Deterministic workflows
Rules, triggers and webhooks that move data or transact on a schedule nobody reviews. No AI model involved — and still in scope of the regulation that governs enterprise systems.
AI agents and deterministic workflows — one audit and control layer across every platform where your company builds unattended systems. Identity, pre-execution policy, immutable evidence.
the_scope
Rules, triggers and webhooks that move data or transact on a schedule nobody reviews. No AI model involved — and still in scope of the regulation that governs enterprise systems.
Model-driven steps that decide, draft and act — the same operations as species A, with one more variable nobody can replay by hand.
Same obligations. Same blind spot.
Low-code and the rise of agentic AI handed every department the power to build or customise its own corporate tooling. That autonomy is a win for the business (real operational agility) — and a governance problem for whoever answers for IT (CTOs and CISOs, personally accountable for work built by others): the automation estate now grows outside the review process, and a large part of it runs unidentified and unsupervised. Infrastructure in the shadows is no longer an exception: it is a widespread — and dangerous — condition in an automated company.
the_gap
Your auditor (in a preventive review) or an inspector (on a filed complaint) will ask, about every automation:
anatomy
Four ordinary examples that could be running in a company like yours.
01 · TRIGGER
An invoice is issued in the automated billing platform: with Stripe, say, right after an online sale.
02 · AUTOMATION
A webhook fires with an API key embedded in an n8n flow.
03 · WRITE
The record is replicated into the company’s Sage accounting ERP.
An invoice carrying a name, tax ID and address is processing of personal data — all the more relevant when your customer is an individual or a sole trader. If the flow is not rigorously documented, “in no register” means the record of processing activities (Art. 30) has been incomplete for two years: a present defect, not a future risk. A plain-text API key, never rotated, with write access to accounting, does not survive Art. 32.1.d; and if it leaks, the 72-hour breach notification (Art. 33) is unreachable when nobody knows the flow exists. Stripe and n8n are processors: are you certain there is a DPA, and that transfers are covered with each provider?
The flow is a link in the invoicing chain: it transforms and replicates invoicing records into Sage with no trace, no owner and editable by anyone with access to the flow — an unassessed link inside the SIF perimeter. Integrity, unalterability and traceability required from 1 Jan 2027 for companies; penalties up to €50,000 per financial year.
If the company is an essential or important entity — or supplies one: an uninventoried asset with a credential outside every access policy, three chained providers (Stripe, n8n, Sage) with no supply-chain assessment, and a 24-hour early warning that is unreachable without telemetry. Under Art. 20 the management body is personally accountable.
Directly applicable if you are a financial entity or an ICT provider to one: this is an ICT asset supporting a business function, to be identified, documented and kept current, with Stripe and n8n in the third-party register. For everyone else, it is the inventory standard European regulators are converging on.
Does not apply — and that is the argument. Without a single line of AI, four frameworks in force already reach this flow. The day someone adds an AI node (extracting invoice data with an LLM, say), the classification changes: Art. 50, and potentially more. Only a live census catches that transition.
Built by an employee who no longer works here, with credentials written in plain text inside an external flow, moving invoicing data into accounting without a line in any internal manual and without a single review in two years. The exposure is immediate: a processing activity missing from the Art. 30 record, a permanent write credential that does not survive Art. 32, an unassessed link in the invoicing chain ahead of VeriFactu, and an uninventoried asset with no owner if NIS2 or DORA reach you.
WITH KIMETAI
With Kimetai the flow is inventoried and classified from day one, its API key becomes a governed identity with an accountable owner, and every write into accounting carries a signed, sealed decision — the evidence VeriFactu, NIS2 and an Art. 30 audit ask for.
value_proposition
With AI or without it, built by IT or by a business team. You connect your tools once and we show you every agent and workflow — including whatever nobody declared.
We help you identify each automation, the systems it reads from or writes into, its criticality and the regulation that reaches it — versioned, and reviewed again whenever the flow changes.
We give you one configuration environment where you decide whether to allow, block or require human review for every action your agents and workflows execute — all in a single place.
We give you the infrastructure to store and immutably seal every action your workflows and agents take, so you hold real evidence in front of a regulator or an auditor.
and_moreover
They record what already happened.
Kimetai decides before it happens.
the_console
Workflows and AI agents in the same inventory, the same policy model and the same audit trail — in a console everyone can read the same way.
illustrative view · synthetic data
recent_decisions
simulated on last 30 days: 4 would-block · 0 breaking changes
architecture
Wherever your automations were built, governance converges in one place.
One inventory · one permission model · one audit trail
Third-party names are integration targets or technologies already integrated in Kimetai.
regulation_timeline
Pick your country to see what applies, ordered by date of applicability.
Applies across the EU
Record of processing activities (Art. 30) and the right to human intervention in automated decisions (Art. 22.3).
In force since 2018
Applies across the EU
Asset management as a mandatory measure, with direct accountability for management bodies.
Since Oct 2024
Applies across the EU
Complete inventory of ICT assets and dependencies, plus a register of third-party providers.
Since Jan 2025
Applies across the EU
Systems that interact with people or generate synthetic content must disclose it.
02-08-2026
Applies across the EU
Human oversight, event logging and technical dossier.
02-12-2027
Applies across the EU
Converges the national invoicing regimes into intra-EU digital reporting.
From 2030
Six different national invoicing regimes, converging into ViDA from 2030. Select a country to see the one that applies to you.
NIS2 national transposition and thresholds vary by country — verify your own case.
Informational. Not legal advice. · Last reviewed: August 2026
We map your inventory with you: what runs, who owns it, which frameworks reach it.