The layer your security review is looking for. A policy engine evaluates every tool call, approvals are enforced at runtime and spent after one use, PII and prompt injection are screened by policy, spend has hard ceilings, and every action lands in an immutable, exportable audit trail — pinned to the exact configuration it ran under.
In a pack, governance arrives on: permissions, approval gates and the audit ledger active from run one.
See Solution Packs →One hour, five questions, and the checklist green thirteen minutes early: the catalog, single-use grants, the trail, config-pinned history, and the failure drills. Sound on.
A model can be talked out of a plan. It cannot be talked past a gate that sits in the execution path. Every control on this page is enforced where the action happens — on the tool call, at runtime, with the verdict recorded.
That's the difference between a policy document and a policy engine. One asks the AI to behave; the other makes misbehavior a no-op. And because the controls live in the runtime, they cover every entry point the same way: chat, schedule, trigger, API, mobile, MCP client.
Scope what it touches, screen what it reads, gate what it writes, cap what it spends — and keep a record of all of it, forever pinned to the config that produced it.
Governance here is not a PDF your vendor emails you. It's a policy engine that sits between every worker and every tool: rules with a priority order, conditions on the integration, the exact function and whether it reads or writes, and five possible verdicts — allow, deny, require approval, alert, or log. Every evaluation is recorded, including the ones that allowed.

The platform ships a catalog of 1,095 integration functions across 50 integrations, each with a human-readable name and a read-or-write classification. When you write a policy, you pick the exact functions it governs — 'Send email', 'Approve merge request', 'Delete row' — instead of guessing at wildcard patterns and hoping they match.

Most platforms check permissions when a plan is written. This one also checks at the moment each tool call executes — a runtime authorization floor underneath everything. A write that was never approved doesn't run, even if a clever prompt, an injected instruction or a misbehaving model put it in the plan. And every approval is single-use: it releases exactly one action, then the next one asks again.

Autonomy is not a switch, it's a dial with four positions: human-in-the-loop, supervised, bounded, full. Each AI employee carries its own scope, with hard caps on actions per turn, and moves up only when its record earns it. Widening autonomy is one change; narrowing it back is one change too — and both are versioned.

Two policies watch the data itself. A PII policy detects emails, phone numbers, SSNs, card numbers, addresses and names in what agents read and write, and masks, hashes, removes or flags them — your choice, with allowlists for the exceptions. A prompt-injection shield scans untrusted content — tool results, knowledge chunks, table rows, webhook payloads — before it re-enters a model's context, and flags, wraps or blocks anything that looks like an instruction.

Budgets are hard caps, per day or per month, per workspace, employee or team. The platform forecasts spend against the period and shows the breach date before it happens. Circuit breakers watch cost and error thresholds live and auto-pause a worker the moment one trips — a runaway loop burns a ceiling, not a quarter's budget. Critical halts page the right people even through quiet hours.

Every run and every tool call lands in the audit trail: inputs and outputs sanitized, PII flagged, read-vs-write classified, filterable by worker, integration, user and date. And because configuration is immutably versioned, each run is pinned to the exact configuration it executed under — so 'what was this agent allowed to do on March 3rd' is a lookup, not an argument.

Every object in the platform is scoped to an organization and a workspace — data, workers, policies, budgets, audit. Inside the org, a single authorization matrix decides what each role can do: Owner, Admin, Builder, Member, one role per person, every API check answered from the same matrix. Groups share access to specific resources without escalating anyone's authority, and SSO, 2FA and session limits sit underneath it all.

Follow a single consequential action — an AP agent releasing a vendor payment — through the layers it crosses. Not a workflow you configure step by step; this is what the runtime does, every time, on its own.

Six rule types, five verdicts, priority-ordered and versioned. Evaluated on every tool call; every evaluation logged.
1,095 functions across 50 integrations, named and read/write-classified, so policies bind to exactly what you mean.
Writes gated at execution time. Approvals are single-use grants that expire; unapproved steps cannot run.
Four scopes per worker, human-in-the-loop to full, with hard per-turn action caps. Reversible in one move.
PII detected and masked, hashed, removed or flagged. Untrusted content screened before it reaches a model.
Hard daily and monthly caps with breach-date forecasting; breakers auto-pause a worker when a threshold trips.
Every run and tool call recorded and sanitized, each pinned to the exact config version it executed under.
How long run data, audit records and conversation history live is a policy you set, not a vendor default.
Complete operating system for a Chartered Accountant practice. Tracks clients, engagements, statutory deadlines, and IT/GST notices. Includes AI agents for notice triage, GST reconciliation, filing reminders, and client communication. Comes with an AI Employee (Priya) who coordinates compliance work end-to-end.
The accounts payable and bank reconciliation desk a fractional controller runs for a client. Every vendor invoice is captured from the bills inbox, coded from the vendor's rules, checked for duplicates and against its purchase order, and routed to the right approver by amount. Approved invoices become a posting pack for the ledger and a weekly payment run. Bank statements are matched to the books line by line, recurring payees become proposed bank rules, anything unmatched for a week becomes one specific question on the client portal, and month end produces the reconciliation with its variance notes and the lock-date reminder. Comes with Cass, an AP and Close Coordinator who runs the queue.
Signal-based outbound for a founder or a small GTM team. Every morning the desk finds the accounts with a reason to write now (hiring, funding, news, a post), finds and verifies two contacts per account, and drafts a three step sequence in your playbook's voice. You approve, and the email goes from your own inbox. Replies land in one queue, classified with the next step ready. Meetings get a one-page brief. Your CRM stays the record. Comes with Remy, an Outbound Coordinator who runs the morning queue.
Contracts drafted, sent, chased, filed and watched, with a person at every step that matters. A colleague requests a contract from the portal; the drafter fills the approved template from the request and the CRM and marks what it could not fill. A person reviews and sends it for signature. Every morning the unsigned envelopes are chased and the old ones escalated. When a contract is signed its key terms (payment, liability, termination, renewal, governing law) are read from the PDF into a table with anything non-standard flagged, and the signed copy is filed by counterparty and type under your naming convention. Every Monday the contracts inside their notice window get a renew, renegotiate or terminate note for the owner. Works with Dropbox Sign, Google Docs, Google Drive and HubSpot. No agent ever signs, voids or counter-signs. Comes with Ren, a Contracts Coordinator, a Contracts Helpdesk and a portal for requesters.
The support team's queue, prepared. Every new ticket is read, categorised, given a priority and a drafted reply from your help centre within a minute; a person reads and sends. Questions that keep coming back become draft articles. Bugs are escalated to engineering with the steps and the evidence attached. Calls are summarised into a ticket. At the end of the day the team gets the volume, the response time and the three complaints of the day. Works with your helpdesk (Zendesk, Freshdesk, Intercom, Help Scout, Gorgias, Front and others), your phone tool and your issue tracker. Nothing is sent, refunded or closed by the software. Comes with Sol, a Support Coordinator.
Founder-led content for a founder or a small team. Every morning the desk listens (Reddit, LinkedIn, X, YouTube) for what your buyers are asking, turns the best of it into ideas by pillar, and drafts posts in your voice for LinkedIn and X. You approve; the desk hands you the final text to paste and post. Comments and reactions on what you published are harvested, and the people who match your ICP become leads. A newsletter issue is assembled from the week. Monday tells you which pillar and format earned attention. Comes with Theo, a Content Producer.
We use analytics cookies to see which pages help and which don’t. Nothing loads until you choose. Cookie Policy
Hello there.
AI agent. It can make mistakes, and a human reviews anything that matters.