Trace the change each item records before anything moves it — the hazard control, the design input, the closure nobody justified — and hold every transition for a named approver.
An item is groomed, and the change it records travels with it into whatever state it moves to.
02
A transition is offered on the controlled workflow, because the wrong process still records the change.
Reason
03
An item goes stale, and it is raised rather than closed, because a stale control is an open control.
04
A closure is proposed with no action behind it, and the justification for taking none is written or it is refused.
05
An item carrying a pre-authorised change is kept inside the envelope that authorised it.
Decide
06
An item that is a design input is edited, and that edit is a modification under MDR Article 10(9)(a).
07
A ranking is produced over the work and not the person, because the other kind is co-determined in Germany.
Out
08
An item traces to no change at all, and that is reported as the finding rather than tidied away.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
Grooming, tracing and flagging belong to the agent. The transition belongs to a named approver, who moves the item on the controlled workflow and owns it there.
Example workflow
One item, tracker to transition
AgentHuman
1Item receivedA tracker item, a change request, a hazard log entry or a linked design record
2Context assembledThe item as it stands, the traces it carries, the workflow it sits on and the change it records
3Grooming proposedThe state it would move to, the traces it keeps, the justification and confidence
4Controls appliedTrace checks, controlled-workflow checks, justification checks and grooming confidence
No human action required
Stages 1 to 4 run unaided, and no item moves at any of them — the agent is proposing, and the approver lane opens at the transition gate.
5DecisionSplits at the transition gate
Routine item
Goes to the named approver to sign.
Anything tracing to a control
Adds a quality owner read first.
Approver review
The item is held with its traces, its justification and the state it would move to.
Approve · Reopen · Send to quality review
Approved — by the named approver▼
6Tracker and record systems updatedOnly where write access and record control allow it
7Outcome evaluatedTrace survival, closure reversals, approver corrections and what review found
Reversals
Each reopened item is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Closing an item that records a hazard control.
Amending a story that is a design input.
Merging two items that trace to two hazards.
Signing a design change into the record.
Automation boundaryAgent acts unaided
✓Trace each item back to the change it records.
✓Flag an item that has gone stale without any closure.
✓Report each closure that carries no written justification beside it.
✓Hold the transition for the approver named on the controlled workflow.
The change space is agreed in advance, and nothing leaves it except by a named approver.
Deciding that a control has been implemented.
Assigning work from a personal work history.
Producing a score a manager would lean on.
Changes to the workflow or the closure rules.
Example output
One backlog item, annotated
Our workflow orchestration agent sequences a process across systems and retries only what is safe to repeat; this one grooms the list, and in a regulated shop the list is the design record.
Backlog item · single ticketIllustrative example
Item
Recorded as
Traces to
Change of record
Confidence
Held for
Alarm-suppression control
Open, last touched in April
Hazard log entry
Design change, 6 August 2026
Held unclosed
The named quality approver
As receivedTaken from the tracker and the hazard log; the binding record rule sits in a paywalled standard.
What the item carriesHazard log entryDesign change recordVerification result
Why no closure hereClosing an item that records a control is a judgement a person makes.
ActionApproveReopenSend to quality review
What the score decidesBelow the configured threshold an item gets a quality read before the approver sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every itemFrom the tracker that holds it
03Evidence
Where the item ends up
The agent does not decide that a closure was right. When the audit lands months later, the reversal is filed against the release the closure sat in, and the approver is named on it.
01Approved path
A ticket can be a control
Ask which side of the fork you are on. For ordinary software a backlog is a private list. For a device — and class I counts once it is automated with computer software — the same list is the design record, and non-compliance means adulteration under section 501(h).
02Human review
What was checked, and not found
No law was found that requires a backlog to exist, that requires prioritisation to be fair, rational or explainable, or that gives anybody standing to challenge a deprioritised item. What binds does so collaterally.
04Build an evidence trail
The item, the change it recorded and the person who approved it stay together.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Issue and work trackersJira · Azure DevOps · Linear Shortcut · tracker workflow APIs
Quality and record systemseQMS · document control Design and change control records
Risk and hazard recordsHazard logs · risk registers Controls and their implementation items
Agent
Backlog and workflow grooming
Reads the item Proposes the move Holds for the approver
Delivery and planningBoards · release and sprint plans Dependency and transition records
A project-level traceability figure can read clean while the items behind hazard controls carry most of the reversals. Nestack reports the reversal rate by item class, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Items behind a hazard control
6.4%
3.7×
Review
Design-input change items
4.5%
2.6×
Review
Merged and deduplicated items
2.8%
1.6×
Watch
Routine delivery items
1.4%
0.8×
Normal
Bar: reversal-rate lift vs. routine-item baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What a stale closure costs
A loop ends when the hazard control closed as stale is a standing case. That suite is what the next grooming pass is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Reversal rate rises on items behind a hazard control.
02Diagnose
The ticket closed as stale, which was the last written trace of a hazard control, is worked backwards through the pass until one cause is left standing.
03Improve
Numbered the change leaves, and the items that drove it are filed with it.
04Verify
A single red item case is enough to stop the pass.
05Learn
The case is kept, and the closure rules are amended in that commit.
Learn → DetectThe return edge. The next pass is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, grooming workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Item-lifecycle discovery and automation-boundary work.
02Tracker, record and hazard sources.
03Closure-rule and design-change-record trace mapping.
04Backlog item ingestion.
05Item, control and change binding.
06Closure scoring and review routing.
07Approver sign-off workflow.
08Tracker and record integration.
09Closure and traceability cases.
10Guardrails and transition controls.
11Item-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne project, one cycleProductionProduction tracker workflowAdvancedMultiple projects / trackers
Introduced at Pilot
Grooming to your controlled workflow✓✓✓
Named approver sign-off✓✓✓
Backlog-inventory baseline✓✓✓
Introduced at Production
Reporting by item class—✓✓
Quality review workflow in your systems—✓✓
Approved write-back—✓✓
Tracker-and-record integration—✓✓
Introduced at Advanced
Multi-source traceability——✓
Cross-project item packs——✓
Large backlog estates——✓
Multi-project transition controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, backlog volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your live projects and the workflow each item moves on→Change-envelope and controlled-workflow mappingWeek 1
02Representative items, traces and closure history→Trace binding, closure logic and the backlog baselineWeek 2
03Your approvers and any works-council agreement in force→Workflow mapping, trace binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Tracker, eQMS and hazard-log assessment, then integration setupWeek 2
05Closures you would not want inspected→Traceability cases and failure-mode testingWeek 4
06What no transition may erase→Closure scoring, review routing, guardrails and release controlsWeek 3
07A named approver who signs the transition→Release to the named approver, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The bands take their width from the work, which is why week five holds two and not one padded one.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Backlog discovery, workflow mapping and the automation boundaryW2Tracker integration and the backlog-inventory baselineW3Grooming workflow, closure logic and release controlsW4Evaluation suite, traceability cases and failure-mode testingW5Record integration, pilot passes and targeted correctionsW6One delivery cycle run under the programme owner, then Agent Care handover
Reading the bandEach bar spans only the weeks its own work is named for, and week five carries two.
At the end of W6When the item record validates, Agent Care picks the agent up.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Product AI agent
Build a backlog and workflow agent around the closure your last audit had to explain.
Show us one project and the items its last pass closed. If design inputs and hazard controls live in your backlog, then a stale closure amends a controlled record. Micro-X was cited in 2024, on pre-QMSR numbering, for recording a real change by the wrong procedure.