Governed automation for consequential work

Build autonomy. Keep control.

Describe a process in plain language. Boundlane designs it against your systems, proves it safely in shadow mode, and runs it with approvals, auditability and hard limits.

boundlane / studio
When an AP invoice arrives, compare its total to the purchase order total and hold anything more than two percent over for a human to approve.
Built it against a tolerance you can edit without a rebuild, with the hold gated on AP manager approval. It never touches bank details — that tool does not exist in its toolset.
gate passed · evals 3/3
Automation package
Trigger
invoice_matched
Tools
5
Config
ap-tolerance
Approval
ap_manager
Forbidden
change_bank_details
Stage
shadow
shadow run · AP invoice
no payment side effect
RUNcompare_invoice_to_po· 4% over
SIMplace_hold· shadow
BLOCKchange_bank_details· forbidden
ENDreport_escalate
Starts with zero live writesDesigned against your connected systemsEvery action produces reviewable evidence
How it works

Automation breaks down when process knowledge, engineering and governance are separated.

The knowledge lives with the people who run the process, the implementation lives in an engineering backlog, and the controls arrive last. Boundlane keeps all three in one versioned system.

Process knowledge

Lives in documents and in the heads of the people who run the process.

Captured as versioned requirements, rules and exceptions the automation is built from.

Engineering capacity

Every change queues behind an integration backlog.

The implementation is generated against the systems you connected, and proved before it ships.

Governance

Prompts and access tokens get treated as controls.

Policy is enforced outside the model, and every effect is recorded.

01
Understand

Reads your process documents and the structure of the systems you connect. Records the rules it learns, and asks when a fact it needs is missing rather than assuming one.

02
Build and prove

Writes the workflow, the tools and the guardrails, then tests them against scenarios and against cases that already happened. It cannot go live until that passes.

03
Run and improve

Executes under policy, routes approvals and exceptions to the right people, and turns what the runs reveal into the next version.

Two surfaces over one versioned package. Boundlane Studio builds it and proves it; Boundlane Control runs it under policy. The package that passes the gate is the package that executes — pinned by hash, and refused at runtime if the bytes changed.

The product

See what every automation can do — and why.

Each automation brings its workflow, rules, approvals, rollout stage and run evidence together in one reviewable place.

app.boundlane.com
The connectors page showing a connected ERP with its discovered objects and fields, above a catalogue of available connectors and what each level of verification means.
Step 1 of 6

Connect a system and it gets read, not configured.

Connecting reads the real objects, fields and picklist values into a context graph — three objects and seventeen fields here. That graph is what the agent designs against, which is why it cannot invent a field you do not have.

Taken from the running product, not a mockup.

See the full invoice-matching example
Governance

Governance enforced outside the model.

The model can propose an action. Only Boundlane’s policy layer can authorise what reaches your systems, and it decides the same way whatever the prompt says.

  • Forbidden actions never execute, in any rollout stage
  • Per-tenant secrets, envelope-encrypted; the master key can live in a cloud KMS
  • Row-level isolation across every tenant query
  • Hash-chained audit trail; the chain head can be anchored outside the platform
what the dispatcher does with a forbidden call
1The model proposes changing a supplier's bank details.
2Policy is consulted before the toolbox, not after.
3Refused, recorded, and escalated to a person.

This holds in every rollout stage, including GA, and no approval can override it. An action on the forbidden list is not gated — it is absent.

and every automation can answer
  • What did it do?
  • Why was the action allowed or refused?
  • Who approved it?
  • Can the effect be reversed?
Domains

Built for high-consequence work across the enterprise.

Each domain carries its own vocabulary, its own approval roles, and its own list of actions an automation may never take. The guardrails change with the function; the way they are enforced does not.

Finance operations

Invoice matching, reconciliation, close tasks, supplier and payment workflows.

Never releases a payment

IT operations

Access requests, incident triage, provisioning, change management and service desk flows.

Never disables multi-factor authentication

HR operations

Onboarding, offboarding, case management and the records that follow a person through them.

Never changes bank details

Revenue operations

Lead routing, quote approval, renewals, territory and pipeline hygiene.

Never grants admin access

Customer support

Ticket triage, entitlement checks, escalation paths and refund review.

Never deletes an audit record

Custom domain packs

Define your own vocabulary, business roles and hard limits. Everything else on this page works the same way.

Never exports records in bulk

Reference architecture

Horizontal reach and vertical depth, without the trade between them.

QuantumBlack, AI by McKinsey, publishes an enterprise agentic-platform architecture that frames the two as opposites: horizontal assistants scale easily but sit loosely on the process, while workflow-embedded systems are transformative and narrow. Boundlane is horizontal in distribution — anyone across the functions above describes a process in plain language — and vertical in output, because each automation is built against that system’s real schema and runs under that function’s own approval roles and forbidden actions. Read against their diagram, it matches three of the four agentic-system archetypes and is also the shared-services layer beneath them. The fourth archetype, frameworks for developers building custom agents, is not ours — and is named there as one of the boxes we decline.

Where Boundlane sits, box by box

An independent reading of a published architecture. Not an endorsement, partnership or affiliation.

Turn one process into a governed automation.

Start in shadow. Learn from real cases. Promote only when the evidence supports it.