Compliance validator built into TerraFormGen. The generated Terraform they act on lives in the run's terraform/ file set.

AuditIQ is a separate product

AuditIQ, the AWS Well-Architected Review console, is a standalone product on its own page. It is not an agent in the delivery pipeline and does not run as a pipeline stage.
Was this page helpful?View as llms.txt