XceedNexus

Agents you can actually deploy

XceedNexus is the orchestration and governance layer of Xceed365HR. It coordinates every AI agent across the platform and constrains what each one can do, so your team can put agents to work on payroll and people data without giving up control.

Why a control layer

Every vendor has agents. Few can tell you what theirs are allowed to do

That gap is where enterprise AI projects stall. The pilot goes well, the demo impresses HR, and then the request reaches security.

Orchestration

What makes agents useful

Agents across payroll, leave, hiring, learning and every add-on suite work as one coordinated system rather than a scattering of separate bots. They share context and hand work between each other to complete a request end to end.

Governance

What makes agents deployable

An agent holds no credentials of its own and cannot query a database. It reaches data only through the product's own API calls, acting as the person who asked and inheriting exactly that person's permissions. It acts on instruction, never on initiative.

You are not asked to trust our agents. You are shown the boundary they operate inside, and given the record of everything they have done.

What XceedNexus does

Six controls, working together

Every agent in the core suites and the add-on suites runs through XceedNexus. None operates outside it.

Defines each agent's reach

XceedNexus specifies the exact API calls an agent may make, and it has no other route to data. You know precisely what an agent can touch before you switch it on.

Routes work across suites

A request is broken into steps and handed between the agents best suited to each. Your team asks for an outcome instead of learning which module owns which task.

Inherits your permissions

An agent acts as the person who asked, carrying that person's rights and nothing more. There is no second permission model to build and maintain.

Holds work at approval gates

Consequential actions stop and wait for a named approver. Payroll is prepared in minutes and still never runs without a person accepting it.

Records every action

Each step is logged with its tenant context and retained indefinitely. You can reconstruct what happened months later for an auditor, a regulator or an employee dispute.

Runs where your data lives

Agent work happens inside the regional shard holding your data. Residency commitments continue to hold when AI is involved, which is where most residency promises quietly break.

Security and trust

Written for security review

Every claim below is a control, at a stated layer, that an auditor can test.

  • Agents do not store your data, and no customer data trains any model. Agents retain nothing after completing an instruction. Models run inside our own environment, process only the payload required to carry out the instruction, and retain nothing once the response is returned.
  • Agents act only on instruction, through the product's own API. An agent holds no credentials and no standing database access. It calls the same documented API a human calls, under the identity of the person who asked, inheriting that person's permissions and the same row-level policy. It cannot query the database directly or widen its own scope.
  • Isolation is enforced by the database, not by application code. The platform is multi-tenant with logical separation, deployed as regional shards in Nigeria, Kenya, South Africa and the UAE, with your data resident in your region's shard. Row-level security policies in PostgreSQL bind to a tenant context taken from the authenticated principal, database roles are least privilege so no application path can bypass them, and cross-tenant access tests run on every build. Encryption is applied in transit and at rest, with per-tenant keys.
  • Consequential actions require a person. Agents prepare and recommend. Actions with real consequence, a payroll run being the clearest case, stop at an approval gate until a named human accepts them. When an agent is wrong, it is wrong in a proposal a person reviews, not in a payment already made.
  • Everything is recorded, permanently. Every agent action is logged with its tenant context and retained indefinitely, so any decision can be reconstructed long after the fact.

Certifications and evidence

ISO 27001:2022 Certified Company SOC 2 Type II Certified GDPR Compliant

We hold SOC 2 Type II and ISO 27001:2022 certification, comply with GDPR, and publish an AI Security Policy and a Trust Center. Our SOC 2 Type II report and penetration test summary are available under NDA.

Straight answers

What security teams ask us

Will your agents train on our employee data?

No customer data is used to train any model. Models run inside our environment, process only what is needed to complete the instruction, and retain nothing afterwards.

We are multi-tenant. How is our data separated from another client's?

Separation is enforced by the database through row-level security policies bound to a tenant context taken from the authenticated principal, backed by least-privilege database roles so no application path can bypass them. Cross-tenant access is tested automatically on every build.

Where does our data physically sit?

In the regional shard for your market, with shards operating in Nigeria, Kenya, South Africa and the UAE. Agent execution happens inside that same shard, so residency holds when AI is involved.

What stops an agent doing something we never approved?

An agent has no credentials and no direct data access, and can only make the specific API calls it is permitted, acting as the user who asked and holding no more rights than that person. It acts on instruction and never on its own initiative.

Can we audit what the AI did?

Every agent action is logged with tenant context and retained indefinitely. You can reconstruct any sequence of steps, including who instructed it and who approved it.

What happens when an agent gets something wrong?

Consequential actions wait at a human approval gate, so an error surfaces as a proposal a person declines rather than an action already taken. The full log lets you trace what the agent did and why it proposed it.

See XceedNexus running your payroll

Bring your security team. We will walk the controls, the logs and the approval gates in the product, not in a slide.