IT Control Plane
Identity, permissions, models and deployment
One admin view holds every agent and app your teams have built: what each may reach, who may put it live, which model it runs and what it did.
Everything built on Riff shows up there, including what a team built for itself last week, which is what lets IT say yes.
Access control, for people and agents
People sign in as themselves. An agent carries a scope of its own, granted action by action.
Single sign-on with your directory
People arrive through your identity provider, with owner, admin and collaborator roles. Joiners and leavers are handled where you already handle them.
Named actions, granted one by one
An agent holds a list of the actions it may call, such as updating a purchase order line or reading one mailbox folder. What is outside the list stays outside its reach.
Reach set per agent
Which integrations an agent may go through, and which records inside them. A scope you can read on one screen and change in one place.
People keep their own permissions
An agent working for someone answers within what that person is allowed to see. Asking an agent gives a wider view of the business to nobody.
Data access
Connected once for the account, switched off in one place, and left where it lives.
Integrations belong to the account
The ERP, the mailboxes, the warehouse and the services around them are set up once and shared across projects. Each has its own switch, so turning one off takes it away from every agent and app at once.
The system of record stays the source
Context points at the record where it lives rather than copying it into a warehouse of its own, so a date changed in the ERP is current the same minute.
Models and inference on your terms
A default model for the account, overridden per automation where a task needs a different one, and inference location set per data class, in the EU by default.
Retention and governance stay yours
Your data governance and retention policies carry over. What is kept, for how long and where, is your decision.
Acting in your systems
Agents act through deterministic tools that call your systems' own business functions.
Tools with typed inputs
Every action an agent can take in a system is a named tool with a defined signature, built and tested by your team or ours, and versioned like the rest of your software.
Your ERP's own rules apply
The tool calls the business function the ERP exposes, so its validation, its numbering and its audit trail hold exactly as they do when a person does the same thing.
Strict limits per action
Value thresholds, approval steps and what an agent may do on its own are set per tool and per agent. Above the line it proposes and a person decides.
Deterministic and repeatable
Given the same case, the tool does the same thing. The judgment is in choosing the action; carrying it out is code, and it is tested against your history before it goes live.
Observability
What ran, what it touched, what needs a person, and what it cost.
- Window
When an agent is allowed to run
Always available, or inside a window you set, say every ten minutes between six in the morning and eleven at night, Monday to Friday.
- Each run
Runs, success rate, items touched
Every trigger reports how often it ran, how much of it succeeded, what it worked on and what is waiting for attention.
- Each case
A trail per case
What the agent proposed, what it did in the system, what a person took over and when each state changed. Readable by the team that owns the process, and by audit.
- Cost
Spend you can see
Model usage per user, project, agent and model, with budgets, caps and alerts. For proven agents, per-agent pricing puts the model cost risk with Riff.
- Runs
- 100
- Succeeded
- 100%
- Items touched
- 47
- Needs a person
- 3
Every case keeps its own trail: proposed, done, taken over, and when.
Governance
Building is open to the teams who know the work. Putting something live is a decision.
- In development
Teams build in their own project
Anyone with access can build against the context and the tools that already exist, and IT sees it from the first version.
- Requested
Deployment is a permission
Either anyone with access can deploy, or deployment is restricted and needs explicit permission. Requests queue in the admin view with what the agent reaches and what it may do, and only owners and admins can change the setting.
- Deployed
The same rules for the AI you already use
Through MCP, Copilot, Claude and the agents your teams build reach the same context and the same tested tools, on the permissions of whoever is asking. One place to govern AI rather than one per tool.
Security and compliance
The paperwork your review asks for, published and kept current.
SOC 2 Type II and ISO 27001
Both in place, with the reports and the security package available to customers under NDA.
ISO 42001, GDPR and the EU AI Act
AI management, data protection and the AI Act covered, with the DPA behind them and our posture on each published live in the trust center.
Penetration testing
Run by an independent party, periodically and on demand, with the summary available to customers.
Cloud or on-prem, EU by default
Riff runs on top of the systems you already have, including legacy on-prem ERP. Staging and production, agent health monitored, updates rolled out without disrupting live operations.
One place to answer for AI
The register, the permissions, the trails and the spend sit in the same admin view, so a question from audit or a regulator is answered from the product rather than assembled by hand.
What Riff is not
- Not an ERP replacementRiff sits on top of your systems of record.
- Not a general-purpose assistantAgents have specific operational roles.
- Not a workflow toolAgents have judgment and context, not just trigger-action rules.
- Not an analytics platformThe context layer serves operations, and your BI tools plug into it.
We leave capability, not dependency
Our forward-deployed team works as part of your organisation from day one, deploys the first agents, and stays as the backstop until your own capability exists. Your builders learn on real use cases with our team alongside, the platform carries the standards, and your domain experts end up owning, extending and building agents around your own strategic goals.