the governed layer between AI and the systems that run your businessone decision, every callerruns on your own hardware
01 The enterprise AI foundation

The AI decides what it wants to do.
Xema decides what it may do.

Xema sits between your AI and the systems that run your business. It turns your APIs, tools, data and workflows into governed business capabilities — named operations with an owner, a permission, an approval path and a record.

People, agents, apps and workflows all reach your systems the same way, through the same decision. The question your organisation answers is “who may execute booking.change on this booking” — not which model called which endpoint.

See what gets done
✓ People, agents, apps — one decision path✓ Approvals that suspend & resume✓ Change the AI, keep the governance✓ Cloud, on-prem, or no network at all
agents · at workyour work · done · in your control
Xema between everything that acts and the systems it reachesFour bands. At the top, everything that can act: people, agents, apps and workflows, and other platforms. Below them a single capability boundary carrying permissions, approvals and an audit trail. Below that the Xema foundation — objects, capabilities and policies, one model of the business. At the bottom the systems it reaches: your APIs, MCP servers, automations and SaaS systems, each replaceable without changing the bands above.WHO ACTS — people, agents, apps, other platformspeopleask, and approveagentsact for a personapps & workflowscall capabilitiesother platformsreach in from outsideONE CAPABILITY BOUNDARYpermissionsapprovalsaudit trailTHE XEMA FOUNDATIONone model of your businessobjects · capabilities · policiesYOUR SYSTEMSyour APIsMCP serversautomationsSaaS systemschange any of these without changing anything above
02The problem

Every AI project rebuilds the plumbing.
And invents its own idea of who may do what.

An assistant here, an agent there, an automation in a third tool. Each one wires up the same systems, holds its own credentials, and expresses permission as an instruction it was given. So the security review starts over every time, the work never accumulates, and nobody can answer “what is this allowed to do?” from one place.

i The integration work repeats

Every new AI project reconnects the same systems with its own credentials and its own idea of what an operation is. The tenth one costs what the first one cost.

ii The rule lives in a prompt

“Only refund when the customer has been verified” is an instruction, not a control. Anything that can influence the prompt can influence the rule — and nothing records that it did.

iii The model is the vendor’s

Define your permissions inside one AI platform and you have modelled your organisation around that vendor’s product. Replacing it means designing all of it again.

03What Xema does

Define a capability once.
Everything reaches it the same way.

A capability is the operation your business actually cares about — refund an invoice, change a booking, redline a contract — with its inputs, its risk, who may run it and who has to approve. It is the contract your organisation governs. The API, the workflow or the MCP server behind it is an implementation you can swap.

01 Declare the capability

Name the operation, its schema, its risk, and what happens when it goes wrong. This is the thing your permissions and approvals attach to.

02 Bind it to an implementation

An internal API, an MCP server, a Xema workflow, an n8n automation, a partner's agent. Change the binding later; the capability the business governs does not move.

03 Let anything call it

A person, an agent, an app, a schedule, an external platform. Same decision, same credentials boundary, same record — whichever one it is.

Where Xema sitsone boundary · every participant
platform · overview
Where Xema sits between AI and your systemsFour bands, top to bottom. First, everything that can act: people, agents, apps, workflows and other platforms. Second, the capability boundary — every call answers seven questions (who, what, which, may, using, under what, recorded) and is allowed, held for a human answer, or refused, and audited either way. Third, your capabilities: named business operations such as booking.change, invoice.refund and contract.redline. Fourth, the implementations each capability is bound to — your APIs, MCP servers, Xema workflows, automations and SaaS systems — which can be replaced without changing anything in the three bands above.WHO ACTSpeopleagentsappsworkflowsother platformsTHE CAPABILITY BOUNDARYwho · what · which · may · using · under what · recordedallow · ask · deny — and recorded either wayone decision · every callerYOUR CAPABILITIESbooking.changeinvoice.refundcontract.redlinethe contract your organisation governs — it outlives what implements itBOUND TO ANY IMPLEMENTATIONyour APIsMCP serversXema workflowsautomationsSaaS systems

People, agents, apps and workflows sit above. Your APIs, MCP servers, SaaS tools and automations sit below. Nothing crosses from one to the other except through a named capability, and every crossing is decided, credentialed and recorded at the same point.

Work in motionreliable · reviewable · in your control
live · at work
Work running inside your own environmentA dashed perimeter labelled "your environment" holds a live view of four jobs running side by side: a code review that is approved, a contract draft ready for review, an incident-response run that is on track, and a live support-desk agent. Below the perimeter, an audit-trail ticker records every action, described as reviewable, exportable and fully traceable.⌖ YOUR ENVIRONMENTyour environment · your data · your controlXEMA · LIVEhealthy · runningCODE REVIEWreview-changesapproved ✓DOCUMENT WORKdraft-contractready for reviewOPERATIONSincident-responserunning · on trackCUSTOMER AGENTsupport-desklive · in your controlall running with your knowledge + governanceCOMPLETE AUDIT TRAIL — every action recordedreviewable · exportable · fully traceable

Reviews, document work, operations, and long-running sessions run side by side — on a schedule, on an incoming event, or on demand — each in your organisation's own execution namespace.

04What gets built on it

Many departments.
One foundation underneath.

A biome is the delivered software for a business domain — customer care, finance, legal, engineering — with its own capabilities, processes, knowledge and screens. Install a second one and you get a second domain, not a second platform: the same identity, permissions, connections, approvals and audit trail carry it.

Support · Customer support

Resolve every case the moment it arrives.

As a request comes in, an agent reads it against your knowledge base, answers the routine ones, and routes the urgent ones to a person — around the clock, without a queue.

always ongrounded in your knowledgeescalates to people
Workflow diagramA workflow of 5 steps: new case (as it arrives); understand (against your knowledge); route (by urgency); alert on-call (urgent only); reply (from your knowledge). It runs new case to understand, understand to route, route to alert on-call, route to reply.new caseas it arrivesunderstandagainst your knowledgerouteby urgencyalert on-callurgent onlyreplyfrom your knowledge
Legal & contracts · Legal & contracts

Redline every contract against your playbook.

An agent extracts each clause, checks it against your playbook, and hands counsel a risk-sorted brief. The agent does the line-by-line; your team approves the deviations.

clause by clausehuman approvalrisk-sorted
Workflow diagramA workflow of 6 steps: new contract (as it arrives); extract clauses (every clause); review each (clause by clause); redline (against your playbook); merge findings (sorted by risk); counsel approval (blocks high risk). It runs new contract to extract clauses, extract clauses to review each, extract clauses to redline, review each to merge findings, redline to merge findings, merge findings to counsel approval.new contractas it arrivesextract clausesevery clausereview eachclause by clauseredlineagainst your playbookmerge findingssorted by riskcounsel approvalblocks high riskHUM
Engineering · Engineering

From idea to a shipped,
reviewed change.

An agent carries a feature through every stage — framing, plan, spec, implementation, review — pausing for a human decision where it matters, and leaving a versioned deliverable at each one.

multi-stagehuman approvalsversioned at every stage
Workflow diagramA workflow of 8 steps: new feature (approved request); frame the idea (your knowledge); shape the plan (decisions · risks); plan approval (tech leads); author the spec (to your standard); do the work (with the team); governance review (security · compliance); ship & close (shipped · versioned). It runs new feature to frame the idea, new feature to shape the plan, frame the idea to plan approval, shape the plan to plan approval, plan approval to author the spec, plan approval to do the work, author the spec to governance review, do the work to ship & close, governance review to ship & close.new featureapproved requestframe the ideayour knowledgeshape the plandecisions · risksplan approvaltech leadsHUMauthor the specto your standarddo the workwith the teamgovernance reviewsecurity · complianceship & closeshipped · versioned
Finance & audit · Finance & audit

Continuous checks, before standup.

Every morning an agent reconciles the books, scans for anomalies, escalates the criticals to the controller, and delivers the digest — every figure traceable to the work that produced it.

on a scheduleanomaly checksevidence packet
Workflow diagramA workflow of 5 steps: every morning (on a schedule); reconcile ledger (reads your books); scan for anomalies (flags outliers); escalate (to the controller); daily digest (chat · email). It runs every morning to reconcile ledger, reconcile ledger to scan for anomalies, scan for anomalies to escalate, scan for anomalies to daily digest.every morningon a schedulereconcile ledgerreads your booksscan for anomaliesflags outliersescalateto the controllerdaily digestchat · email
01 Engineering

Ships reviewed code changes.

Agents review every proposed change against your standards, do the line-by-line work, and hand back a finished assessment — your engineers keep the final approval.

02 Documents & knowledge

Turns your material into finished documents.

Agents draft, review and render documents against your own knowledge base and your own document templates — and every version is kept.

03 Customer support

Resolves cases, not just replies.

Agents work each case against your knowledge and process to a real resolution, and bring in a person the moment it matters.

04 Sales enablement

Turns raw context into ready proposals.

Agents assemble proposals, briefs, and answers from your deals and product knowledge — reviewed before anything leaves the building.

05 Legal & contracts

Reviews and redlines to a decision.

Agents check every clause against your playbook and deliver a risk-sorted brief; your counsel approves the deviations.

06 Finance, audit, close

Runs recurring closes and checks.

Agents reconcile the books, scan for anomalies, escalate the criticals, and assemble the evidence packet — every figure linked to the step that produced it.

07 Operations

Runs the process, every time.

Recurring operational work executed the same way on every run, because the process is a published revision rather than a script somebody edited.

08 Research

Delivers analyzed findings, not links.

Agents gather, read, and synthesize across your sources into a finished write-up you can act on.

09 Across the org

One permission model, every department.

Whatever a team builds, it is the same capabilities, the same reach ceilings and the same approval path — so a second use case does not mean a second platform to govern.

05Why Xema

You will change AI vendors.
You should not have to redesign your organisation.

The model you use today will not be the model you use in two years, and the platform you buy this quarter will not be the last one. What has to survive all of it is your own model of the business — its objects, its capabilities, and the rules about who may do what.

So Xema owns that layer and nothing else claims it. A model provider, an MCP server, an n8n workflow, another vendor's agent — each is an implementation sitting behind a capability you defined. Swap any of them and the permissions, approvals and audit trail are untouched.

That is also why the second use case is cheaper than the first: it reaches capabilities that already exist, under rules that already hold. The work compounds instead of scattering across disconnected tools.

The abstraction is yours

Objects, capabilities, permissions and policies are defined in Xema. Everything else is a replaceable implementation, provider or participant behind them.

Governance outside the model

A prompt cannot reach past the capability boundary. Whatever an agent decides it wants to do, what it may do is decided somewhere it cannot edit — and the refusal is recorded with its reason.

One foundation, many domains

Biomes are the delivered software: agents, capabilities, processes, knowledge and screens for a business domain. They all share one identity, permission, connection and audit foundation, so a second domain is not a second platform.

Integrate, hybrid, or sovereign

Start with everything external. Move as much in-house as you want. End up running your own models on your own hardware. Same architecture at every stage — there is no rewrite between them.

⌖ ONE ABSTRACTION · EVERYTHING ELSE REPLACEABLEyour objects · your capabilities · your rules
One abstraction at the centre, replaceable technology around itA hub labelled "the Xema foundation — your capabilities, and the rules about who may run them" sits at the centre of six spokes: your AI (the models you choose), your knowledge (your documents, data and decisions), your systems (the tools you already use), your governance (approvals, audit, permissions), your environment (your control, your data), and your agents (expertise, judgment, scope). A dashed ring encloses all of them.THE XEMA FOUNDATIONyour capabilitiesand who may run themyour AIthe models you chooseyour knowledgeyour docs, data & decisionsyour systemsthe tools you already useyour governanceapprovals · audit · permissionsyour environmentyour control, your datayour agentsexpertise · judgment · scope

the models, the tools and the platforms change · what they connect to stays yours

You don't rent your AI strategy. You own the objects, the capabilities and the rules — and Xema is what lets the technology underneath change without them.

06Trust & control

Control isn't a setting you bolt on.
It's how the platform works.

The controls sit on the path the work takes, not beside it. Every capability call — from a person, an agent, an app or a workflow — is named, bounded by the authority of the subject behind it, and either allowed, refused, or held for a human answer. The platform decides, not a process document and not a system prompt.

i Approvals suspend the work

When a decision comes back “needs approval”, the call is suspended into durable storage and resumed exactly once after a person answers — not failed, not retried from the top.

ii Owner-bounded by default

An agent acts with the authority of the person it acts for. That is what it gets when it declares nothing, and no setting raises it above them.

iii Silence is a refusal

An agent call that does not state how far it intends to reach is refused. So is one whose ceiling cannot be resolved. Nothing is admitted because a check was unavailable.

iv Refusals carry their reason

Every capability an agent invokes passes one router. What it admits and what it refuses are both recorded, each with the decision code behind it.

v Runs on your own hardware

The same platform installs onto a single on-prem node with local model inference — or from a signed offline bundle where there is no network at all.

vi One standard for “done”

Define the shape of a deliverable once, as a spec, and the work agents hand back is produced and versioned against it.

vii Sensitivity only ever rises

A container declares how sensitive its contents are. Anything inside can raise that and can never lower it — and declaring nothing means inheriting, not defaulting.

viii See what a restriction blocks first

Before a data restriction is switched on, the platform shows you exactly what would start being refused and which setting decided each one. The preview and the live decision are the same code, so what you were shown is what happens.

ix Going back moves a pointer

Every version of every skill, agent, process, result and app is kept exactly as it was. Returning to one points at it again — nothing is copied, re-checked, or destroyed on the way.

x Placement is declared, never guessed

Work runs on the pool of machines your organisation named. If the platform cannot read where your work belongs, the run is refused — it is never quietly relocated.

07How we help you get live

A platform.
And the team that gets it working.

Putting AI to work at the core of your business is part product, part program. Xema is yours to run — and we work alongside teams doing it, scoping the first processes, connecting your systems, and shaping the governance that fits.

Platform

Xema, the product

The foundation your AI work sits on — one capability model, one permission model, one connector edge, one audit trail.

  • · Installs on your own hardware
  • · Connectors for the tools you use
  • · Every capability call decided
  • · Grows by installing biomes
Partnership

Our team, alongside yours

A hands-on team scopes your first processes, models your governance, and ships the first agents before handing them to your org.

  • · Process & standards design
  • · Governance & policy modelling
  • · Co-built packages & connectors
  • · Handover to your own team
In the box

What ships without you building it

A reference engineering solution, a library of connectors, and editions that go from managed cloud to a box with no network.

  • · A full software-delivery solution
  • · Connectors: SCM, trackers, chat, mail
  • · Cloud, on-prem and air-gap editions
  • · Local model inference on-box
Get a demo

Start with one process.
End with a layer everything uses.

We work with a small number of teams each quarter. We take one real process, turn the systems it touches into governed capabilities, and put it live under your own approvals — engineering, support, sales, legal, finance, operations, wherever the work is waiting.

How it goes
01   scope one real process
02   connect the systems it touches
03   ship it, with its approvals
04   the next one reuses all of it
Same platform the whole way.
Already have access?
Xema — the governed layer between AI and your systems