Platform · Architecture

Governed intelligence, in your perimeter.

Limen is engineered for the place most AI never reaches: a regulated, security-reviewed, latency-sensitive operation where a wrong action has a cost. The architecture makes the intelligence governable, and keeps it inside your boundary.


01 / 03, How it works
01

Discover the workflow

T1 Recon instruments the real work, read-only, and returns a ranked, costed map of automation candidates. Nothing is built before it is measured.

02

Map the schema

We build the semantic bridge to your systems of record, PSS, MRO, cargo, DMS, through APIs, middleware, or host-command emulation where no API exists.

03

Stand up the models

Domain-adapted models are deployed inside your VPC or air-gapped, behind the identity gateway and PII masking, on hardware you control.

04

Wrap it in determinism

Each workflow becomes a state machine with evaluation gates. The controller confirms consequential writes with a human and halts rather than guesses.

05

Improve continuously

Telemetry feeds monthly in-perimeter fine-tuning on operator corrections; the discovery engine proposes the next workflow. The platform compounds.


02 / 03, The write-back problem

Reading is easy.
Acting is the product.

Most enterprise AI stops at advice because writing back to a system of record is hard, regulated, and unforgiving. Limen's semantic bridge issues validated, structured commands, never free-form guesses, behind a two-phase confirmation and an immutable audit trail. Where a system has no API, we fall back through middleware, terminal emulation, and computer-use, with the same safety envelope.


03 / 03, T1 Recon, the audit

Automatic workflow discovery, before you automate anything.

Consulting teams sit in workshops for months guessing where the bottlenecks are. T1 Recon uses software to diagnose them: a read-only audit that observes how work actually flows across your stack and returns a ranked, costed map of the highest-return automations. The fee credits in full against the pilot that follows.

Five signals, one work graph

Desktop observation, system and audit logs, the entitlement graph, the document corpus and network signal, fused into a single picture of how work is really permitted to flow.

A board-ready ROI map

Each candidate scored on frequency × duration × labour rate × error rate × downstream cost, against your numbers, not vendor slideware.

Platform FAQ

What does 'one governed agent over the stack' actually mean?+

It means a single workspace where one agent reads across every system an operator would otherwise toggle between, and writes back to them under a deterministic control plane. Your systems of record keep running unchanged as headless backends; the agent becomes the governed layer in front of them. The operator reviews and confirms; the agent does the transcription, lookup and execution.

What is the semantic bridge and two-phase confirmation?+

The semantic bridge translates intent into validated, structured commands against your systems, never free-form guesses pasted into a field. Two-phase confirmation means any consequential write is drafted, shown to the operator with its exact effect, and executed only on explicit approval. Together they make the agent act like a disciplined colleague, not an autocomplete with database access.

How does Limen prevent hallucinations and unsafe actions?+

Every workflow is modelled as a state machine with evaluation gates, rather than left to an unconstrained agent. The semantic bridge issues validated structured commands, consequential writes require two-phase human confirmation, and the controller halts and hands back to a person rather than improvising. When it is uncertain, it stops, by design, not by luck. See security.

How is this different from RPA?+

RPA follows brittle, pre-recorded scripts and shatters the moment a screen or field changes. Limen reads meaning across systems and composes the right validated action in context, so it adapts to the case instead of breaking on it. It is the difference between a macro that replays keystrokes and an agent that understands the workflow it is executing.

Isn't this just an LLM wrapper?+

No. A thin wrapper is a chat box in front of a public API, no state, no control, no memory of your operation, and your data on someone else's servers. Limen is a deterministic control plane, a semantic bridge to your systems, domain-adapted models that live inside your perimeter, and a workflow graph fitted to how your operation actually runs. The model is the smallest part of the product. See why the copilot fails.

Which systems does Limen integrate with?+

The systems of record an operation cannot replace: passenger service systems, MRO and maintenance records such as AMOS, cargo platforms, document and practice management systems, core banking and policy-admin platforms, claims engines, and electronic health records. We connect through APIs and middleware where they exist, and fall back to host-command emulation or computer-use where they do not, under the same safety envelope.

What is T1 Recon?+

T1 Recon is a read-only, automated workflow-discovery audit. It fuses five signals, desktop observation, system and audit logs, the entitlement graph, the document corpus and network signal, into one picture of how work is really permitted to flow, then returns a ranked, costed Top-N automation map scored against your own numbers. The fee credits in full against the pilot that follows. See the process.

Does Limen replace our existing software?+

No. Your PSS, MRO, cargo systems, core banking, EHR and DMS become headless backends that keep doing exactly what they do; Limen puts one governed workspace in front of them. The goal is to end the swivel-chair between systems, not to run another multi-year migration you did not ask for.

Walk the architecture with our engineers.

Security & sovereignty