Level 4 taught a manufacturing company to govern AI. Level 5 is about building the part that acts. A drafting assistant suggests; an automation does. It raises a proposed purchase requisition, updates a maintenance work order, routes a supplier certificate, drafts a nonconformance record or posts a status to the MES, and when it is wrong the error has already reached a record, a part, a customer or a controlled file by the time anyone looks. This level teaches automation whose authority is bounded in writing, whose every action is recorded, and whose failures are caught by design rather than by a customer auditor.

The first three modules set authority and orchestrate the work. Module one explains what changes when a system can act instead of write, sets the ladder from suggesting to acting inside the office systems, applies a three-question test before any authority is granted, and explains why nothing in this tier touches a controller, a robot, a CNC, an HMI or a safety function. Module two bounds each agent in writing on an agent authority register, with scope, systems, data classes, permitted and forbidden actions, rate and value limits, a named owner and a review date, and sets the permanent list of acts that stay with named people: dispositioning a part, releasing a lot, signing a certificate of conformance, closing a corrective action, approving a supplier, releasing a controlled file, making a reporting decision, placing an order and moving money. Module three splits a plant workflow into steps a system runs and steps a person owns, sequences them with an owned exception path, makes retries safe when a step half-completed, and designs every workflow to stop rather than improvise.

Modules four to six are the integrations. Module four draws every system an automation touches, labels the class of data crossing each edge, and writes a data contract for fields, units, revision identity and failure behaviour. Module five starts every integration with ERP, MES, QMS and CMMS read-only and in shadow, reads an interface contract before choosing how to connect, earns each write through proposed records a person commits, and explains why a write to a quality system carries electronic-record weight a spreadsheet edit does not. Module six treats the plant-floor network as a different problem, sorts the zero-trust ideas that carry over from those that do not, sets hazardous-energy control and machine guarding as absolute limits on automation scope, and writes the OT boundary statement that lets historian data flow out while nothing flows in.

Modules seven to nine are human control. Module seven designs approval gates that carry their own evidence and produce a decision rather than a click, explains what the research on automation bias studied and where its limits lie, fits gate volume to a twelve-hour shift, and measures whether a gate changes anything. Module eight gives every automation its own identity rather than a person's login, derives its roles from the data classes it touches, keeps credentials out of prompts and spreadsheets, enforces customer-programme and export-control segregation exactly as for people, and offboards an automation as deliberately as an employee. Module nine designs a stop named people may press without asking, reconciles work in flight and half-written records, keeps the manual route written and practised, and plans the return to automation and the day the vendor is down mid-shift.

Modules ten to twelve are defence and observation. Module ten traces how instruction-like text reaches a plant automation through quotes, packing slips, certificates, scans, email and machine output, from the defender's side only, and manages injection as a residual risk rather than a solved one. Module eleven specifies what every agent action record must hold, what it must never hold, how the log is kept intact and retained, and how to build a trail a customer auditor or incident reviewer can follow. Module twelve finds failures that raise no error, watches for drift after a model, vendor, material or process change, uses canary records with known answers and alerts people will still read, and counts the human review burden honestly.

Module thirteen responds when an automation has already acted: containing it without making things worse, tracing what reached a part, a record, a customer or a controlled file, finding the notification clocks that may apply and the named person who decides each, and running a review that changes the system. Module fourteen measures return against a baseline the plant took itself, counts review time as a cost, refuses double-counted savings and borrowed figures, and stages a rollout with stop criteria written first and a tested way back. The capstone is the Automation Implementation Project for a fictional plant. The level ships with a printable workbook and ten templates, and the examination draws forty scenario questions from a reviewed bank.

Everything here is professional education. It is not legal, engineering, quality, safety, cybersecurity or export-control advice, and it does not replace the employer's safety programme and its lockout/tagout and machine-guarding procedures, a licensed professional engineer where a state requires one, the person your quality system names, an empowered customer representative, your export authority, legal counsel, or the law that applies to your plant. Completing the level earns an independent educational certificate issued by AI Coalition Network with a public verification page. It is not an engineering licence, a systems-integration or safety qualification, a cybersecurity certification or a regulatory approval, it carries no professional development hours, and it qualifies no one as an authorised employee, a competent person, an auditor or an assessor under any standard, scheme or contract.