VaultPilot's 9 defense layers: an agent that writes to your PDM cannot improvise

I built an AI agent with write access to Autodesk Vault in production. And the first thing I designed was not what it does. It was what it CANNOT do.
An agent that only reads data is a nice demo. One that writes to your PDM (lifecycles, properties, BOMs, ECOs) plays in a different league: a mistake there has no Ctrl+Z. A wrongly changed state can release a drawing that was not ready, or stall a production order.
That is why VaultPilot, the agent we developed together with Avant Leap for Autodesk Vault Professional 2026, starts from a premise that marketing finds uncomfortable: the model can be wrong. The whole design assumes that at some point it will be, and surrounds it with 9 anti-hallucination defense layers.
The layers that do the heavy lifting
Dry-run with confirmation. Before touching anything, the agent shows exactly what will change: which files, which properties, which states. Then it waits for your confirmation. The real operation only happens after your "yes".
Validation against the real schema. LLMs happily invent property names and states that do not exist. Every operation is validated against the real schema of YOUR Vault: if the property does not exist, the operation does not happen.
Write verification. After every change, the agent reads the data back and compares it with what should be there. If it does not match, it reports it.
Hard limits. There are operations the agent refuses to execute, no matter how you ask. That is not a limitation: it is a feature. An agent without red lines is not finished.
Full audit trail. Who asked for what, what changed and when. Everything logged, everything traceable.
The layer almost nobody designs well
Every chat runs with the user's own credentials. No service accounts with admin rights, no backdoors. If you cannot release that drawing, neither can the agent. The agent inherits your limits instead of bypassing them.
The right question
VaultPilot exposes 28 tools across 9 categories: search, lifecycles, properties, bulk operations, BOMs, ECOs, jobs, ERP integration and reports. But when you evaluate an agent that writes to production data, the right question is not "what can your AI do?".
It is "what do you prevent it from doing?".
Is a process inside your Autodesk products stealing your hours?
Tell me about it and I will honestly say whether it needs AI, classic automation or something simpler. No hype.