AI in practice / Customer self-service

One agent talks to the customer. Another does the work.

Customers get an answer straight away. The organisation stays protected: the agent they talk to has nothing to leak, and it never gives advice.

You are a pension member asking about your transfer. The agent you chat to holds no data. It passes your question to a servicing agent, which reads your case. Anything that needs a person is handed to a colleague.

AnyCompany Pensions is fictional and all data is synthetic. This is a demonstration, not a pension service.

Chat with the self-service agent

Pick a question below or type your own.

Use fictional text only. Each message is handled on its own; the agent does not remember earlier messages.

How it works

The agent that talks holds nothing

The self-service agent has no access to records. It can do two things: ask the servicing agent, and read approved general guidance. If it is manipulated, there is nothing for it to leak.

The agents use open standards

The two agents are built separately, in different languages. They talk over the Agent2Agent (A2A) protocol, and the guidance is served over the Model Context Protocol (MCP). Either agent could be replaced without changing the other.

Authority travels in a token

The servicing agent does not trust what the calling agent says. It acts only on a short-lived token that names the signed-in session, issued by the chat service.

How a chat message is handled The customer’s message goes to the chat service, which screens it and issues a token. The self-service agent calls the servicing agent over A2A and the guidance server over MCP. The reply is checked before the customer sees it. Requests that need a person go to a colleague. CustomerChat serviceSelf-service agent Servicing agentGuidance serverCase recordColleague chat in the browser screens the message,checks the spend limit,issues a 60-second token Python, Pydantic AIholds no data;two model turns at most reached over A2A;read-only tools reached over MCP;approved text only this member’s case,read by the servicingagent only approves or rejectsanything handed over A2AMCPhandover for approval

What the customer can and cannot get

Status, straight away

The status and dates come from the case record. The agent’s wording is checked against the record, and if it adds or changes a fact, the record-based answer is shown in its place.

No advice, ever

A question about what to do with a pension is never answered by a model. The customer sees fixed wording, and a handover is created for a colleague to approve.

Nothing happens on its own

Neither agent can change a record, send a message or move money. A handover only becomes a task when a colleague approves it.

How well it works

A small, synthetic test set run with live model calls. It shows how this build behaved; it is not a guarantee.

For engineers

The two agents and their interfaces
Why two models
The agent that talks to the customer runs on Claude Sonnet 4.6, chosen for natural wording that stays within instructions. The servicing agent runs on Amazon Nova Pro, the lowest-cost model that passed its evaluation for a routing and tool-calling task. Each is one setting.
Self-service agent
Python with Pydantic AI. Its first model turn must be tool calls and its second must be the answer, so it is bounded at two model calls. The model is a reviewed, configurable choice, called directly in London with the pinned guardrail.
Servicing agent
TypeScript. A bounded tool-use loop with two read-only tools. It publishes an A2A agent card and accepts SendMessage over the JSON-RPC binding. This is the same agent that serves the colleague-assisted page.
Guidance server
An MCP server over streamable HTTP with one read-only tool. Documents are pinned by hash and screened before they are returned.
Delegation
The chat service issues a signed token that names the session by hash and expires in 60 seconds. Both interfaces refuse callers without it. The agent never sees the session cookie.
Reply checks
The agent’s wording is shown only if every figure in it appears in the record or the approved guidance, it contains no advice wording, markup or links, and the guardrail passes it. Otherwise the record-based answer or a fixed reply is shown.
The stricter rule wins
If the message looks like a request for advice or support and the self-service agent did not ask the servicing agent, the chat service routes it there anyway.
Limits of this demonstration

Each message is handled on its own, with no conversation memory. The chat’s test set is small and was written by the same person who built it. Demo sessions stand in for customer sign-in. A phone channel would use the same servicing agent, but is not built here.

Want agents like this in your organisation?

I take AI agents from a business problem into production, working with the team that owns it. Tell me what you are trying to do.

Email Dan Message on LinkedIn More use cases