Your tools already have the answer. Someone still spends Friday afternoon assembling it.
Say how the work goes, once, in your own words. It then runs on your own accounts, waits for a person before it writes anything, and leaves a record you can read back.
Nothing is written until a person approves it. Every run leaves an audit trail. It runs inside your own accounts, on infrastructure resident in the European Union.
A recorded run. The marks of the systems a team already uses drift in a field of light. A spoken request, Make the Friday support handover: what is still open, who owns it, and who is actually covering the weekend. docks at the top of the frame beside a four step plan: Find the escalation still open; Look up who owns that account; Read what the customer last asked; Get the answer only a person has. One thread of light then walks the systems in order rather than fanning out to them, leaving the path it took faintly lit behind it. The ticket system returns the one escalation still open and the account named on it. That name is what the account record is looked up by, and the record points at a mail thread. The customer’s last reply in that thread asks who is reachable on Saturday, which is a question only a person can answer, so it goes to Nadia in the team chat and she answers that Tom has Saturday. The four answers compose into a handover document. The document is drawn with a dashed border while it is only proposed, waits for approval, and becomes solid and stamped as posted once a person approves it.
Recorded run
Make the Friday support handover: what is still open, who owns it, and who is actually covering the weekend.
The job below is the one in the panel above. Here is what it takes when a person does it, and which system it sends them to each time.
Needed a person
0Lookups
Seven of those steps fetched something a system already knew. One needed a person.
SystemStep
01
tickets
Open the ticket queue.
02
tickets
Filter to what is still unresolved.
03
crm
Work out which account each one belongs to.
04
crm
Open the account to see who owns it.
05
#team-ops
Two of those owners are away. They said so in a channel on Tuesday.
06
No system
One ticket needs an answer only a colleague has, so you ask.
And then you wait.
07
doc
Write all of it into a document.
08
#handover
Post the link before people leave.
That is one Friday. Now count how many of those steps needed a person’s judgement, and how many needed someone to go and look up a thing a system already knew.
It is not only Fridays.
A payment dispute opens.
#supportcrmorders#finance
It is nobody’s job, so it belongs to whoever saw it first.
The monthly figure lives in four exports.
crmbillingsheets#finance
And the two people whose numbers are missing have to be chased for them.
If the reason it is still manual is that nobody was allowed to connect the two systems, that is the other half of this page.
Source
Copying by hand is also where the errors are. A 2025 meta-analysis in the International Journal of Medical Informatics pooled 84 studies of clinical data processing and found that people transcribing from existing records erred on 6.57% of fields, against 0.14% when two people entered the same data independently. Different setting, same act: a person reading one system and typing into another.
Pick the task your team actually repeats. That is the one to bring.
It starts with a sentence.
Most of this work begins with something somebody says out loud. Say it into your phone and the words are turned into text on the device, kept whole however long the sentence runs, and read back as a plan before anything is touched.
Nothing you said is trimmed
A long request is not a problem to be shortened. What you said stays attached to the run in full, so the request and the record of it are the same words.
The microphone is a way in, not a mode
Anything you can say you can also type, in the same composer at your desk. The plan that comes back is the same either way, and so is the approval in front of the one step that writes.
The request screen on a phone. It is 09:28 and the microphone is open: a bar meter moves beside it and seven seconds have been counted. The sentence said so far is set in full, wrapping over as many lines as it needs and cut short nowhere: Pull the latest from the incident channel and send it to the leads. Two chips beside it say the words are turned into text on the device, and that it asks before writing. Under that is the plan the sentence has already become: read the incident channel, draft the incident handover, and send it to Marta Rusek and Jonas Weber, which is the one step marked as needing approval, going out as sanne.bakker@kenward.ai. Along the foot sit a keyboard, the microphone, the meter and a Done button, and below them the five places the product has: requests, approvals, agents, connectors and the ledger.
09:28
New request✱ AI-generated demo
Listening0:07
Pull the latest from the incident channel and send it to the leads.
Ask in plain language. Every line of the answer names the document, thread or channel it came from, so you can check it before you act on it.
The requests screen of the application. Someone asks, What did we commit to Nordvik Logistics about where their data lives? The answer comes back as three lines, each one followed by the documents, threads and channels it was read out of, and beside it is the list of four sources with the words each one contributed. Every citation is a button: opening one shows the fragment it came from. All four sources were read and nothing was written. Every name, address and document here is sample data.
What did we commit to Nordvik Logistics about where their data lives?
asked 09:41
Answerevery line cited
Their signed order form keeps customer data inside the EU, with Frankfurt named as the primary region.
Jonas Weber put the same thing in writing during the renewal, and added that backups stay in region too.
An exception to run analytics elsewhere was raised in the account channel, then withdrawn the same week.
Assembled from 4 sources. Nothing was written.
Read fromread only
Open a citation to read the line it came from.
Ask about an account, or say it out loud
Sovereign · EUAsk before writing↵ send⇧↵ new line
Every citation above opens the line it came from. An answer you cannot check is a rumour with better formatting.
Nobody chose to run this many tools.
Okta counted an average of 101 applications per company in 2025, measured across its own customer base. Kenward works inside the accounts you already have, with the access you grant and nothing past it. How far that reaches comes in three tiers.
Slack
Notion
Linear
GitHub
Gmail
Google Drive
Google Calendar
Jira
Confluence
Figma
Stripe
HubSpot
Salesforce
Zendesk
Intercom
Asana
Trello
Monday
ClickUp
Airtable
Dropbox
GitLab
Sentry
Datadog
PagerDuty
PostgreSQL
Shopify
QuickBooks
Zoom
Outlook
Teams
OneDrive
SharePoint
Something else
The connectors screen of the application. Ten systems are connected, all processed in the EU, in Amsterdam: Slack, Outlook, Notion, Google Drive, Stripe, Linear, Google Calendar, GitHub, Confluence and HubSpot. Each tile carries what the connection may touch, how much of it was granted, and when it last synced: Slack reads and posts to four channels, Stripe may refund up to two hundred and fifty euro, and Drive is read only across six folders. Two more, Jira and Zendesk, are drawn dashed because they are not connected. A tile at the end offers to connect another, and along the foot is the audit chain every write on these connections lands on.
The tools most teams live in are wired in end to end. Kenward reads from them, and writes back to them once a person approves the write.
Connected with a key you already hold
Plenty more come online the moment you hand Kenward a key your team already has. Nothing new to buy, nothing new to deploy.
Added when a run needs it
The rest of the catalogue is added on request, under the same permissions and the same approval rules as everything above it.
Something in your stack that nobody else has is added the same way.
The work does not stay one size.
A task becomes a routine, and a routine becomes something that watches on its own. Every rung below is built from the same reads, writes and approvals, which is why the safety story does not change as you climb.
0Action
The answer already exists across five tools. Getting it out is the work.
“Pull the latest from the incident channel and send it to the leads.”
One read that cites where every line came from, one message composed from it, and one write into another tool.
A looping scene of one action, playing inside the application. A spoken request, Pull the latest from the incident channel and send it to the leads., arrives. The incident channel is read and returns three short facts: Checkout started failing, cited to #incident-2481 09:04; A rollback is out, cited to #incident-2481 09:12; Two customers still waiting, cited to #incident-2481 09:26. Those facts compose into a short update addressed to the two leads, drawn with a dashed border while it is only proposed. It is then written out as an email and becomes solid with an amber edge, stamped as sent with an audit reference.
Pull the latest from the incident channel and send it to the leads.
Request
#incident-2481Read
Checkout started failing#incident-2481 09:04
A rollback is out#incident-2481 09:12
Two customers still waiting#incident-2481 09:26
Incident updateMarta Rusek, Jonas Weber
Checkout started failing at 09:04, a rollback is out, and two customers are still waiting.
Sent 09:31 · audit 6b2c91d4
Ask for something, or say it out loud
Sovereign · EUAsk before writing↵ send⇧↵ new line
1Automation
The alert arrives on its own. Whether anything happens next depends on who is looking.
“When a payment dispute opens, post it to the finance channel and draft the reply.”
A trigger, the actions it is allowed to take, and the accounts it may touch. Set up by saying it, not by writing code.
A looping scene of one automation being set up by speaking. Someone says, When a payment dispute opens, post it to the finance channel and draft the reply. The sentence resolves into three named parts that fill in one at a time: a trigger, a payment dispute opening in Stripe; two actions, posting to the finance channel in Slack and drafting the reply in Gmail; and the grants it may use, Stripe read, Slack post, Gmail draft. The whole card is dashed and muted while it is only proposed, then it is published and becomes solid with an amber left edge, live on your own accounts.
When a payment dispute opens, post it to the finance channel and draft the reply.
draft
Dispute responderDraft
Trigger
A payment dispute openscharge.dispute.created
Actions
Post it to #financeDraft the reply
Grants
Stripe readSlack postGmail draft
Nothing runs until you publish
Publish
Ask for something, or say it out loud
Sovereign · EUAsk before writing↵ send⇧↵ new line
2Agent built by speaking
Some steps need one judgement call, which is the reason they never got automated.
“Watch this channel. When a customer sounds unhappy, draft a reply and open a ticket.”
The same bounded workflow, given one judgement call. Its shape and its permissions stay fixed and readable.
A looping scene of an agent built by speaking. Someone says, Watch this channel. When a customer sounds unhappy, draft a reply and open a ticket. It becomes an agent card with four parts. Three of them carry a lock, meaning the agent cannot change them: the trigger, a new message in the customer voice channel; the actions, drafting a reply in Gmail and opening a ticket in Linear; and the grants, Slack read, Draft only, Ticket create. The fourth part is marked in amber and is the only place a model decides anything: whether the customer sounds unhappy. The card is dashed while it is proposed, then becomes solid with an amber left edge and shows one completed run, a reply drafted and ticket KW-2481 opened.
Watch this channel. When a customer sounds unhappy, draft a reply and open a ticket.
proposed
Customer mood watchProposed
Trigger
#customer-voice
Judgement
Is the customer unhappy?The only call the model makes.
Actions
Draft the replyOpen a ticket
Grants
Slack readDraft onlyTicket create
Last run · reply drafted, KW-2481 opened
Ask for something, or say it out loud
Sovereign · EUAsk before writing↵ send⇧↵ new line
3ViewOn the roadmap. Not running yet.
Once software acts on your behalf, someone will ask what it did. Answering should not mean going to look.
“Show me every agent running, what it touched, and what it cost this week.”
A saved read-only view over the same ledger the audit trail is written to. It reads, it never writes.
A saved view over the audit ledger. Someone asks, Show me every agent running, what it touched, and what it cost this week. A table headed "Agents running" opens and fills one row at a time with sample data: Dispute responder, touching stripe and slack, 18.42 euro; Customer mood watch, touching slack and linear, 11.07 euro; Contract intake, touching google-drive and notion, 8.63 euro; Weekly board brief, touching gmail and notion, 2.94 euro. A footer adds the four agents up to 41.06 euro for the week. The view is then saved and marked read only: it reads the ledger and cannot write to it. Every figure shown is sample data.
Show me every agent running, what it touched, and what it cost this week.
reading
Agents runningSample dataReading ledger
AgentTouchedCost, EUR
Dispute responder18.42
Customer mood watch11.07
Contract intake8.63
Weekly board brief2.94
Four agents running this week41.06
This view reads the ledger. It cannot write to it.reads ledger.agent_runs · writes none
Ask the ledger something, or say it out loud
Sovereign · EUAsk before writing↵ send⇧↵ new line
4Mini-appOn the roadmap. Not running yet.
The request for a small internal tool never reaches the top of anyone’s queue, so the process runs in a spreadsheet instead.
“A queue to review incoming contracts, tag them, and route the approved ones to legal.”
A fixed kit of parts assembles the queue, the tags and the approval route, so it looks like the rest of the product.
A small internal tool assembling itself. Someone says, A queue to review incoming contracts, tag them, and route the approved ones to legal. A fixed kit of standard parts is laid out: Queue, Tags, Approval route, Audit trail. Each part is dashed while it is unused and solid once it is placed. The queue arrives first with three contracts waiting: Vermeer Logistiek MSA, Lindau Energie DPA, Serrano Labs NDA. Tags are suggested for the first contract, then the approval route is proposed, drawn dashed. The tool is then used once: the tags are applied and the contract is routed to Katrien Bos in legal, which turns the route solid with an amber edge and writes it to the audit trail.
A queue to review incoming contracts, tag them, and route the approved ones to legal.
in review
Standard parts
QueueTagsApproval routeAudit trail
Contract reviewBuilt from standard parts
Queue · 3
Vermeer Logistiek MSAIn review
Lindau Energie DPANew
Serrano Labs NDANew
Vermeer Logistiek MSA
Suggested tags
MSAEU dataAuto renewal
Route to legal#legal-review · Katrien BosApprove
5Auto-detectOn the roadmap. Not running yet.
The fourth time you do something by hand it stops being a task and becomes a habit nobody questions.
“You have drafted this same reply several times this week. Do you want an agent for it?”
The ledger notices repeated intent and proposes the same trusted parts back to you. Proposed, never running until you say so.
A ledger noticing a repeated intent. Four near identical sample entries arrive, one at a time: Re: delivery date, order 4819 on Mon, drafted; Re: delivery date, order 4867 on Tue, drafted; Re: delivery date, order 4903 on Wed, drafted; Re: delivery date, order 5012 on Fri, drafted. The wording they share is then held in full strength while the order number that varies drops back, so the four read as one pattern. An agent called Delivery delay responder is proposed back, drawn with a dashed border because it is only a proposal: You have drafted this same reply several times this week. Do you want an agent for it? It reads Gmail, composes the reply you usually send, and is granted drafting only. The scene ends with the proposal still waiting. Nothing runs until a person accepts it. The entries shown are sample data.
The same intent, four times. One pattern, and the wording never changed.
Delivery delay responder
Not running
“You have drafted this same reply several times this week. Do you want an agent for it?”
ReadGmail
ComposeYour usual reply
GrantDraft only
Nothing runs until you acceptNot nowCreate agent
Describe an agent, or say it out loud
Sovereign · EUAsk before writing↵ send⇧↵ new line
Reading your tools is plumbing.
Every vendor has it now, and it stops being interesting the moment it works. A tool that answers questions well still leaves the work exactly where it was.
What is worth buildingsits after that.
The people who actually do the work say how the work goes, and that becomes software: running on your own accounts, waiting for a person before it writes anything, leaving a record you can read afterwards.
The system your work depends on is usually the one nobody supports.
A handful of systems carry most of the work, and those are modelled properly, in both directions. Everything else connects with a key you already hold.
Adding one yourself takes a server address, or a sentence describing the API. Nothing to install on our side, and nothing to wait for.
A proposed connection, drawn dashed because nothing has happened yet. It offers two ways in, a server address or a sentence describing the API, and says at its foot that whatever comes in joins the same list of connections as everything else, with the same scope line and the same approval rule in front of every write.
New connectionproposed
AddressPaste a server addressConnect
SentenceDescribe the API in a sentence
It joins the same list of connections as everything else, with the same scope line and the same approval rule in front of every write.
Your key
Anything with an API connects using credentials you already hold. The key stays yours, and it stays where you put it.
Missing one
The rest of the catalogue is brought in as people ask for it. If the one you need is missing, say so and it gets added.
Not wanting to give an agent write access is the correct instinct.
So we did not ask you to drop it. A write here is a proposal: drafted, shown to you in full, naming the account it would touch and the exact content it would leave behind. Nothing goes out until a person approves it, and what you approve lands on a record you can read back.
You do not have to start here. A connection can be read-only, and stay read-only until it has earned more.
1
The agent proposes
A write is drafted against the connection you granted, and nothing is sent. Dashed means it has not happened.
2
A person approves
You see the exact change first: the field, the value it holds now, and the value it would hold. Approve it, or deny it.
3
It commits to the record
Only then does the write run, and it is appended to an audit chain where each entry signs the one before it, so an edit after the fact breaks the chain.
A scene you advance by scrolling, playing inside the approval inbox. Three writes are waiting in the inbox behind it. Raised over that canvas is one consent card for the tool hubspot.contact.update, proposing to set the renewal owner on the Bergkamp Transport account, changing it from Joris Aaltink to Sofie Lindqvist. The card is drawn with a dashed border while it is only a proposal, and it carries approve and deny controls. Once it is approved the card becomes solid with an amber left edge, the controls are replaced by a line reading approved by Sanne Bakker at 14:02, and a new entry, 2f8ac06d, joins the audit chain along its foot, linked after the two entries already there, 9c41f0a2 and 4b7de315.
Checkout failed 09:04, rollback out 09:12, two customers waiting.
2 min agoHandover writer
ApproveDiscardEdit firstsend as sanne.bakker@kenward.ai·expires in 58 min
Create page in Incidents database
Handover doc, 4 properties set, no existing page matched.
2 min agoHandover writer
Issue credit of € 41.20 on dispute 2481
Second reminder unanswered, policy match on rule 4.
14 min agoDispute watcher
Post handover to #ops-handover
Approved by Sanne Bakker, written 09:31.
31 min agoHandover writer
6b2c91d4→a17f0c93→e40b7712append only
Nothing else is waiting. Approved writes appear in the ledger.
Earlier todayall 41 in the ledger
Comment on OPS-118
Approved by Marta Rusek, written 08:52.
1 h agoDispute watcher
Move 3 contracts to Reviewed
Approved by Sanne Bakker, written 08:14.
2 h agoContract triage
hubspot.contact.updateAsk each time
Set the renewal owner on the Bergkamp Transport account
Renewal owner
Joris AaltinkSofie Lindqvist
ApproveDeny
Approved by Sanne Bakker14:02
Audit chain9c41f0a24b7de3152f8ac06d
You have said no to tools like this before. Here is what you would be reviewing.
Resident in the European Union by construction, self-hosted when that is what the situation needs, and no round trip across the Atlantic to answer a question about your own work.
One run, drawn inside a single boundary: a request arriving in your tenant, retrieval over your own index, the model call against European inference, the write that happens once a person approves it, and the entry left in your ledger. Every stop is inside the same European deployment and nothing in the path crosses the Atlantic.
Inside the boundaryResident in the EU
A request arrivesyour tenant
Retrieval over your own datayour index
The model callEU inference
The write, once a person approves ityour accounts
The entry left in the audit trailyour ledger
Nothing crosses the Atlantic
By construction
Resident in the EU by default
Your documents, the index built from them and the model calls made against them stay inside the European Union. It is where the deployment is, not a setting you have to go and find.
GDPR, the DSA and NIS2 as requirements
They are treated as things the software has to satisfy now, in how data is held, logged and erased, rather than as items sitting on a roadmap.
By your choice
Self-hosted when the situation needs it
Some work cannot leave the building. The same software runs in your own environment, with the same approvals and the same audit trail, on infrastructure you control.
If this is the part someone else has to sign off, send them this section. These are the three documents they will ask for.
Data processing agreement
Subprocessor list
Deletion procedure
Kenward is a company founded in the Netherlands, working under the rules it is built for.
Bring one task someone does every week by copying between tools.
Questions worth asking before you connect anything.
The short answers. Where the honest answer is a limit, that is the answer.
Notion AI and Copilot already do this. Why would we add another one?
They answer questions about documents someone wrote. This answers from your live tools and then does the work: it drafts the message, waits for a person, sends it, and records what it sent. That is a different category, not a better version of the same one. If you already have one of them, the useful test is one real task, end to end, and we are happy for that to be the comparison.
Why would we give an agent permission to send things on our behalf?
You would not, and you should not start there. A connection can be read-only, and stay read-only until it has earned more. When you do allow a write, the write is proposed first, in full, naming the account it would touch and the exact content it would leave behind, and nothing goes out until a person approves it. Per workflow you decide whether that approval is asked every time or granted once as a standing rule.
Which of the things on this page actually work today?
Rungs 0, 1 and 2 run today: a single action, a triggered automation, and a bounded agent with one judgement call. Anything above that is labelled on the page as roadmap because it is roadmap. If a demo shows you something, it is running.
Our IT department will want a DPA, a subprocessor list and a deletion procedure. Do those exist?
Yes. They are the three documents named in the section on where it runs, and you get them as documents rather than as claims on a page. Kenward runs on European infrastructure, your documents stay in the systems they already live in, and what we keep is the record of the run rather than a second copy of your files. Teams that need it run Kenward inside their own cloud.
Can you prove deletion?
Yes, and it is worth asking, because most tools in this space cannot. Disconnect a connection and every workflow built on it stops. Ask for erasure and the record of what was held, and what was removed, is part of the same audit trail as everything else.
What happens when it does not know the answer?
It stops and says so. A run that cannot find what it needs comes back with the question rather than a confident guess, and that step stays unfinished until someone answers it. Visibly stuck is the behaviour we design for. Quietly wrong is the failure we do not accept.
Can something it did be undone?
Most writes can be reversed from the run that made them, and the reversal is recorded like any other write. Some cannot be: a sent email is sent, a paid invoice is paid. Those are exactly the actions worth keeping behind an approval.
What does it cost, and what do we commit to?
Pilots are priced and run on a 60-day term, cancel anytime. The success criterion is written into the pilot itself: at least one thing running every week that your team would notice if it stopped. If that has not happened, there is nothing to convert.
Something we have not answered here? Write to hello@kenward.ai and a person will reply.