One platform across departments, brands and countries — administered by you.
A bank, a telco, an insurer, a retail group: many departments, several brands, existing core systems, a security team with a checklist, and thousands of staff running processes across a dozen tools. flow is built for that estate — one system for the processes, the relationships and the communication, connected to the core systems it hasn't replaced yet.
Tenancy, identity, integration and control — designed in, not added later.
Multi-tenant estate
Departments, brands, subsidiaries and countries as tenants with their own data boundary, components, policies, languages and users — under one administration tree. Cross-tenant views only where you grant them.
Enterprise identity
SSO via SAML or OIDC, SCIM provisioning, MFA enforcement, role-based permissions to field level. Build permission, policy ownership, approval and administration are separate roles.
Integration with what's there
Core banking, policy administration, OSS/BSS, ERP, CRM, HRIS, field service, data warehouse. Each one becomes a component with a contract: what agents may read, what they may write, under which limits.
Control and evidence
Complete audit log, policy versioning, simulation before change, SIEM export, retention per record type. Evidence packs for internal audit and regulators from the log itself.
- Meridian Group · administration, SSO, audit
- Retail bank · 1,200 seats · WhatsApp, voice, IDV, fraud, core
- Contact center · 900 · autonomous + approve modes
- Branches · 300 · assist mode, appointment desk
- Cards · 340 seats · disputes, fraud alerts, collections
- Insurance subsidiary · 260 seats · claims, policy service
- Cyprus branch · 90 seats · EN/EL · EU residency
- Employee desk · 6,800 employees · HR self-service
Each department runs its own tenant. The group sees the whole.
Tenants inherit group policies and can tighten them, never loosen. Components are certified once at group level and switched on per tenant. Data residency and model routing are set per tenant, so a foreign branch can run in its own region with its own rules.
- Group-level policy baselines with tenant-level restrictions
- Component certification once; enablement per tenant with limits
- Residency and inference region per tenant
- Group dashboards across tenants where permitted
- Employee desk as its own tenant, with HRIS as the record
Every department is a developer — inside the guardrails IT sets.
The build tooling is available per tenant with a build role. A department describes the screen, report or automation it needs; flow builds it within that tenant, with the platform's tests and a review gate that IT configures — automatic for low-risk changes, human for anything touching write tools or policy.
- Review gates configurable per change class
- Generated capability uses only certified components and the tenant's permissions
- Version history, attribution and rollback per tenant
- Group can promote a department's capability to other tenants
Shared cloud, private cloud, or inside your boundary.
Shared cloud
Multi-tenant flow cloud with tenant isolation, encryption, regional hosting and Claude inference from our cloud. Fastest to start; typical for SMB-through-partner and mid-size deployments.
WeeksPrivate cloud
Dedicated environment in the region you choose, with your model contract or ours, VPC peering to your systems, and your key management. Typical for banks and insurers.
ProgramDedicated / on your infrastructure
flow deployed inside your boundary, including model inference, with your operations team or a partner running it under our support. For sovereign and highly regulated estates.
ProgramHow a large deployment runs.
Discovery & controls
Request catalog, identity levels, policy cards, component list, residency and model routing. Security review starts here, not at the end.
Foundation tenant
Channels, identity, record sync, communication center for one department. Agents in shadow mode, measured against people.
Modes go live
Autonomous for low-risk requests, approve for the rest. Simulation on history before each policy change. Handover with drafts everywhere.
Estate rollout
Departments and brands added as tenants with inherited baselines. Department teams start building. Partners take over run and expansion.
Start with the department that has the longest queue.
We'll design the tenant, the policy cards and the rollout with you and your partner — and bring the security documentation to the first meeting.