XceedNexus is the orchestration and governance layer of Xceed365HR. It coordinates every AI agent across the platform and constrains what each one can do, so your team can put agents to work on payroll and people data without giving up control.
That gap is where enterprise AI projects stall. The pilot goes well, the demo impresses HR, and then the request reaches security.
Agents across payroll, leave, hiring, learning and every add-on suite work as one coordinated system rather than a scattering of separate bots. They share context and hand work between each other to complete a request end to end.
An agent holds no credentials of its own and cannot query a database. It reaches data only through the product's own API calls, acting as the person who asked and inheriting exactly that person's permissions. It acts on instruction, never on initiative.
You are not asked to trust our agents. You are shown the boundary they operate inside, and given the record of everything they have done.
Every agent in the core suites and the add-on suites runs through XceedNexus. None operates outside it.
XceedNexus specifies the exact API calls an agent may make, and it has no other route to data. You know precisely what an agent can touch before you switch it on.
A request is broken into steps and handed between the agents best suited to each. Your team asks for an outcome instead of learning which module owns which task.
An agent acts as the person who asked, carrying that person's rights and nothing more. There is no second permission model to build and maintain.
Consequential actions stop and wait for a named approver. Payroll is prepared in minutes and still never runs without a person accepting it.
Each step is logged with its tenant context and retained indefinitely. You can reconstruct what happened months later for an auditor, a regulator or an employee dispute.
Agent work happens inside the regional shard holding your data. Residency commitments continue to hold when AI is involved, which is where most residency promises quietly break.
Every claim below is a control, at a stated layer, that an auditor can test.
Certifications and evidence
We hold SOC 2 Type II and ISO 27001:2022 certification, comply with GDPR, and publish an AI Security Policy and a Trust Center. Our SOC 2 Type II report and penetration test summary are available under NDA.
No customer data is used to train any model. Models run inside our environment, process only what is needed to complete the instruction, and retain nothing afterwards.
Separation is enforced by the database through row-level security policies bound to a tenant context taken from the authenticated principal, backed by least-privilege database roles so no application path can bypass them. Cross-tenant access is tested automatically on every build.
In the regional shard for your market, with shards operating in Nigeria, Kenya, South Africa and the UAE. Agent execution happens inside that same shard, so residency holds when AI is involved.
An agent has no credentials and no direct data access, and can only make the specific API calls it is permitted, acting as the user who asked and holding no more rights than that person. It acts on instruction and never on its own initiative.
Every agent action is logged with tenant context and retained indefinitely. You can reconstruct any sequence of steps, including who instructed it and who approved it.
Consequential actions wait at a human approval gate, so an error surfaces as a proposal a person declines rather than an action already taken. The full log lets you trace what the agent did and why it proposed it.
Bring your security team. We will walk the controls, the logs and the approval gates in the product, not in a slide.