DISPATCH · ONE SYSTEM
policy first.
approval at the boundary.
LumenFlow is one control plane for AI agent work: what’s allowed, where a human signs off, and what evidence is left behind — wherever the work actually runs.
One system, three layers
Wherever the agent and wherever the compute, the same policy, approval, and evidence pipeline sits in the middle.
AI / Agents
LumenFlow
Compute / Tools
Policy flows down · Evidence flows up
GovernPolicy before execution.
Scope, spend limits, and quality gates are set before an agent touches anything. The control plane decides what's allowed — it isn't just told what happened afterward.
ApproveHumans stay in control when risk crosses a boundary.
Routine work keeps moving without friction. The moment an action crosses a policy boundary — spend, data access, a production change — it pauses for the person who owns that decision.
ExecuteRun through Sidekick, external agents, or connected compute.
Work happens wherever it makes sense: Sidekick's chat and playground, connected runtimes like Claude Code, Codex, Cursor, and MCP clients, or compute you connect yourself. The same policy and evidence layer wraps all of it.
ProveAn independently inspectable evidence trail.
Every governed action leaves a hash-chained, per-workspace sealed evidence record — what happened, why it was allowed, and who approved it — ready to export and inspect.
Every important decision
should be legible.
Teams need more than a successful run. They need to know why a change was allowed, what evidence was attached, and whether a person was asked to approve it along the way.
Agents you already run, governed the same way
Sidekick is LumenFlow’s own client. Everything below is someone else’s client, connected in as a governed runtime.
Claude Code
Connected runtimeAnthropic's coding agent, enrolled as a connected runtime that reports sessions, events, and evidence back to your workspace.
Codex
Connected runtimeOpenAI's coding agent connects the same way — through the control-plane SDK, under the same policy and evidence layer.
Cursor
Connected runtimeThe Cursor IDE agent enrolls as a connected runtime, so its work is governed and evidenced like any other.
MCP clients
Open protocolAny Model Context Protocol–compatible tool works inside LumenFlow governance without a custom integration.
ChatGPT
OpenAI Apps pilot pathA client start-point for approved delivery review — a pilot path today, not the governance owner.
Each tour starts with a real product surface.
Pick a motion, then compare the same task with and without LumenFlow.
Your AI just booked a $400 flight.
Who approved that?
Sidekick handles everyday tasks — travel, expenses, scheduling. Without governance, you have no idea what it accessed or spent.

Real Sidekick chat surface with the consumer-first entry and the governed workspace shell.
Captured from the real app in a local seeded workspace
The task completes, but nobody can reconstruct what happened or why it was allowed.
14:02:01
searching flights LAX → JFK
14:02:08
found 3 options, selecting cheapest
14:02:12
accessing payment method ending 4829
14:02:14
booking confirmed — $412.00 charged
14:02:15
calendar event created
14:02:16
done
No approval. No budget check. No receipt.
Policy, approvals, and evidence stay attached to the work all the way through completion.
task/booking scope-boundary verified
budget-gate: $412 within $500 trip limit
payment $412 → owner approval required
@you approved via notification
receipt attached: booking + payment + calendar
Budget checked. You approved. Evidence yours.
Use the same scenario with Sidekick in public.
These public scenarios are real anonymous Sidekick runs in a hosted sandbox environment: sandbox-only sample data, live runtime artifacts, and no external writes. Pick one that matches the motion you are touring right now.
Everything above works locally.
Cloud makes it a team’s system.
LumenFlow Cloud is the hosted layer that distributes policy, manages approvals, and retains evidence for a whole team instead of one machine.
Policy distribution
Publish and inspect the rules that determine what agent work is allowed before risky actions happen.
Approvals and signals
Coordinate operator checkpoints, escalation paths, and workflow steering from one hosted system.
Evidence retention and export
Keep receipts, traces, and audit data long enough to support debugging, compliance, and executive reporting.
Every AI action should be legible.
One workspace. Policy, approvals, and evidence from day one. No credit card required.