Platform · Governed AI Orchestration

Built to get
work done.

A financial institution doesn’t need more AI. It needs the work done, in a way it can stand behind.

Grant ISSUED · ACTIVE
ONX-AGENT-07
under grant
Work classFinancial Spreading Valid until2026-12-31 BasisOverride rate < θ RevocationOn breach or drift
R. Kawaguchi, ACA
GRANTOR · CREDIT OFFICER, CORPORATE CREDIT
REGISTERED
Run it.
Most of the work happens on its own. What can’t is checked, and goes to a person.
Check it.
Every claim is written to ProvChain as it happens. Nothing is reconstructed after the fact.
Sign it.
A named party, entitled to the slot, states what the work warrants. Governed by the Nexus Signing Standard.
ORCHESTRATION
Two tiers,
one job

AI agents handle volume on their own.

Manager agents handle the orchestration, assigning work and deciding what’s next. Sub-agents handle the execution, each one specialized, optimized, and accountable for what it produces. That’s why agents can handle volume on their own.

Most of a workflow completes without anyone touching it. What decides which part doesn’t is checked before anything runs, not after.

IDP
Unstructured,
not unusable

Your unstructured data, unlocked.

80% of data inside a financial institution lives in documents, not databases: statements, filings, onboarding documents, customer identities. That’s exactly the work that’s stayed manual, because most software can’t read it. OneNexus unlocks it for automation.

It’s also why accuracy holds up on messy, real-world documents, not just clean test data.

GOVERNANCE
Four things,
checked first

Every step, checked before it runs.

This is how each step can run untouched, and still be provable. Four checks, none optional.

  1. 01Register Nothing unregistered may run.

    Every agent and workflow is registered before it can touch a document. Not on the list, doesn’t run. That’s the whole rule.

    Agent · val Agent · ace Workflow · spreads Version v5 (active) Handler pack Prompt set Contract rules Seed bundle
  2. 02Grants Authority is lent, and it can be taken back.

    Humans hold signing authority. Agents hold a grant of it: scoped to a work class, time-boxed, revocable. It delegates. It never abdicates.

    A named person issues the grant, and stays answerable for what’s signed under it. It covers one type of work and expires. It widens as the agent earns trust, and narrows or gets pulled the moment something drifts. That’s the card above.

  3. 03Policy Nobody chooses the signer. The policy does.

    A policy decides how many people need to sign off, and who’s eligible. If no one qualifies, the case climbs a default ladder:

    AIAnalystManagerInstitution

    That Manager is a person. The Manager tier above is software. Same word, different job.

  4. 04Guardrails What happens while a step runs, not who’s allowed to run it.

    Register decides what’s allowed to run. Policy decides who signs it. Guardrails watch it while it runs: content checks, format checks, rate limits. They keep working whether a person or an agent is behind the wheel.

Same four checks in every deployment: cloud, dedicated, on-premises. None of them get lighter because the software moved into your building.

AUDITABILITY
Proof, not
a promise

Provable, not just promised.

Auditability, to us, is two things: Traceability and Accountability. Neither one alone survives an audit.

Traceability is evidence: what happened, recorded as it happens. That’s ProvChain, an evidence ledger built to accept every claim and never refuse one, which is what makes it useful for a genuine reconstruction later.

Accountability is who’s answerable, and whether they were entitled to be. That’s SignChain, an accountability ledger built to do the opposite: refuse anything invalid. Identity, designation and the role someone signed from, recorded as they stood at the moment of signing, not as they stand today.

The two are joined only when read, never merged in storage.

See the record → Read the seven rules →

LEARNING LOOP
What every
correction earns

It gets better with every correction.

Every correction is already logged, permanently. We also mine those corrections to find where a workflow should improve, so it needs less human review over time.

It changes how a workflow runs. It never changes the record of what happened.

CONFIGURABLE WORKFLOWS
Where this
shows up

Same platform. Live today.

Every OneNexus workflow runs on the same engine, configured differently: different steps, different roles, different thresholds, never different code. That’s what makes deployment a configuration exercise, not a rebuild. Four you can see live right now.

Financial
Spreads
LIVE · V5 ACTIVE
Most active configuration today
See the Sign →
ESG
Assessments
CONFIGURED, NOT CODED
A different work class entirely
See the Sign →
KYC
Files
MULTIPLE ROLES
Maker, Reviewer, Approver, one setup
See the Sign →
Client
Statements
ROUTINE AND EXCEPTION
Same workflow, both cases
See the Sign →

Same platform underneath all four. What changes is configuration, not code.

Before you call it done

“Can you stand behind it?”

Request a demo and see how much of the work runs on its own, and what’s checked before it’s called done.