Tutorial: Operating a Digital Organisational Twin (DOTS)
This tutorial demonstrates how to operate a Digital Organisational Twin (DOTS) to orchestrate specialised AI agents within a secure, sovereign on-premises environment.
Step 1: Map the organisation with the organisational twin
The organisation is mapped by assigning scoped managerial entities to each specialised team of autonomous agents. This hierarchy establishes clear accountability across operations without exposing any personal employee identifiers.

- Managerial governance: structured divisions covering Executive, Business Development, Engineering, IT Services, Finance, and Security.
- Commitment thresholds: financial checkpoints (€800 to €5,000) triggering mandatory sign-off requirements.
- Institutional framing: role-based oversight without disclosing personal individual identities.
Step 2: Supervise live agent activity and execution
Live agent activity is continuously monitored through heartbeat telemetry and real-time execution status streams. The supervision cockpit detects latency spikes and idling workers before disruptions impact production.

- Heartbeat tracking: real-time health checks tracking 26 deployed roles and 142 emitted signals.
- Idle standby savings: 73.8% token economy achieved by keeping dormant agents in sleep state until triggered.
- Real-time event ledger: live 3-second audit stream registering builds, invoice transmissions and microcode updates.
Step 3: Arbitrate HTTP 409 quarantine and approvals
The HTTP 409 quarantine gate intercepts every action exceeding financial, technical or compliance thresholds. Operations are safely paused until a verified human operator signs the approval token.

- High-value quote: €84,500 server tender held pending commercial director electronic signature.
- Infrastructure change: Ceph zero-downtime cluster maintenance requiring sysadmin authorization.
- Privileged access: ISO 27001 bastion rotation awaiting quality and security clearance.
Step 4: Isolate ReBAC memory and knowledge graphs
Knowledge graphs and episodic memory are partitioned across business units using role-based and relationship-based access controls. Sensitive compensation records remain masked while non-confidential operational facts synchronize across teams.

- 23 ontological nodes: distinct memory stores isolating sensitive customer records from general operations.
- 100% NDA isolation: complete separation of client banking and healthcare project databases.
- Blind salary projection: macro-level financial rollups without exposing individual compensation files.
Step 5: Trace agent execution with OpenTelemetry
Agent execution traces are propagated using W3C TraceContext headers and OpenTelemetry spans. The waterfall visualizer connects high-level business goals down to low-level tool calls and verification steps.

- Standardized spans: end-to-end auditability across security audits (280 ms) and incident triage (310 ms).
- Local governance bridge: dedicated sovereign daemon link with zero external SaaS telemetry dependency.
- Sub-agent waterfall: complete hierarchical visualization of root goals, child tasks and validation proofs.
Step 6: Enforce financial quotas and token ceilings
Financial quotas and hard token budgets are enforced per agent to prevent inference cost overruns. Once a threshold is reached, inference calls are automatically blocked until administrative review.

- Global fleet ceiling: hard monthly cap of $2,420 across 26 specialised agent profiles.
- Token allocation: 478 million tokens budgeted with automated sleep reclamation saving 352 million tokens.
- Hard enforcement: 100% active budget blocking preventing runaway inference expenses.
Comparison: Unregulated Swarms vs Sovereign DOTS
Deploying a sovereign organisational twin replaces unconstrained agent swarms with deterministic accountability, strict audit trails and guaranteed data containment on-premises.
| Governance dimension | Unregulated agent swarms | Sovereign DOTS on-premise |
|---|---|---|
| Role boundaries | Isolated agents without clear hierarchy | Multi-level organigram and strict accountability |
| Critical actions | Unchecked direct execution | HTTP 409 quarantine and mandatory human signature |
| Memory & context | Flat shared memory leaking confidential data | Dual topology with blind aggregation and ReBAC |
| Compute auditability | Dispersed unindexed logs | OpenTelemetry waterfall and local telemetry daemon |
| Financial governance | Uncapped API billing with unexpected spikes | Granular quotas and 100% hard blocking rules |
Frequently asked questions
What is a Digital Organisational Twin (DOTS)?
A Digital Organisational Twin (or Digital Organisational Twins) is the real-time software replica of an organisation, modeling its roles, processes and decision flows.
Why run an organisational twin in on-premises DOTS mode?
An on-premises deployment guarantees data sovereignty, regulatory compliance and prevents sensitive business intelligence leaks to external providers.
How does the HTTP 409 quarantine gate protect operations?
The HTTP 409 quarantine mechanism automatically halts high-risk actions exceeding predefined thresholds, requiring human operator sign-off before execution.
Deploy your Digital Organisational Twin with QDNA
Consult with our architects to deploy your Digital Organisational Twins and operational cockpit in a sovereign, on-premises DOTS architecture.
Book a callFurther reading
- Orchestrating multiple code agents in parallel: the supervisor agent
- From chatbot to agentic platform: harness, memory and skills