Executable enterprise policy

    Model how your business may operate. Enforce it on every message.

    A DataInbox rule is not a trigger-action shortcut. It is part of an executable operating model that connects business meaning, context, identity, purpose, risk, permissions, decisions, actions, and evidence. AI can help author the model. The deterministic runtime remains authoritative.
    • Business and domain models
    • Security, data and AI policy
    • Governed state and decisions
    • Validated configuration changes

    A different class of rule engine

    Not IFTTT. Executable enterprise modelling.

    Simple automation asks what should happen after a trigger. DataInbox first asks what the message means, which operating context applies, who has authority, which policy permits the next step, and what evidence must remain.

    Trigger automation

    When this happens, do that

    • Starts from a technical event
    • Automates a local task or integration
    • Often assumes context and data quality
    • Explains execution, not always business authority

    DataInbox policy model

    Given this business context, what is permitted now?

    • Starts from a validated business message
    • Evaluates domain state, identity, purpose, and risk
    • Constrains people, systems, agents, and Companions
    • Produces an accountable decision and traceable result

    The operating model

    Rules express how the enterprise works

    Routing, validation, and approval are outcomes of a richer model. The model can describe the business object, its current state, applicable policy, permitted actors, available capabilities, and the evidence required after execution.

    Message and domain model

    Define what a customer, order, payment, case, decision, or document means, which fields are required, and which business invariants must hold.

    Identity and authority

    Determine which person, system, agent, or Companion may see context, propose a decision, approve it, or perform an action.

    Purpose and permitted use

    Connect data use to purpose, consent, classification, minimisation, retention, deletion, and the conditions that apply to every operation.

    State and decision logic

    Model valid states, transitions, exceptions, approvals, escalations, deadlines, and the next action that is allowed in the current context.

    Risk and regulation

    Translate applicable security, data, AI, and sector requirements into controls that can be evaluated when a business message is processed.

    Outcome and evidence

    Record the input, applicable policy, decision, approval, action, result, and exception as traceable business-message evidence.

    Policy becomes operation

    Turn complex requirements into controls the runtime can evaluate

    Regulations such as GDPR, NIS2, and the EU AI Act do not become one universal checkbox. Their applicable requirements, together with internal security and data policies, must be translated into explicit controls for each operating context.

    DataInbox can support enforcement and evidence. Compliance still depends on your organisation, role, use case, risk classification, configuration, contracts, and operating procedures.

    Security policy

    Classify a message, verify identity and scope, restrict sensitive fields, require stronger approval, and reject a capability that is not permitted.

    Data policy

    Evaluate source, purpose, consent, minimisation, residency, retention, and deletion before data is exposed or used for another operation.

    AI policy

    Select eligible AI Companions, constrain the context they receive, define the output contract, require human oversight, and validate the result before use.

    Operational policy

    Validate business state, route the message, request approval, invoke an allowed capability, handle an exception, and capture the resulting state change.

    AI-assisted authoring

    Let AI do the modelling work without giving it the keys

    An AI agent can analyse policy documents, ask for missing decisions, inspect the supported configuration model, and draft complex Inbox rules. The DataInbox CLI then provides a controlled path from proposal to approved configuration.

    01

    Interpret the requirement

    Business experts, legal teams, security teams, and engineers define the desired operating model. AI can help turn policies and regulation into explicit requirements and testable decisions.

    02

    Draft against the specification

    An AI agent can inspect the DataInbox configuration specification and the current Inbox configuration, then propose structured changes without inventing unsupported fields.

    03

    Validate and compare

    The CLI validates the candidate configuration and produces a diff. A failed validation or an unexpected change stops the process before anything is applied.

    04

    Dry-run and approve

    The proposed configuration is dry-run first. The responsible reviewer can inspect scope and impact before an approved change reaches the Inbox.

    05

    Enforce and evidence

    The deterministic runtime evaluates the approved model for each applicable message and records decisions, actions, outcomes, and exceptions for review.

    Deterministic at runtime

    One governed decision path for people, systems, and agents

    Once approved, the operating model is evaluated when a business message arrives. AI may interpret or propose inside its permitted scope, while rules decide which context is available, which result is acceptable, and which next action may occur.

    Business message
    Contract and context
    Applicable policy
    Permitted decision
    Result and evidence

    Start with one operating decision

    Choose one high-value message flow. Model its context, authority, policy, permitted actions, and evidence, then expand from a controlled foundation.