AI in practice / Customer self-service
One agent talks to the customer. Another does the work.
Customers get an answer straight away. The organisation stays protected: the agent they talk to has nothing to leak, and it never gives advice.
You are a pension member asking about your transfer. The agent you chat to holds no data. It passes your question to a servicing agent, which reads your case. Anything that needs a person is handed to a colleague.
Chat with the self-service agent
Pick a question below or type your own.
Use fictional text only. Each message is handled on its own; the agent does not remember earlier messages.
How it works
The agent that talks holds nothing
The self-service agent has no access to records. It can do two things: ask the servicing agent, and read approved general guidance. If it is manipulated, there is nothing for it to leak.
The agents use open standards
The two agents are built separately, in different languages. They talk over the Agent2Agent (A2A) protocol, and the guidance is served over the Model Context Protocol (MCP). Either agent could be replaced without changing the other.
Authority travels in a token
The servicing agent does not trust what the calling agent says. It acts only on a short-lived token that names the signed-in session, issued by the chat service.
What the customer can and cannot get
Status, straight away
The status and dates come from the case record. The agent’s wording is checked against the record, and if it adds or changes a fact, the record-based answer is shown in its place.
No advice, ever
A question about what to do with a pension is never answered by a model. The customer sees fixed wording, and a handover is created for a colleague to approve.
Nothing happens on its own
Neither agent can change a record, send a message or move money. A handover only becomes a task when a colleague approves it.
How well it works
A small, synthetic test set run with live model calls. It shows how this build behaved; it is not a guarantee.
For engineers
The two agents and their interfaces
- Why two models
- The agent that talks to the customer runs on Claude Sonnet 4.6, chosen for natural wording that stays within instructions. The servicing agent runs on Amazon Nova Pro, the lowest-cost model that passed its evaluation for a routing and tool-calling task. Each is one setting.
- Self-service agent
- Python with Pydantic AI. Its first model turn must be tool calls and its second must be the answer, so it is bounded at two model calls. The model is a reviewed, configurable choice, called directly in London with the pinned guardrail.
- Servicing agent
- TypeScript. A bounded tool-use loop with two read-only tools. It publishes an A2A agent card and accepts SendMessage over the JSON-RPC binding. This is the same agent that serves the colleague-assisted page.
- Guidance server
- An MCP server over streamable HTTP with one read-only tool. Documents are pinned by hash and screened before they are returned.
- Delegation
- The chat service issues a signed token that names the session by hash and expires in 60 seconds. Both interfaces refuse callers without it. The agent never sees the session cookie.
- Reply checks
- The agent’s wording is shown only if every figure in it appears in the record or the approved guidance, it contains no advice wording, markup or links, and the guardrail passes it. Otherwise the record-based answer or a fixed reply is shown.
- The stricter rule wins
- If the message looks like a request for advice or support and the self-service agent did not ask the servicing agent, the chat service routes it there anyway.
Limits of this demonstration
Each message is handled on its own, with no conversation memory. The chat’s test set is small and was written by the same person who built it. Demo sessions stand in for customer sign-in. A phone channel would use the same servicing agent, but is not built here.
Want agents like this in your organisation?
I take AI agents from a business problem into production, working with the team that owns it. Tell me what you are trying to do.
Email Dan Message on LinkedIn More use cases