Operating authority for agent-run companies

Let agents act.
Keep the company in control.

Lagstyr is built to give AI agents room to do consequential work without giving them the keys to the company. Routine, reversible action can run inside certified limits. Material action stops at the policy boundary. Either way, one independent record keeps the mandate, evidence, decision, effect, obligation, and outcome together across the systems you already use.

The proposition

The risk is not that agents cannot work. It is that they can act before the company can answer for it.

Credentials let an agent call an API. Observability records what the model did. Approval software records a click. None of those, alone, proves the agent was entitled to bind the company, that the evidence was fit for the decision, or that the owning system confirmed the result.

Lagstyr makes the operating rule executable: autonomy within certified boundaries; approval at policy boundaries; review by exception. The company can answer, from one connected record: Who allowed this? On what evidence? What changed? What remains owed? Did it work?

Lagstyr is being designed first for owner-led and tightly managed companies moving agents beyond drafting and into work with real consequences—where founders, COOs, CFOs, and company secretaries need the complete chain, not another summary.

Where Lagstyr sits

Your business systems record transactions. Your agent stack records traces. Who records the authority?

Lagstyr sits between agent intent and company consequence. It records what was permitted, on whose mandate, against which evidence, with whose approval, and what obligation followed—then verifies the change in the specialist system that owns it. Accounting, payroll, CRM, documents, code, and payments stay in their rightful systems. Lagstyr holds the authority and management record that normally falls between them.

One authoritative management record

From mandate to outcome, without losing the thread.

Lagstyr sits above the specialist systems that hold company facts. It records the authority and operating context that lets people and agents perform consequential work across them.

  1. 01

    Mandate

    Who or what may act, for which company, in what scope, within which value and time limits.

  2. 02

    Evidence

    The facts, source documents, and their provenance—including uncertainty and conflicts—assembled for the work.

  3. 03

    Decision

    The recommendation, the accountable person's judgement, the approval or refusal, and the reason—kept together.

  4. 04

    Effect

    The authorised change reaches the system that owns it exactly once, and that system is read back afterwards to confirm what really happened.

  5. 05

    Obligation

    Commitments created by the decision remain visible, owned, dated, and linked to the original case.

  6. 06

    Outcome

    Results are measured against the decision, so autonomy can widen, narrow, or stop on evidence.

Lab evidence · supplier renewal

From source document to governed work.

The built components are exercised end to end against our own synthetic documents. They show how facts extracted from a contract become official company records only when a person approves them—software can propose, but it can never quietly make its own output official.

01Ingest

Source documents enter unchanged, with their identity, classification, and origin recorded.

02Read

Embedded text and supported scanned pages are read inside the installation, and every page records how it was read.

03Extract

Renewal dates, notice periods, clauses, and obligations keep a pointer to the exact source passage.

04Govern

An accountable person accepts or rejects the exact proposal they were shown—it cannot change between review and decision.

05Operate

Accepted facts and owned obligations become visible in the contract's journey.

06Measure

The outcome view reports what is evidenced, and leaves unevidenced value visibly absent.

Lab evidence

Evidence to governed obligation

The full journey—reading documents, extracting terms, human approval, recording facts and obligations, and tracking the work—runs end to end on controlled test data.

Next proof

Live action and measured outcome

The next proof is a connector round trip against a customer's systems, followed by an outcome measured from that installation.

Product capability in private development

Built around the company’s authority, not the agent’s convenience.

Eleven connected capabilities make authority executable from identity and evidence through action and measured outcome. The development record holds the dated proof and availability boundaries.

identity

Identity and access

Stable identity for people, companies, agents, suppliers, and contracts; sign-in through your own identity provider; access roles, joiner–mover–leaver cases, and access reviews that close roles and sessions in one step.

authority

Authority and action control

Who may act, for which legal entity, within what limits; routing by autonomy tier; separation of duties; containment; emergency human override; restore—enforced in the database, not only in application code.

management record

Evidence and management record

Governed records with page-level provenance; extraction into six register families that becomes record only on approval; obligations, decisions, reports; tamper-evident history; an exportable evidence pack for any decision.

operator workflow

Operator and approver work

Queues that route work needing judgement to the right person, decision cards that bring the evidence, proposal, limits, and conflicts into one view, an authority workbench, and bounded chat with a governed agent.

agent execution

Agent work loop and governed change

Fourteen reusable agent blueprints, inert until granted authority and evaluated; one model seam; registers of every AI system in use, impact assessments, exceptions, and proposal-and-approval for material changes. Your own workflows compose exact, already-granted skill revisions and stay inert until they pass the test cases you recorded for them. No agent improves itself silently.

processing

Sovereign processing and retrieval

Core records, documents, full-text search, and the console work without a hosted model or embedding key. Pinned local embedding and optional local-agent paths are built; hosted routes stay off until explicitly selected and approved by workload, purpose, and data class.

communications

Communications and channels

Email as governed evidence in and out, notifications with quiet hours and escalation, alerts, native document signing, and rendered reports. None of them can carry an approval or grant authority.

integrations

Integrations and verified effects

Governed connections to the systems that own the facts—accounting, payments, email, calendar, source repositories, tabular imports, monitoring, and signed outbound delivery. Effects are precisely defined, safe to retry, with receipts and read-back; an unknown outcome never becomes a receipt. Your own connectors are signed and published into your installation by approval. One file in the release lists every connection there is, and none is commissioned against a real provider account yet.

enterprise access

Enterprise identity and authorisation

SCIM provisioning, an optional SAML broker, workload identity from Entra, Okta, and SPIFFE, and an AuthZEN connection to your policy engine—which can never grant what the local rules refuse. No real tenant connected yet.

languages

Multilingual operating surface

The operator console supports English, German, Spanish, French, Italian, Dutch, and Portuguese. Its embedded handbook ships in all seven editions—the nine engineering chapters, and now the operator’s chapter on what an installation connects to—with explicit English fallbacks where the remaining business chapters are not yet translated.

outcomes

Measurement and learning

Costs, benefits, feedback, and outcome reporting with explicit denominators, so wider autonomy is an evidence-based decision—switched on only when an installation records real evidence.

Earned autonomy

People control the moments that matter. Machines run the rest, inside certified limits.

Work is routed by autonomy tier before anyone talks about approval. Oversight is proportional to consequence: routine, reversible work in a certified action class runs directly and is sampled for review afterwards; material commitments stop for the exact approval; changes to authority itself always go to an independent, accountable person with the evidence already in view. A class earns wider autonomy only through its own evidence and limits, and pauses automatically when a containment trigger fires.

T0 · read

Read permitted sources. Search, classify, and assemble evidence without changing the source.

T1 · draft

A reference tier, not a separate route: a reversible draft runs as T3, and a consequential commit stays T2, with a person deciding it.

T2 · act after approval

Stop before the effect. A person approves the exact proposal; the kernel applies it and reads the owning system back to confirm what changed.

T3 · act within a certified boundary

Bounded, observable, reversible or compensatable action executes directly; deterministic sampling and forced review floors follow. A tripped containment trigger pauses the whole class. Sensitive or irreversible effects stay T2.

Agents cannot grant themselves tools, widen their limits, choose their own tier, or rewrite the authority model. Human authority remains irreducible.

Sovereignty by construction

Your authority. Your compute. Your choice of processor.

The party that acts must not keep the only record of its authority. The agent, the model provider, and Lagstyr’s own vendor cannot alter that record. One customer controls each deployment, hosted processors are explicit opt-ins, and no vendor connection sits on the runtime authority path.

Strictness first

Authority is enforced in the database

Approval routes, roles, grants, and policy versions are locked while a decision is made; overlapping routes cannot be stored; backdating is refused by the database itself; a copied database credential cannot write; history is append-only and chained daily.

Your compute

One customer. One isolated deployment.

Bring-your-own-compute means the whole system can run on hardware you control, a rented host, or private or public cloud—directly or through an approved operator. It is never a shared customer data plane.

Your processing boundary

Hosted AI is an explicit route, not a dependency

Records, documents, full-text search, and the console work with no hosted model credential. Managed local paths are built; any hosted model or embedding route must be selected and approved for the exact workload, purpose, and data class.

Where things stand

Evidence before claims.

Lagstyr remains in private development. There is no supported release or customer installation yet; the next gate is a controlled design-partner pilot. The development page keeps the dated evidence, availability boundaries, and remaining proof.

Read the path to availability

Operating resources · no email required

See how Lagstyr is governed, installed, and run.

The public handbook now covers business users, administrators, engineering, and DevSecOps. For the wider operating model, the vendor-neutral AI-native guide covers architecture, phased delivery, proportionate governance, and honest benefits discipline.

Read the Lagstyr handbook Download the AI-native guide Free · ungated · public documentation in English