LiveTableau Agent deployed at SUNY

AI agents for the systemsyour agency already runs.

12 production agents for government and public agencies, on Tableau, Power BI and records. Each cites its source.

ISO 9001:2015ISO 27001:2022ISO 20000-1:2018

Illustration of the Kolossus Tableau Agent. It is connected to two published Tableau data sources and an ACS dataset. Asked how the share of limited-English-proficient residents with a bachelor’s degree has changed since 2019, it resolves five filters, queries the sources, verifies each figure against the underlying rows, and returns an answer in which every number carries a numbered citation resolving to the source it came from.

Deployed at
Public sector
  • Tableau Agent
100%of its published Tableau reports retired
Life sciences
  • Dashboards Agent
  • Reports Agent
2agents bound to their existing analytics
Enterprise
  • Bulk Entry Agent
  • Quotation Generator Agent
2custom agents, built to their workflow
  • Four weeks, typical, from bound system to a live agent
  • Zero customer records leave your environment
The catalog

12 agents. Each one bound to a single system.

An agent is not a chatbot with a wider prompt. Each is scoped to a named system of record, inherits that system’s permissions, and answers only what that source can support.

Analytics & dashboards

Agents that sit on the BI layer you already built and answer in plain language, so the dashboard stops being the only way in.

A-01Tableau AgentLive at SUNYTableau Server · Tableau Cloud · published data sources

Answers over the same extracts and workbooks your analysts already maintain, without asking the public to learn the workbook.

Which counties saw the largest change in LEP population since 2019?

A-02Power BI AgentPower BI semantic models · Fabric · Azure SQL

Reads your semantic model, respects row-level security, and returns figures traced to the measure they came from.

What was overtime spend by department last quarter versus budget?

A-03Open Data AgentSocrata · CKAN · ArcGIS Hub · CSV and API endpoints

Turns a public data portal into something answerable, including cross-dataset questions no single view was built for.

How many food service permits were issued in this ZIP code last year?

Citizen services

Front-line agents that answer the questions currently arriving by phone, email and walk-in, grounded in your published rules.

B-01Benefits Eligibility AgentProgram rules · eligibility matrices · policy manuals

Screens a household against published criteria and explains which programs apply and what documentation each needs.

What programs is a family of four at this income level eligible for?

B-02Permits & Licensing AgentMunicipal code · zoning maps · permit schedules

Walks an applicant through what they need before they file, cutting the incomplete applications your staff send back.

What permits do I need to open a food business at this address?

B-03311 Services AgentService catalog · department routing rules · knowledge base

Resolves routine requests directly and routes the rest to the correct department with the context already gathered.

How do I report a broken streetlight and what happens next?

Records & compliance

Agents pointed at the internal workload: the searches, cross-references and lookups that consume skilled staff time.

C-01Records & FOIA AgentRecords management · published reports · prior request log

Checks an incoming request against material already in the public domain before it consumes a full review cycle.

Which published reports already cover this request before we process it?

C-02Grants AgentGrants.gov · award history · reporting requirements

Tracks eligibility, deadlines and reporting obligations across every award your agency holds or is pursuing.

Which of our open awards have reporting due in the next 60 days?

C-03Procurement AgentContract repository · vendor records · solicitation archive

Answers contract, vendor and solicitation questions without another manual pass through the repository.

Do we have an existing contract vehicle covering this category?

Internal knowledge

Staff-facing agents on the systems your teams live in, with visibility scoped to the role of whoever is asking.

D-01SharePoint AgentSharePoint · Microsoft 365 · intranet and policy libraries

Answers internal policy and procedure questions from the document set, honouring existing site permissions.

What is the current travel reimbursement policy for staff?

D-02Case Management AgentCase systems · intake records · service histories

Surfaces case history and next actions for a worker without a manual trawl through separate systems.

Summarise the service history and open actions on this case.

D-03Policy & Research AgentResearch library · legislative text · methodology notes

Queries the full body of reports, datasets and legislative material a policy unit works against.

Which of our reports address workforce participation among recent arrivals?

Custom agents

Don’t see your system?

Most of this catalog began as one agency’s request. A legacy case system, a state-specific registry, an in-house warehouse: that is a scoping conversation, not a roadmap request.

Scope a custom agent
Customers

Agents running in production, not in a pilot deck.

Three deployments across three sectors. Each one is bound to a system the customer already ran, and answers from it.

Public sector

Institute on Immigrant Integration Research & Policy

State University of New York

  • Tableau Agent
nyimmigrants.org(opens in a new tab)
How it works

The agent is bound to the institute's published Tableau data sources and nothing else. A visitor sets the same filters the workbook used, region, county, year, English proficiency, education level and report type, or skips them and types the question outright. It resolves the filters, queries the bound sources, checks each figure against the underlying rows and returns a written answer in which every number carries a citation back to the record it came from. Ask it something the data cannot support and it declines rather than estimating.

Retired the institute's published Tableau reports. Visitors now filter by region, county, year, proficiency and education, or simply type the question, and get a report generated from the institute's own data with every figure traced to its source.

Life sciences

UroGen Pharma

  • Dashboards Agent
  • Reports Agent
urogen.com(opens in a new tab)
How it works

Both agents sit on the analytics layer the company already maintains, inheriting whatever access rules it enforces. Rather than locating a figure in a dashboard or waiting on a report request, a question is asked in plain language and answered from the same underlying measures, with the source of each figure named alongside it.

Dashboard and reporting agents bound to the company's existing analytics, so a figure can be asked for in plain language instead of located in a report.

Enterprise

Impact Systems

  • Bulk Entry Agent
  • Quotation Generator Agent
enterprisetek.net/impact(opens in a new tab)
How it works

Neither agent came from the catalog. The first takes bulk entry against their order records, reading what is submitted and writing it back in the shape the system expects. The second generates a quotation from those same records, so pricing comes out of the data already held rather than being re-keyed from it.

Two custom agents rather than catalog ones: bulk entry against their order data, and quotation generation from the same records.

Why agents

One general assistant fails a public-sector review. Twelve narrow ones pass it.

A single model pointed at everything an agency holds is impossible to scope, permission or audit. Narrow agents are reviewable, and reviewable is the bar procurement actually sets.

01

Scoped to one system

Each agent is bound to a named source: a Tableau site, a permit schedule, a records repository. Its answers cannot wander outside it, because it has nowhere else to look. That single constraint is what makes the rest reviewable.

02

Inherits your permissions

Row-level security, SharePoint site permissions and role visibility carry straight through. A caseworker and a resident asking the same question each see only what they are entitled to.

03

Cites, or declines

Every figure links the record it came from. Questions the source cannot support get a documented decline and a routing path, not a fluent guess.

04

Auditable by default

Every query, answer and citation is written to a log your team owns and exports.

05

Replaceable one at a time

Agents ship and are reviewed individually, so a pilot is one system, not a platform commitment.

06

Runs where you say

On-premise, your cloud tenant, or fully air-gapped against self-hosted models.

Deployment

Four weeks per agent, bind to live.

No warehouse project, no migration, no rebuilding the reports you already publish. The agent reads what exists.

01

Bind

The agent is pointed at one system, such as a Tableau site, a permit schedule or a case system, over a read-only connection inside your network.

02

Ground

Its source is indexed with source-of-truth mapping, so every answer resolves back to a specific document, table or row.

03

Govern

Your team sets roles, redaction rules, retention windows and the refusal boundary. What the agent will not answer is configuration, not hope.

04

Deploy

Embed it where the work happens: public site, intranet or service portal. On-premise, your cloud tenant, or managed by us.

Security & compliance

Cleared for public-sector deployment.

What we are certified against, what every agent does, and what your deployment is configured to support. Stated separately, because procurement will separate them anyway.

Certified

Independently audited standards held by Kolossus.
CertifiedISO 9001:2015Quality Management System

Documented, audited processes for how each agent is built, released and supported.

CertifiedISO 27001:2022Information Security Management

The control framework governing how your data is stored, accessed, logged and retained.

CertifiedISO 20000-1:2018IT Service Management

Defined incident response, change management and service levels for every deployment we run.

How your data is handled

Agent behaviour, configured per deployment.
Data stays in your environmentOn-premise or your own cloud tenant. Records never cross your network boundary.
Never used for trainingYour documents and your users' questions do not train or fine-tune any model.
Full audit logEvery query, answer and citation written to a log your team can export.
SSO and role-based accessSAML/OIDC sign-on, with each agent inheriting its source system's permissions.
PII detection and redactionConfigurable detection and masking before content is indexed or returned.
Retention you controlRetention windows, deletion and export set to your records-management policy.

Designed to support

Frameworks your deployment is configured to align with.
NIST SP 800-53FISMA-aligned deploymentSection 508WCAG 2.1 AAFERPA-aware handlingState records retention

Kolossus is certified against the three ISO standards above. The frameworks in this row describe how a deployment is configured to support your agency’s obligations. Kolossus does not claim certification against them, and does not substitute for your own authorization process.

Questions

Before you take this to IT review.

The questions that come up in every public-sector security and procurement review, answered directly.

Not covered here?

connect@kolossus.ai
What is the difference between an agent and a chatbot?

A chatbot is pointed at everything and asked to behave. An agent is bound to one system of record, such as a Tableau site, a permit schedule or a case system. It inherits that system's permissions, and can only answer what that source supports. That scoping is what makes an agent reviewable: you can state precisely what it can see, what it will refuse, and where every answer came from.

Can we start with one agent rather than the whole catalog?

That is the normal path. Almost every deployment starts with a single agent on a single system, most often a Tableau or Power BI agent replacing a dashboard, because the before-and-after is easy to judge. Additional agents are added once the first is in production.

Where does our data live, and does it leave our network?

It stays where you put it. Agents can be deployed entirely inside your own environment, on-premise or in your cloud tenant, so agency records never cross your network boundary. Where you prefer a managed deployment, data residency is set to the region you specify and documented in the deployment agreement.

Do you train models on our data?

No. Your documents, datasets and the questions your users ask are never used to train or fine-tune any model. They are used only to answer the query in front of them, and are retained according to the retention policy your team configures.

Can agents run fully on-premise or air-gapped?

Yes. Kolossus supports fully on-premise deployment against self-hosted models, with no outbound calls to third-party model providers. This is the configuration most often chosen by agencies handling regulated or protected records.

Which certifications does Kolossus hold?

Kolossus holds three certifications: ISO 9001:2015 for quality management, ISO 27001:2022 for information security management, and ISO 20000-1:2018 for IT service management. Deployments are additionally configured to support agency obligations under frameworks such as NIST SP 800-53, FISMA, Section 508 and FERPA, but Kolossus does not claim certification against those frameworks and does not substitute for your own authorization process.

How do you stop an agent from making things up?

Scope first: an agent bound to one source has nowhere else to draw from. Every answer is grounded in indexed records and carries a citation back to the document or dataset it came from, so any claim can be checked in one click. When a question falls outside the source the agent declines and offers a routing path. Refusal boundaries are configured by your team, and every query and response is written to an audit log.

Are the agents Section 508 and WCAG 2.1 AA accessible?

Agents are built to WCAG 2.1 AA: fully keyboard operable, screen-reader tested, with visible focus states and no reliance on colour alone. This is a common reason agencies move away from embedded dashboard tools, which are frequently the least accessible component on a public site.

What does it take to replace an existing dashboard?

Typically about four weeks per agent. We bind the agent to the same underlying data sources the dashboard reads, index them with source-of-truth mapping, configure the filters your users already recognise, and embed it where the dashboard sits today. The SUNY III-RP deployment on nyimmigrants.org followed exactly this path.

How is it procured, and what does a pilot look like?

A pilot is scoped to one agent on one system, runs in your environment, and produces something your team can put in front of real users. We supply the security documentation, ISO certificates, deployment architecture and accessibility statement your procurement and IT review will ask for.

Get started

Book a demo on your own system.

Name the system: a Tableau site, a permit schedule, a records repository. We will show you an agent answering real questions against it.

  • See an agent answering questions on a system you actually run.
  • Walk the citation trail, the audit log and the refusal behaviour.
  • Review the deployment architecture with your IT and security leads.
  • Leave with a scoped pilot plan and the compliance documentation pack.

Prefer email? Write to connect@kolossus.ai and we will reply with the same information.