Team up
for digital change

Harmony partners with companies to accelerate growth and navigate digital transformation.
We provide comprehensive business consultancy and tailored IT solutions. We pride ourselves on a no-nonsense and people-first approach.
Contacteer ons!

Team up
for digital change

Harmony helpt bedrijven groeien door digitale transformatie met business consultancy en IT-oplossingen. No nonsense, met ervaring en enthousiasme.

Onze AANPAK

The future is built on collaboration
Let’s create success, together.

Who we are
People powering real results
This is what people say about us...
"Harmony’s CustomerConnect has been a game-changer. It's truly accelerated our communication process."
It's official
We are thrilled to share that we've been certified as a Great Place To Work! This recognition validates our culture, but our journey to excellence continues...
Connect
Questions? We are happy to help. Reach out via phone, email, or stop by any of our offices.
Careers
Develop your expertise on complex, rewarding projects and a supportive team that invests in your growth.

Onze EXPERTISE

Digital transformation for innovative companies

Bridging the gap between ambition and results

De brug tussen ambitie en een resultaat

Our consultants are more than just digital specialists; they are strategists who understand your business from every angle.

We combine proven digital expertise with human-centered methods to successfully guide your business into the digital future. Our motto? Driving transformation, faster, better.

INTEGRATIE

Experts in complex integration challenges

A practical integration platform promotes seamless data exchange, better client and employee experiences, and always-on access to crucial business information.

Our integration specialists make your IT landscape future-proof and ready for the artificial Intelligence revolution.

BUSINESS APPLICATIES

Your own application landscape of smart and fast apps

Standard packages are excellent, but sometimes they fall short. We build tailormade applications that fit your unique demands exactly.

With OutSystems, we build a customized application landscape for your ambition. Low code, high performance: applications your team loves to use and that deliver a clear return on investment.

KLANTCOMMUNICATIE

Personalised communication tailored to your customers

No two clients are alike. Some prefer physical mail, while others rely entirely on app or email updates.

With CustomerConnect we offer a digital tool to take care of personalised communication that feels unique to every customer, whether delivered through the letterbox or digital channels.

We believe in empowering talent to drive change.
Let's build success stories, together.

Trusted by

Our insights

All articles
Artificial Intelligence
Going beyond the pilot: Making Agentic AI work in production

Generative AI has taken the boardroom by storm over the past couple of years. Today, almost every organisation is experimenting with copilots, chatbots and AI-driven assistants. Yet for many CIOs and CTOs across the Benelux, Nordic and DACH regions, the same question keeps coming back: how do we move from clever answers to controlled action within real business processes?

The market is moving fast. AI today mostly supports the generation of content, insights and analysis. A new phase is now emerging in which AI doesn't just advise, it acts. This is Agentic AI.

It's a phase in which AI no longer simply responds to a prompt. Instead, it helps deliver business outcomes by steering systems, retrieving information, carrying out actions, and collaborating with people and other AI agents. It isn't a chatbot with a job title. It's a governed piece of software that translates goals into action within clearly defined boundaries.

Analysts expect Agentic AI to find its way into enterprise software and operational IT environments more and more over the coming years. At the same time, it's becoming clear that autonomy without sufficient controls introduces new risks around security, cost management and operational stability. The question many organisations now face isn't whether Agentic AI will break through. It's how to deploy it safely, manageably and at scale.

That's the challenge behind the AI Agentic Lab we set up at Harmony. It isn't an experimental playground. It's an environment where we work with clients to explore how AI agents can be safely integrated into existing processes, systems and architectures. The goal is to shorten the distance between a promising pilot and a production-ready solution, and to get a clear picture of what that actually costs. The business models behind AI tooling are still very much in flux, and pricing shifts constantly, which is exactly why the AI Agentic Lab puts serious effort into mapping out the costs of a first MVP or proof of concept.

The Benelux, Nordic and DACH gap: from pilot to production

Across the Benelux, the Nordics and the DACH region, the challenge is no longer generating interest in AI. That interest is already there in abundance. The real gap lies between experimenting and operationalising.

Local market research across these markets tells a consistent story: many organisations now have AI strategies and pilots in place, yet only a small proportion are running AI at scale in production. A lack of specialist integration expertise and complex governance questions are consistently cited as the biggest obstacles to further adoption.

The Harmony AI Agentic Lab sits precisely at that intersection of AI, integration, architecture and governance, starting not from the technology alone but from concrete business processes and measurable business value.

The shift from task-driven to goal-driven

Traditional automation is task-driven. You define in advance which steps need to happen, and in what order. An AI agent works in a fundamentally different way: instead of a task, it's given a goal.

For example: "Reduce the turnaround time of customer files by 15%."

To reach that goal, the agent can analyse process information, identify missing data, consult relevant systems, and propose or carry out next steps. Think of an HR agent that, once a contract is signed, independently assigns IT access rights, orders hardware and sets up an onboarding schedule.

Not every step needs to run fully autonomously from day one. In mature agentic architectures, autonomy is built up in stages:

  1. Assistive Agent. Advises and suggests actions; the human decides.
  2. Supervised Agent. Prepares actions; the human approves before execution.
  3. Bounded Execution Agent. Carries out low-risk tasks independently, within predefined limits.
  4. Orchestrated Multi-Agent Process. Coordinates activity across multiple systems, with continuous monitoring and escalation.

For IT leaders, this marks a shift away from software that simply reacts to input, towards intelligent execution layers that actively contribute to business objectives.

The real challenge isn't just AI. It's integration

Demonstrating a working AI agent has become relatively straightforward. The real challenge starts when an agent needs access to business-critical systems and live data. That's where the hard questions surface:

  • Which datasets is the agent allowed to use?
  • What permissions does it get within the ERP or CRM system?
  • How do we stop an agent operating beyond its remit?

An AI agent without access to the right systems remains, in the end, a smart conversation partner. Real business value only emerges once AI can read, write and act in a controlled way within day-to-day operational reality.

That's why, within Harmony IT, we build on years of integration expertise. Using technologies such as MuleSoft, Frends, Oracle and OutSystems, we connect agents to the systems behind the scenes, so they can act in a controlled, governed way. Agentic AI then stops being a bolt-on technology and becomes a powerful extension of your existing application landscape.

RAG: from model knowledge to business knowledge

Public AI models don't have access to your internal documents, policies or contractual agreements. That's why many enterprise AI solutions are built on Retrieval-Augmented Generation (RAG).

RAG gives an agent controlled access to relevant business information at exactly the moment it's needed. This makes outputs better substantiated and traceable back to their sources, grounds answers more firmly in validated business information, and significantly reduces the risk of hallucination.

From standalone agents to a governed ecosystem

In practice, a process is rarely handled by a single agent. Increasingly, we see specialist agents working together: a service agent for customer queries, an integration agent for data retrieval, a compliance agent for checks, and so on.

Together, they form an ecosystem with clearly divided responsibilities. Human-in-the-loop oversight remains essential here, not because the technology falls short, but because context, accountability and strategic judgement call for it.

Governance doesn't have to be a brake on innovation

As AI is given more autonomy, governance matters more, not less. For organisations operating under the strict rules of GDPR and the EU AI Act, which is being phased in step by step, that's simply non-negotiable. Coverage does vary slightly across the region: GDPR applies directly within the EU and, via the EEA, in Norway and Iceland, while Switzerland works to its own broadly equivalent FADP. The EU AI Act itself is an EU instrument, so organisations in Switzerland and the EEA states should check how, or whether, it applies to them directly.

Within the Harmony AI Agentic Lab, we work to a principle we call Governance by Design. An agentic environment is never just one model. It consists of a reasoning layer, an integration layer, and robust Identity & Access Management (IAM). With explicit identities for agents, fine-grained access rights and comprehensive audit trails, we make sure AI behaves predictably, verifiably and responsibly. Security, guardrails and data sovereignty are non-negotiable parts of that picture too.

From demo to digital colleague: the Harmony Agentic Lab

Over the coming years, many organisations will build AI agents. Some projects will remain impressive demos. Others will grow into a fundamental part of the business.

The difference won't come down to the model alone. It comes down to the quality of the integrations, the enterprise architecture, the governance, and the ability to let AI collaborate safely with people and systems.

That's why we set up the AI Agentic Lab at Harmony: to help organisations make the leap from experiment to production, and from AI tool to digital colleague.

Together, we explore which processes hold the most potential, what architecture is needed to let agents work safely alongside existing systems, and what governance measures are needed to keep risk under control.

Rather than one-off demonstrations, we focus on concrete outcomes:

  • identifying and validating use cases;
  • a business case and ROI estimate;
  • architecture and integration blueprints;
  • governance and security frameworks;
  • working prototypes;
  • a roadmap to production.

The result is a structured pathway that lets organisations grow, in a controlled way, from experiment to enterprise-wide adoption.

Explore. Experiment. Accelerate.

Not to demonstrate AI, but to make it actually work.

Ready to move from demo to digital colleague? Discover what the Harmony AI Agentic Lab can do for your organisation, and turn experiments into measurable business value. Get in touch with us today.

Lees meer
Artificial Intelligence
Hacking agents is easy. Securing them is difficult.

AI agents are shifting rapidly from answering questions to taking actions. They retrieve customer data, trigger workflows, create documents, communicate with business systems, and automate decisions. With that new power comes a new challenge: as agents grow more capable, the consequences of failure grow considerably larger too.

At the recent OutSystems ONE 2026 Conference, security and governance came up again and again in the conversations around agentic systems. The pattern is hard to miss: building an agent gets easier every month, while securing it stays genuinely hard.

At Harmony Group, we increasingly work with organisations that want to go agentic, and one lesson keeps proving itself: security cannot be treated as an afterthought.

The Big Misconception

When people talk about AI risk, they often think immediately of data privacy. Questions such as:

  • Will our own data be used to train public models?
  • Are we masking personally identifiable information (PII)?
  • Can sensitive customer information leak into prompts?

These are important questions, and sound privacy controls remain indispensable.

But privacy and security are not the same thing.

The incidents that surprise organisations most are often not privacy problems at all, but failures in system design, governance, and security. Attackers increasingly target AI systems through techniques such as prompt injection, jailbreak attempts, poisoned content, and compromised integrations. The goal is often not to reach data directly, but to manipulate the agent's behaviour.

If an AI agent is manipulated into ignoring its instructions, exposing sensitive processes, or carrying out unintended actions, the model provider is not the only party affected. The organisation operating the agent carries the responsibility, and the reputational risk along with it.

What This Looks Like in Practice

Abstract warnings about "prompt injection" only become tangible with a concrete example. Take EchoLeak (CVE-2025-32711), a vulnerability in Microsoft 365 Copilot discovered in 2025.

What made it dangerous? It was a zero-click attack. The victim only had to receive a malicious email; opening it was not even necessary. As soon as the user later asked Copilot to, say, summarise some documents, the AI also read that email in the background. The attacker's hidden instructions were carried out directly, quietly leading to a leak of company data.

No firewall was breached and no passwords were stolen. The assistant simply did what it was meant to do: read and process content. The instructions just came from the wrong person.

The structural problem: indirect prompt injection

This phenomenon is called indirect prompt injection: hostile instructions that do not come from the user themselves, but sit hidden in external content the AI takes in. It was described in theory as far back as 2023 (Greshake et al.), but EchoLeak proves it is now a real risk to enterprise software.

Security researcher Simon Willison explains this vulnerability through the "lethal trifecta". Any AI system that combines the following three properties is, by design, susceptible to data theft:

  1. Access to private data.
  2. Exposure to untrusted content (such as emails or websites).
  3. The ability to communicate externally.

Because most useful enterprise agents need precisely these three functions to do their work, securing them is so extremely complex.

An Architecture Problem

One of the biggest mistakes organisations make, therefore, is assuming that AI security can be outsourced to the model provider.

Modern AI systems are far more than a single LLM. They consist of prompts, orchestration layers, APIs, databases, vector stores, external tools, business logic, and user interfaces working together.

Even the most advanced model can become a security liability the moment it is built into an insecure architecture.

The real challenge, then, is not securing the model itself but the entire ecosystem around it. And that calls for a broader view of how agentic systems are designed, deployed, and governed.

A Way to Think About the AI Stack

It helps to see agentic systems as a layered problem, where each layer introduces different risks and calls for different protections. It is less a proprietary framework than a practical way of making sure nothing gets overlooked.

Broadly, it breaks down into three domains.

1. The Capability Layer (Models)

This layer contains the large language models, embedding models, and reasoning engines that power the agent.

These models are incredibly capable, but they are not deterministic security systems. They can be influenced by carefully crafted input and remain susceptible to prompt injection and jailbreak techniques. Prompt injection sits at the top of the OWASP Top 10 for LLM Applications, and understanding those limitations is the first step towards a secure implementation.

2. The Intelligence Layer (Pipelines and Orchestration)

This is where the real business logic lives. The intelligence layer connects models to APIs, databases, enterprise applications, knowledge sources, and other agents. It orchestrates workflows and determines how information flows through the system.

Classic cybersecurity concerns remain highly relevant here. Compromised credentials, exposed API keys, vulnerable integrations, or insufficient access controls can allow attackers to bypass the user interface entirely and communicate directly with backend services.

This is also where the most under-appreciated agentic risk lives: excessive agency. OWASP lists this as a distinct top-ten risk for LLM applications, and it is arguably the defining agentic vulnerability. An agent has excessive agency when it holds more capability, permission, or autonomy than the task requires: too many tools, overly broad API scopes, or the ability to take consequential actions (send, delete, pay, escalate) without a human check.

EchoLeak is dangerous because Copilot could both read private content and act within a context that untrusted input could reach. Break that combination (separate reading from any external action, require confirmation before consequential steps, grant the narrowest permissions the task needs) and the same injection attempt fails without harm. In practice, agentic security is largely about the disciplined management of what an agent is allowed to do, not just what it is allowed to read. As agents gain access to more enterprise systems, governance at this layer becomes critical.

3. The Experience Layer (User Interaction)

The experience layer covers the applications, portals, and interfaces through which users interact with agents.

This is often where malicious input enters the system. Users may, deliberately or unwittingly, supply misleading, contradictory, or manipulative instructions. And as EchoLeak shows, hostile input does not always come from the person at the keyboard; it can ride in on any content the agent takes in. Without proper safeguards, those inputs can influence behaviour further down the chain and produce unexpected outcomes.

Public-facing agents should therefore be designed on the assumption that hostile input is ultimately inevitable.

How We Approach Secure AI at Harmony

There is no universal security framework you can simply drop onto every AI project. Security starts with context.

Define the threat model first. A customer-facing support agent faces completely different risks from an internal HR assistant or an AI-driven clinical decision-support tool. Before you build in controls, you need to understand the specific risks of the use case you are solving.

Trust no input, wherever it comes from. User prompts, retrieved documents, emails, and responses from external APIs all deserve the same treatment as external input entering a classic application. Validation, separation of responsibilities, and controlled access remain essential.

Constrain agency deliberately. Give an agent the fewest tools and the narrowest permissions its task requires, separate read access from write and send access, and put a human in the loop for consequential or irreversible actions.

Put guardrails and governance in place. Modern AI platforms increasingly offer dedicated governance capabilities. Where a low-code platform such as OutSystems, with Agent Guardrails, focuses on monitoring and protecting prompts and responses at the application level, MuleSoft extends that governance into the data and integration layer. Through MuleSoft you can enforce strict API policies on the gateways that connect LLMs and (external) AI services to your enterprise systems. Such controls do not eliminate risk, but they form an important layer within a broader defence-in-depth strategy.

Stay close to the research. The AI security landscape changes at a remarkable pace, and many emerging attack techniques surface in research papers long before they become mainstream in the industry. Staying informed means following academic research, security communities, and frameworks such as OWASP's guidance for the security of LLM and agentic applications.

Building for Enterprise Requirements

At Harmony IT, we do not just help customers adopt AI. We also work out how to keep it running in tightly regulated environments, with private development ecosystems, controlled CI/CD pipelines, and reusable AI assets that fit real compliance requirements.

We also experiment through internal research and community projects, including work on AI benchmarking and evaluation tooling, because you cannot secure or trust what you cannot measure.

The Road Ahead

AI agents are rapidly becoming part of the IT landscape. The question is no longer whether organisations will deploy them, but how they will do so responsibly.

Security can no longer be a compliance checkbox added at the end of a project. It has to sit in the architecture from day one.

Because while building an agent gets easier every month, building one that stays trustworthy under pressure is the real engineering challenge.

Putting agents into production and want a fresh pair of eyes on where they might have too many permissions? That is a conversation we are glad to have.

Lees meer
Life at Harmony
Corporate Social Responsibility: how we take it to heart

When I started working in digital transformation, everything centred on technology.

Working more efficiently. Improving processes. Helping organisations grow. New tools, new ways of collaborating; that was what mattered.

But the longer I've worked in this sector, the clearer it becomes: real progress isn't just about systems. It's about people. About energy. About wellbeing. And about the impact you have as an organisation on the world around you.

Over the past year, a question kept surfacing for us:

If we're helping organisations transform, how do we ensure we're making a positive impact ourselves?

Not just for our clients. But for our colleagues too. Our community. Society.

CSR can start with a question


Corporate social responsibility often sounds like something requiring a formal strategic plan straightaway. Sustainability reports. Targets through to 2030. The whole package.

For us, it started much simpler. One colleague took the initiative, sent an email asking who wanted to get involved, and that's how the CSR working group came about.

We put a collection box for used batteries in the office. No grand announcement. No communications campaign. It was simply needed.

That captures how we approach this: small, concrete actions that people genuinely care about. No big speeches. Just doing it. And there are plenty more examples of activities we run—here's a straightforward, honest list of them.

Transformation demands energy. From you. From your team.


Our sector moves fast. Projects come one after another. Change is constant, and before you know it, you're just pressing on. That's why last year we deliberately focused on rest, resilience and sleep.

Not as some abstract concept. But practically: How do you create space for people to do good work? How do you prevent yourself and your team burning out? We organised practical sessions with the team.

After one of those sessions, a colleague said: "I thought I was just a poor sleeper. But actually, I never take proper breaks."

That's the point. Technology transforms organisations, but people make that transformation happen. Looking after those people is crucial.

Looking after each other can also be something practical


Another initiative that generated a lot of positive response was first aid training.

Not because we expect something to go wrong every day. But because there's something reassuring about knowing you can help if it's needed.

The training itself was typical Harmony: serious in content, but with room for humour and genuine conversation.

Impact beyond our own doors


What perhaps made the strongest impression were the actions we took beyond our organisation.

We donate regularly to different causes. But the Christmas collection drives for food banks in the Netherlands and Bosnia, and St Vincent de Paul in Belgium, always generate real engagement. We fill several boxes in the office each year.

Colleagues don't just bring items. They choose carefully. They do a bit of extra shopping for "the box." Some colleagues explain why they want to contribute. They share difficult periods. Stories about how close vulnerability sometimes sits to home.

In those moments, it doesn't feel like a "corporate initiative." It feels like something we're doing together.

Not everything is straightforward


Not every action drew large numbers immediately. Sometimes we had to remind people. Sometimes we questioned whether we were approaching it the right way.

Even when things don't go as hoped, we can still extract something from it. To stay true to ourselves, for example. Because corporate social responsibility only works if it's genuine. Not because it looks good on LinkedIn, but because it aligns with who you are as an organisation.

So we keep it simple. Start small. Listen. Adjust.

Actually, it's much like how we approach digital transformations.

What this reveals about how we work


What I find most valuable is that these initiatives don't feel imposed from above.

They emerge from conversations. From colleagues' ideas. From small suggestions that grow because people genuinely care about them.

That no-nonsense mentality suits our sector too. We believe in trying, learning and improving. Not waiting for the perfect plan, but starting and getting better as we go.

And perhaps that's the most important lesson from the past year: you don't change culture through grand statements.

You build culture through small, consistent actions.

Where we're heading


We're still at the beginning with our CSR working group. That's fine.

CSR isn't a project with an end date. It's a way of working. A way of thinking about what responsibility means.

We want to keep investing in wellbeing, sustainability and social impact. Not because it ticks a box, but because we genuinely believe it matters.

Digital progress is powerful. Digital progress with genuine attention to people; that's what we're after.

Lees meer