Governed AI tools for the systems your business already runs on. Create a service catalog of AI prompts and scripts your team can run with one click. Fully role-based with cost tracking and audit trail — everything you need to put AI tools, connected to your core back office systems, in front of staff and clients. You build the AI service items, your users run them on a secure platform with one click.
| Feature | Netridium Business | Netridium Enterprise |
|---|---|---|
| AI authoring | ||
| Prompt (natural language)Describe the outcome in plain English. The AI pulls from your connected systems, works out the steps, and returns the result in one pass. | ✓ | ✓ |
| AgentGive it a goal instead of instructions. It plans its own steps, works until the goal is met, and checks its result against the objective before returning it. | — | ✓ |
| LogicScript Portal LanguageWrite the process as structured LSPL — explicit steps, branches, validation — that the AI executes in order. Repeatable, and it reads the same to any two people. | — | ✓ |
| Python scriptsDeterministic control for exact calculations and logic the AI should not improvise. Runs in a secret-less sandbox and can call the model where you want judgement. | — | ✓ |
| AI service catalog | ||
| Published service catalogA searchable list of the AI tools your organization has approved, grouped into folders and pinnable per user. Each person sees only the items their role allows. | ✓ | ✓ |
| One-click fulfilmentUsers run a finished tool from a single button — no prompt writing, no training, no model logins to hand out. | ✓ | ✓ |
| Customizable request formsAttach a short typed form to any item — dates, numbers, dropdowns, free text. Values are validated in the browser, at submit, and again in the engine. | ✓ | ✓ |
| Unattended schedulingGive an item several named schedules — daily, weekly, or monthly in the timezone you choose — each enabled independently, with the next run time shown and results emailed on completion. | ✓ | ✓ |
| Report-grade outputResults come back as Excel workbooks, print-ready PDF, formatted HTML, charts, plain text, or raw JSON. | ✓ | ✓ |
| Model-authored documentsLet the model build the deliverable itself — a live-formula Excel workbook, a filled Word template, a PowerPoint deck — inside your own AI account. | — | ✓ |
| Background run queueRuns process asynchronously with live status that survives navigating away, and can be cancelled mid-flight. | ✓ | ✓ |
| Access-controlled sharingShare a finished report by email. The link opens a viewer the recipient must sign in to reach, never a raw file. | ✓ | ✓ |
| Run history & CSV exportEvery run is kept with its inputs, result, and cost, ready to re-open, re-run, audit, or export. | ✓ | ✓ |
| Identity & access | ||
| SAML 2.0 single sign-onYour team signs in with the identity provider you already run — Okta, Entra ID, Ping, or any SAML 2.0 IdP. | — | ✓ |
| Granular RBACRoles carry per-item permission, separating who can see a Service Item from who can run it. | ✓ | ✓ |
| Enforceable MFARequire an authenticator code from everyone reaching the workspace, with a members list showing who is already covered before you switch it on. Any user can enrol from their own profile on any plan. | ✓ | ✓ |
| Screened passwordsServer-enforced 12-character minimum, checked against a public breach corpus, and never the account's own name or email. | ✓ | ✓ |
| Membership approvalNew members wait for an admin to approve them and assign a role before they can reach anything. | ✓ | ✓ |
| Separation of dutiesThe person who authors a tool is not the person who runs it. Builders and runners are distinct seats with distinct permissions. | ✓ | ✓ |
| IT financial management | ||
| ShowbackEvery run records token usage and billable cost, rolled up by day, folder, Service Item, user, and cost center — visibility without an internal invoice. | ✓ | ✓ |
| ChargebackThose same figures reconcile to your Netridium invoice, so AI spend can be recharged to the team, department, or client that incurred it. | ✓ | ✓ |
| Cost centersTag Service Items to attribute spend. Attribution is snapshotted at run time, so re-tagging an item never moves historical cost. | — | ✓ |
| Monthly budgetsCap a calendar month's spend for the workspace and per cost center. Runs are refused at the ceiling, and an admitted run is clamped to what is left rather than overshooting. | — | ✓ |
| Per-run limitsOptional ceilings on cost, connector calls, and duration — a workspace default, overridable per item. Enforced during the run, not audited after it, and they fail closed. | — | ✓ |
| Four AI model tiersRoute quick jobs to a fast, low-cost model and hard jobs to a frontier model, per item. Tiers are curated aliases, so they move to newer models without touching your catalog. | — | ✓ |
| Batch modeRun eligible jobs at roughly half the cost when speed is not critical. | ✓ | ✓ |
| Usage creditsBuy blocks of usage that renew each billing period against the card on file, with full or prorated first periods. | ✓ | ✓ |
| Bring your own AI keyRun a workspace entirely on its own Anthropic key, so spend and data flow stay under its control and are billed direct. | — | ✓ |
| Data sources | ||
| Back-office connectorsNetSuite, Salesforce, Xero, QuickBooks Online, Maxio, and HubSpot — depth in finance and operations rather than shallow reach across hundreds of apps. | ✓ | ✓ |
| Open MCP standardConnectors speak the open Model Context Protocol, so anything that exposes an MCP endpoint can be added without waiting on our roadmap. | ✓ | ✓ |
| One-click OAuthMost connectors authorize through the provider's own login. There are no API keys to copy, distribute, or rotate. | ✓ | ✓ |
| Sandbox vs productionSalesforce and QuickBooks connections require an explicit environment choice with no default, badged on the card, so test data is never mistaken for live. | ✓ | ✓ |
| Read-only by defaultA connector cannot change anything until an admin turns updates on. Least privilege is the shipping state, not a setting you have to remember. | ✓ | ✓ |
| Dual-authorized write-backWriting to a system of record needs updates enabled on both the item and the connector, plus your own AI key and a cost and duration ceiling. Every write-enabled run confirms first. | — | ✓ |
| Per-workspace credentialsEach workspace authorizes its own accounts. Credentials are never pooled or shared across workspaces. | ✓ | ✓ |
| Audit & data protection | ||
| Complete audit trailEvery run, connector write, and admin change is recorded, filterable by date and exportable to CSV. | ✓ | ✓ |
| AES-256-GCM at restConnector credentials and AI keys are encrypted at rest with an application-layer key and never returned to the browser. | ✓ | ✓ |
| SSRF-guarded egressOutbound calls are checked against an approved host allowlist and blocked from internal, loopback, and cloud-metadata addresses. | ✓ | ✓ |
| Multi-tenant isolationEvery workspace's data is isolated at the database level, eliminating cross-tenant leakage. | ✓ | ✓ |
| Runaway spend safeguardsNetridium-operated daily ceilings warn and then auto-pause a runaway workspace, behind a platform-wide circuit breaker. | ✓ | ✓ |
| Multi-tenancy & the channel | ||
| Workspace isolationEach client is a fully isolated workspace with its own data, connectors, tools, users, and results. | ✓ | ✓ |
| Client Manager consoleManage all client workspaces, staff, and invitations from a single console. | ✓ | ✓ |
| Build once, deliver to manyAuthor a tool once and distribute it across client workspaces. | ✓ | ✓ |
| Per-client controlsEach client carries its own settings, branding, AI key, notification policy, and grants. | ✓ | ✓ |
| Staff & invitationsInvite staff and client users by email, assign roles, and require approval where needed. | ✓ | ✓ |
Stand up a secure, multi-tenant portal for your prompts, scripts, and agents in under an hour.