Skip to content
By department

Built for how each team works.

Five teams, five illustrations. Any workflow that touches business data - human or agentic - runs through the same boundary.

Choose a department

What sales gets with Boundary on.

  • Real answers from live systems

    Pipeline, risk and forecasts from the CRM, in whatever AI your team already uses.

  • Workflows your risk team can approve

    Follow-ups, renewals and onboarding, worked end to end by the agents you chose.

  • Nothing private in the model

    Identities tokenised or withheld before anything leaves your systems.

app.boundarycontrol.com/deals

Deal · Brightwave Rollout

amount£45,000allowed
contact[Contact #7]tokenised
emailwithheldwithheld
draftHi [Contact #7], following up on the proposal we discussed...by token

No name reached the model. No email. The figures passed through.

Any assistant · any connected system · one policyRecorded to the audit ledger

What support gets with Boundary on.

  • A queue your assistant can rank

    SLA risk surfaced across live tickets, in whatever assistant your team already uses.

  • Recommendations, never interventions

    Your agents rank and suggest, read-only; escalations hold for a human approval.

  • No customer in the model

    Names and messages tokenised or withheld before anything leaves your systems.

app.boundarycontrol.com/queue

Open queue · ranked by your assistant

ticket 341[Customer #4] · SLA 2hat risk
ticket 337[Customer #9] · SLA 6hnext
ticket 329[Customer #2] · SLA 2don track
actionescalation raised, awaiting approvalheld

Read-only: triage recommended, nothing changed.

Any assistant · any connected system · one policyRecorded to the audit ledger

What operations gets with Boundary on.

  • Processes safe to run end to end

    A won deal becomes the ticket, the tasks and the welcome draft, without exposing the customer.

  • Three systems, one instruction

    Your agents work across your CRM, tickets and mail as a single governed run.

  • Identity never leaves home

    The customer stays a token throughout; real values are restored on write, inside your systems.

app.boundarycontrol.com/runs/onboarding

Onboarding run · [Company #3]

crmdeal hits Closed won, run startsallowed
ticketscommissioning ticket · [Company #3]by token
mailwelcome draft, holds for approvalheld
write-backreal values restored inside your systemson write

One agent, three systems; the customer stays a token the entire way.

Any assistant · any connected system · one policyRecorded to the audit ledger

What finance gets with Boundary on.

  • Analysis on real figures

    Deal values, stages and close dates ground every summary your AI produces.

  • Reviews safe to hand to an agent

    The pipeline review drafted end to end by your agent, held for your approval.

  • The names never pass

    Identity fields are tokenised before anything leaves; structure preserved, exposure removed.

app.boundarycontrol.com/reviews/pipeline

Pipeline review · governed

Q3 pipeline£486,000 · 14 dealsallowed
largest deal£45,000 · [Company #3]tokenised
weighted close68%allowed
sendreview drafted, holds for approvalheld

Real figures, tokenised identities. No name reached the model.

Any assistant · any connected system · one policyRecorded to the audit ledger

What IT gets with Boundary on.

  • One policy over everything

    Every assistant and every connected system, governed by rules you set once.

  • Approvals that fail closed

    Escalations wait for single-use human sign-off; refusals are logged, not lost.

  • Control you can prove

    Revoke access in one click, and read every decision back from the audit ledger.

app.boundarycontrol.com/ledger

Audit ledger · live

sendcross-customer email blockedrefused
escalationsingle-use manager approvalawaiting
accessaccount revoked; tokens stopped resolvingapplied
recordevery decision hash-chainedledger

Refusals are logged, not lost. The ledger holds every decision.

Any assistant · any connected system · one policyRecorded to the audit ledger
See them run

Example workflows, end to end.

Every block above maps to a workflow you can watch end to end: what happened, what the model saw, and where else the same boundary applies.

Choose a workflow
+ more across your stackbrowse integrations
Operations · apps in this runHubSpotJiraOutlook
  • A deal hits Closed won in HubSpot and the onboarding run kicks off.
  • Boundary tokenises the customer before context leaves: the agent plans against [Company #3] and [Contact #7].
  • A commissioning ticket lands in Jira with the real customer attached, resolved on write inside your systems.
  • The welcome email drafts in Outlook and holds for a human to approve.
  • The audit ledger records every field, policy and outcome across all three apps.
Your agent runs the whole onboarding across three systems; the customer stays a token the entire way.
Sales · apps in this runHubSpotOutlookMicrosoft 365
  • The agent reads the renewal from live deal data: value, stage and days to expiry pass through.
  • It drafts the check-in email to a contact it knows only as [Contact #12].
  • A follow-up task and a calendar hold are created in Microsoft 365, referencing the customer by token.
  • Every write resolves to real values inside your systems; the draft holds for approval.
Email draft, follow-up task and calendar hold from one instruction, all by token, all resolved on write.
Customer Support · apps in this runJiraOutlook
  • The agent ranks the open queue by priority and age, read-only, seeing customers only as tokens.
  • It flags the ticket at real risk of breaching SLA and raises the escalation.
  • Then it stops: a single-use, fail-closed manager approval is required before anything touches the customer.
  • On approval, the apology-and-plan email drafts in Outlook with real values restored on write.
  • The refusal path is real too: nudged into mixing two customers, the send is refused and logged.
The agent triages, escalates and stops; a single-use, fail-closed approval stands between it and the customer.
Finance · apps in this runHubSpotOutlook
  • The agent reasons over every live deal: amounts, stages and close dates pass through.
  • Every company in the pipeline stays a [Company #N] token while risk is ranked.
  • The review summary drafts in Outlook for the leadership list, held for approval.
  • Structure preserved, exposure removed: the ledger shows exactly which fields the model received.
The numbers pass, the names tokenise: a full risk-ranked review and a distribution draft without identity exposure.
What happened
  1. 01 - trigger

    Brightwave Rollout moves to Closed won. The onboarding agent picks up the deal and requests its context.

  2. 02 - classified

    Boundary classifies every field inline: stage and amount pass, company and contact become tokens, email is withheld.

  3. 03 - ticket

    The agent raises the Jira commissioning ticket by token; Boundary resolves the real customer on write, inside your estate.

  4. 04 - draft

    The welcome email drafts in Outlook with real values restored server-side, and holds for your approval before anything sends.

  5. 05 - recorded

    The ledger holds the complete run: three systems, every decision, and an agent that never learned who the customer is.

What the model saw

> onboard [Company #3]: commissioning ticket, then a welcome email to [Contact #7]

company[Company #3]Tokenised
contact[Contact #7]Tokenised
deal_amount£45,000Allowed
emailwithheldWithheld

A complete business process across three systems. The model planned it all and never saw a name.

Where else this applies
SalesforceMicrosoft 365 MailXero

Any won-deal trigger can start the same governed run wherever your CRM and ticketing live.

Browse all integrations
What happened
  1. 01 - request

    A rep asks the assistant to work the renewal that expires this quarter. The agent requests the deal context.

  2. 02 - classified

    Renewal value, stage and dates pass; the customer and contact tokenise; direct contact details are withheld.

  3. 03 - drafted

    The check-in email drafts to [Contact #12]; Boundary rehydrates the real address server-side inside the call. Draft only.

  4. 04 - scheduled

    A follow-up task and a calendar hold are created by token and resolved on write. The rep reviews and sends.

What the model saw

> work the at-risk renewal expiring this quarter: email, task, calendar hold

contact[Contact #12]Tokenised
renewal_value£28,000Allowed
days_to_expiry41Allowed
emailwithheldWithheld

Three actions across two systems from one instruction. The model worked entirely on tokens.

Where else this applies
SalesforceMicrosoft 365 Mail

The same renewal motion runs wherever your pipeline and mail live.

Browse all integrations
What happened
  1. 01 - triage

    The agent reads the open Jira queue and ranks it by priority and age. Correct triage, zero customer names seen.

  2. 02 - flagged

    One ticket is hours from an SLA breach. The agent raises the escalation against [Customer #4] and stops.

  3. 03 - approval

    A manager receives a single-use approval request. Fail-closed: no response means nothing proceeds.

  4. 04 - resolved

    On approval the customer email drafts with real values resolved on write. Every step, including the stop, is in the ledger.

What the model saw

> triage the open queue and escalate anything at breach risk

ticketSUP-341Allowed
customer[Customer #4]Tokenised
sla_remaining2h 10mAllowed
contact_emailwithheldWithheld

The queue was triaged and the escalation raised without a single customer identity reaching the model.

Where else this applies
HubSpotMicrosoft 365 Mail

The same human-in-the-loop gate applies to any workflow that ends at a customer.

Browse all integrations
What happened
  1. 01 - request

    Finance asks for the quarterly pipeline review. The agent requests deal context across the live pipeline.

  2. 02 - classified

    Analytical fields pass: values, stages, dates. Every customer identity tokenises. Contact details are withheld.

  3. 03 - ranked

    The agent ranks risk on real figures, largest exposure first, each company known only as a token.

  4. 04 - drafted

    The summary drafts in Outlook for review and approval; tokens resolve inside your systems, not in the model.

What the model saw

> rank the pipeline by risk and draft the quarterly summary

pipeline_total£486,000Allowed
largest_deal£45,000Allowed
company[Company #3]Tokenised
owner_emailwithheldWithheld

A board-ready review built on real figures. Identities never left the boundary.

Where else this applies
SalesforceXero

The same tier behaviour governs any reporting run over commercial data.

Browse all integrations
Get started

Arrange a proof of value.

Start a free proof of value: we provision the tenant, you bring one or two apps and a handful of users, and watch Boundary control them workflow by workflow.

Arrange a proof of value