The agentic traffic era has opened — agents now query your systems, compare your products, and execute on behalf of customers without a human in the loop. Owning your external surface is the thesis; this is what it looks like on IBM i — the concrete stack your environment needs before that traffic arrives.
Agent-ready is not a single thing you turn on. It is five gates an organization opens, in order, before agentic traffic can flow through its systems without breaking. Miss any one layer and you create a failure mode. Build them in the wrong order and the governance layer never catches up to the execution layer.
The IBM i organizations sitting on decades of encoded business logic are closer to agent-ready than most. The hard part — trusted data, object-level security, journaled audit trails, business rules proven at scale — is already built. What's missing is the layer that makes it consumable by an agent. This reference maps the five gates, what each one is, and where IBM i sits in it.
"This surface already exists. The only question is whether you've governed it — or left agents to read you on their own terms."
This is your external surface: the outward face agents form their picture of you from. By default your IBM i system has no presence an agent can navigate — no llms.txt, no structured manifest, no declared policy on what an agent may query or invoke. But the surface is not neutral in its absence. Agents still arrive; they simply read you badly, or route to a competitor whose surface is legible. This layer isn't about being found — it's about being correctly and safely represented to a class of reader that already outnumbers humans on the web.
"Can an agent understand what you do well enough to act on it correctly?"
The business logic that governs your operations lives in RPG programs and Db2 tables. No agent can read RPG directly. But agentic coding tools can surface that logic into human-readable documentation that becomes the foundation for machine-readable specifications. This is the knowledge-extraction step — and it is where decades of encoded logic becomes an asset an agent can finally reach. It is the work of closing Knowledge Distance on the technology side.
"Can an agent reach the sovereign core — without changing it?"
This is the bridge layer: APIs and the MCP interface that make RPG and Db2 reachable and agent-legible without rewriting the core. The encoded logic stays exactly where it is, protected at the center; the access layer exposes it on terms you define. This is where IBM i's reliability becomes an agentic advantage rather than a constraint.
"When an agent acts, can you prove what it did — and stop what it shouldn't?"
Governance is the layer that makes everything above it safe, which is why it is built into the foundation rather than bolted on at the end. Every agent action authenticated, permissioned, and logged. Runtime enforcement, deterministic policy, and an audit trail are not features you add later — they are the precondition for letting an agent near the core at all.
"Can agents do real work — under human governance — at agentic speed?"
With the four layers beneath it in place, agents can execute real work against the systems that run the business — querying, comparing, acting on behalf of customers — while humans govern strategy, judgment, ethics, and escalation. This is human-agentic operation: agents execute, humans govern, the sovereign core stays protected the whole way.
The five gates are not a menu. They are a sequence, and the order is the whole point. Skip a gate or invert the order, and the failure shows up exactly where you can least afford it — at the boundary between an agent and the core that runs your business.
The advantage for IBM i organizations is that the hardest part is already done. The logic exists. The reliability exists. What remains is the reachability — built in, not bolted on.
This page asks whether an agent can reach your logic at all. Its companion asks where the value sits once it can — five layers of the agentic stack, and which one resists commoditization. The agentic stack →
Owning your surface is a thesis that holds for any organization on any platform — the full argument, and why it may need to go first, lives at Pegasus Source. But its deepest layers — edge, governance, and the core an agent must never rewrite — are inseparable from the platform they run on. That is the part that is ours. On IBM i, guarding the surface isn't a set of files bolted to a website; it's object-level security, journaling, and a sovereign core that records every touch, below the application, where getting past the edge buys an attacker far less than it does anywhere else. The thesis is universal. Guarding the perimeter on IBM i is not.
03 / 03 · The technology axis · ← 02 The agentic stack · ↑ Back to the map