Cloud-managed agents
Productized workflows running in NWA-managed Google Agent Engine.
- Same-week deployment of prebuilt workflows
- No GCP for you to administer
- Self-serve from the Core Console
- Per-firm budget caps and audit log
Deploy in the cloud, in a hybrid configuration, or on a private appliance — same platform, same operator surface. Workflows are versioned entities with built-in audit, budget caps, and human-review checkpoints.
The choice is about data sensitivity and customization need, not features. Every workflow runs against the same audit log, budget governance, and human-review hooks regardless of where it lives.
Productized workflows running in NWA-managed Google Agent Engine.
Bespoke agents designed for your operations and your tools.
For workflows where customer data never leaves the premises.
A trigger arrives. The platform queues the job, evaluates a budget preflight, runs each step with audit before-and-after, optionally pauses for human review, and returns a result. Every transition is observable and reversible.
Each workflow is a stable identity with versioned releases. The control plane catalogs them; you assign a release to a node and enable it independently. There's no "redeploy" to ship a workflow.
Every workflow has a stable workflow_id and a manifest describing triggers, secrets, and risk level.
Each version is a published release with a digest and source commit. Drafts are promoted to approved before assignment.
An approved release is assigned to a specific node, default-disabled. Different nodes can run different versions of the same workflow.
Flip the switch when you're ready. Reversible — disable any time without redeploying anything.
Every guardrail below ships on by default. You opt out per workflow if a use case warrants it, but silent overspend or unlogged steps are not a configurable state.
A monthly token ceiling per firm. A per-job ceiling per workflow. Both raise an error before the API call — not an after-the-fact bill shock.
STARTED and COMPLETED/FAILED for every workflow step. Every LLM call captured with firm, agent, model, tokens, and timestamp.
Retrieval-augmented generation runs against your data. Only the relevant chunks reach the LLM — full documents never leave the node on Private Edge.
Every node carries an MDM-issued device certificate. The control plane authenticates each connection. No shared API keys, no inbound ports.
The split is the same shape across tiers, but the surface area you own narrows as the data sensitivity rises.
| Responsibility | Core | Forge | Private Edge |
|---|---|---|---|
| Cloud infrastructure | NWA | NWA | NWA (control plane) |
| On-prem hardware | — | — | NWA (managed appliance) |
| Workflow design | NWA (productized) | NWA (custom) | NWA (custom) |
| Data residency | NWA cloud | NWA cloud and/or customer premises | Customer premises |
| Operator surface | Core Console (NWA-hosted) | Core Console (NWA-hosted) | Local + control plane (NWA-hosted) |
| Cost governance | Per-firm cap, NWA-enforced | Per-firm cap, NWA-enforced | Per-firm cap, NWA-enforced |
| Human review configuration | You | You + NWA | You + NWA |
| Customer support | NWA | NWA | NWA |
Free 30-minute call. We'll walk through your highest-leverage workflow and recommend a deployment mode.
Talk with engineering