AI on Rails

All the power of AI.
Enterprise-safe by design.

-

AI on Rails

All the power of AI.
Enterprise-safe by design.

-
-
-
Gradient Circle Image
Gradient Circle Image
-
-

Understanding

Agentic Semantic Layer

Where AI learns what your business means.

"Most agent failures are not model failures anymore. They are context failures."

Philipp Schmid, Google DeepMind

This is the context gap.
The documented reason 95% of enterprise AI pilots deliver no measurable business impact (MIT NANDA, State of AI in Business 2025). The model is fine. It has no idea what customer, active, approved, or at-risk mean in your business. Without shared definitions, every agent makes its own guess.

-
-
-
-

The safe space where AI learns your business
The Agentic Semantic Layer holds definitions, not data. Agents shape, refine, and extend it without ever touching the systems underneath. It is also the gateway every agent passes through to reach your data: business definitions on the way in, governed access on the way out.

Close the context gap.

AI stops pattern-matching your data and starts understanding it.

Answer any business question.

Create any data visualisation.

Correctly design any dashboard.

Metadata databases can't hold.

Agent-cultivated, human-approved.

Safe by design.

Article 10, ready.

Gradient Circle Image
Gradient Circle Image
Gradient Circle Image
-
-

Continuity

Agentic Memory

Multi-layered and episodic. The memory that makes AI a colleague, not a chatbot.

"Most GenAI systems do not retain feedback, adapt to context, or improve over time."

MIT NANDA, State of AI in Business 2025

-
-

This is the learning gap,
The second half of why enterprise AI stays stuck in pilot. Even with the right business definitions, an agent without memory forgets every preference, every decision, every lesson it has earned. It cannot get better at working with you, and it cannot get better at working with your company.

Memory that scopes, verifies, and merges

Agentic Memory captures three kinds of knowing:

Agentic Memory captures three kinds of knowing:

Conversational memory.

Seamless Data Integration Process

What people prefer, what was discussed, what was decided.

Skill memory.

Seamless Data Integration Process

Which approaches work, which fail, how to repeat success.

Tool memory.

Seamless Data Integration Process

Which tools, called how, returning what.

All three are stored across four layers,
each with its own governance:

All three are stored across four layers, each with its own governance:

User + agent.

Seamless Data Integration Process

Your personal preferences, facts, and history.

Effortlessly connect with diverse data sources, ensuring smooth data flow for real-time insights and accurate analysis.

Team + agent.

Seamless Data Integration Process

Shared team knowledge, approved before it spreads.

Effortlessly connect with diverse data sources, ensuring smooth data flow for real-time insights and accurate analysis.

Org + agent.

Seamless Data Integration Process

Company-wide patterns, approved by the business.

Effortlessly connect with diverse data sources, ensuring smooth data flow for real-time insights and accurate analysis.

Memories are recollected on demand and proactively injected when context calls for them. Every conversation can become a long-form episodic memory, semantically chunked and queryable across the organisation. Newer memories carry more weight, and overlapping memories auto-merge over time.

Close the learning gap.

Agents stop starting from zero and start working from everything you have taught them.

Agents that remember you.

Teams that compound.

Organisational memory that stays.

Approval at every shared level.

Recency that matters.

Open standards underneath.

Article 10 + GDPR, ready.

Gradient Circle Image
Gradient Circle Image
-
-

Policy

Policy Engine

Real business rules and verifiable judgment. The architecture that keeps agents on policy.

"Guardrails were the right answer for chatbots. Policies are the right answer for agents."

Rubrik

Prompts are not policies.
A guardrail written into a system prompt is a suggestion: easy to bypass, impossible to audit, impossible to update without touching the agent. Compliance, finance, security, and legal cannot run on suggestions. They need rules: deterministic, versioned, machine-checked, enforceable.

-
-
-
-
-
-

Verifiable Judgment, not opaque scoring
The Policy Engine pairs a deterministic business rules engine with an LLM judge. The rules are real: structured, versioned, the same kind operations teams have used for fifty years. The judge applies them in context, selecting which rules matter for the situation in front of it. We call this Verifiable Judgment: the determinism of a rule engine and the semantic reach of a judge, both observable and both auditable.

Agents stay on policy,

Because the policy is the system, not a prompt.

Real rules, not prompts.

Judgment you can trace.

Rules extracted from your policies.

The right rule at the right time.

Less friction with compliance and legal.

Rules-as-a-service.

Article 9, ready.

Gradient Circle Image
Gradient Circle Image
-
-

Determinism

Process Engine

AI designs the workflow.
The workflow runs the work.

"Leading organisations fundamentally rework processes when deploying AI, three times the rate of other firms."

McKinsey, State of AI 2025

A schedule is not a process.
The current standard for agentic repeated work is a cron timer pointed at a natural-language instruction. Set it once, the LLM runs it on a schedule, each run is fresh, each run is probabilistic. That works for personal scripts and hobby automation. It does not work for closing the books, onboarding a customer, processing a claim, or escalating an incident. Repeated business work has to be deterministic, observable, and provable.-

-
-
-
-

Agent-built. Engine-run.
The Process Engine is a real workflow engine: structured, versioned, observable, and deterministic at execution. A process agent reads what you want and builds a workflow as a first-class artifact. The artifact runs every time the same way. The agent comes back only when the workflow needs to evolve. iPaaS-grade engineering on the execution side, AI on the design side.

The platform ships with Cyclr embedded and supports n8n, Zapier, and other engines as plug-in alternatives. Workflows can call agents, agents can launch workflows, and every step is logged, every change versioned, every result reproducible.

Retire the cron-and-prompt pattern.

Repeated business work belongs in a process, not a re-invocation.

AI builds, the process runs.

Deterministic by default.

Process as artifact.

Engine of your choice.

Agents and workflows that compose.

Enterprise-grade governance.

Article 15, ready.

Gradient Circle Image
Gradient Circle Image
-
-

Accountability

Identity &
Access Control

Real business rules and verifiable judgment. The architecture that keeps agents on policy.

"80% of companies say their AI agents
have taken unintended actions."

SailPoint, 2025

-
-

No identity, no accountability.
Anonymous agents are unmanageable agents. If you cannot tell which agent did something, you cannot govern it, audit it, or trust it. Yet most platforms still let agents share credentials, reuse user sessions, or operate as unidentified service accounts. Every one of them is a future incident.

Treat agents like employees
The principle is simple: every agent is a first-class identity, provisioned by IT, scoped by role, deprovisioned when no longer needed. In security terms, agents are non-human identities (NHIs). Identity & Access Control treats them exactly the way it treats employees, because that is what they have become. Each agent gets its own credentials, its own scope, its own audit trail. Two operating modes:

  • Acting as themselves. Their own permissions, suited to their role.

  • Acting on behalf of a user. Inheriting the user's scope, never exceeding it, with the delegation chain captured at every step.

Underneath, FraiOS runs on WorkOS for enterprise-grade identity: SSO, SAML, SCIM directory sync, RBAC + fine-grained authorisation, and OAuth on-behalf-of token flows. It plugs into the identity platform you already operate.

Every action has a who, a why, and a trail.

Anonymous agents become accountable principals.

Instant notifications.

Assignments to teams or users.

Comments and @-mentions.

Advanced search.

Decisions that survive.

Article 14, ready.

Gradient Circle Image
Gradient Circle Image
-
-

Collaboration

Human-in-the-Loop

Where agents and people work together. Not where AI pings you and waits.

"Effective human oversight is required for high-risk AI systems."

EU AI Act, Article 14

-
-

Most HITL is a pause button.
The agent stops, a notification fires, somebody clicks approve. That works for a developer working alone. It does not work for a team of fifteen, an escalation that needs three approvers, a decision that takes a week, or an audit that asks who said yes and when. Real enterprise HITL is a workplace, not an interrupt.

A workplace for agents and people
Human-in-the-Loop in FraiOS is built on AgentScope's interrupt and intervention primitives: safe interruption, plan pause and resume, real-time hooks into the agent's reasoning. The surface above is a full collaboration system. Agents send tasks to people the same way colleagues send tasks to colleagues. Tasks have owners, assignees, comments, mentions, attachments, and history. Approvals can take a minute or a fortnight. The work routes itself.

The same surface handles agent-to-human, human-to-agent, and human-to-human handoff. One inbox. One searchable history. One place every decision lives.

Autonomy is earned, not assumed.

Human-in-the-Loop is the workplace where you earn it.

Every action, every tool call, every decision.

Meaning, not raw lines.

Pattern detection in real time.

SaaS events folded in.

The learning loop.

Articles 12, 19, and 26, ready.

Gradient Circle Image
Gradient Circle Image
-
-

Verification

Semantic Audit Log

Every action captured with meaning. Queryable, replayable, learnable.

"High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system."

EU AI Act, Article 12

Raw logs are not audits.
A line that says POST /api/v1/orders 200 OK tells you a request happened. It does not tell you what an agent did, why it did it, on whose behalf, or with what business consequence. When something goes wrong, you cannot reconstruct it. When something goes right, you cannot learn from it. Most agent platforms ship raw logs and call it observability.

-
-
-
-

Events with meaning, end to end
Every action in FraiOS is captured as a Semantic Event: not "tool call made" but "Agent X, acting on behalf of User Y, accessed Customer Z's record because of Trigger W and produced Outcome V." Tool calls are logged in full: arguments in, results out, latency, cost. The Event Store keeps the canonical record. The Signal Engine is a Complex Event Processor that watches the stream, detects patterns across events, correlates them across time and systems, and emits higher-order events when something meaningful is happening.

Connected SaaS systems stream their business events into the same store, so the platform sees what is happening across your CRM, helpdesk, ERP, and payment systems in one stream. The same events that audit the past become the context that informs the next agent decision. The log is the substrate, not the side effect.

The Semantic Audit Log is the substrate.

Every other rail is trustworthy because of it.

What exactly gets captured?

Will an audit make sense to a non-technical reader?

Can the system flag things in real time?

Does it cover events from our other systems too?

Does the platform get smarter over time?

Does it satisfy the EU AI Act's logging and retention requirements?

Run your business on AI.
Run AI on Rails.

AI is abundant. Value is earned. FraiOS uses seven enterprise-ready rails to align AI with your business and your operations with AI, so people and agents can create value together. Start small: remove one constraint, release the flow and let each gain compound into momentum.

Remove your first constraint

Run your business on AI.
Run AI on Rails.

AI is abundant. Value is earned. FraiOS uses seven enterprise-ready rails to align AI with your business and your operations with AI, so people and agents can create value together. Start small: remove one constraint, release the flow and let each gain compound into momentum.

Remove your first constraint

Run your business on AI. Run AI on Rails.

AI is abundant. Value is earned. FraiOS uses seven enterprise-ready rails to align AI with your business and your operations with AI, so people and agents can create value together. Start small: remove one constraint, release the flow and let each gain compound into momentum.

Remove your first constraint

The Operating System for Frontier Firms · © 2026

The Operating System for Frontier Firms · © 2026