Agentic automation

Enterprise AI agents that work alongside your robots

Run Python AI agents on governed Windows Robots today, with managed agents, tool approvals and guardrails in beta. One platform for agents, RPA and the controls around them.

Request a demo Read the Python agent tutorial

How VeloPhex runs agentic automation

VeloPhex runs AI agents and deterministic robots on one governed platform: agents reason, robots act, and Orchestrator controls credentials, approvals, limits and the audit trail. New to the idea? Read what agentic automation is.

Rules-based RPA is still the right tool when every step is known. Agents earn their place where the input is unstructured or the next step needs judgement: reading an email, choosing a resolution, drafting a reply. Most real processes need both, which is why VeloPhex treats them as one lifecycle instead of two products.

Available now

Run AI agents on governed Robots today

Any agent you can write in Python runs as a VeloPhex automation, with the same packaging, identity and audit as your RPA.

Your agent framework

LangChain, LangGraph, CrewAI or the OpenAI and Anthropic SDKs, pinned in a uv lock file and installed in an isolated environment per package.

Keys from the vault

Model keys and system credentials are redeemed at run time from Orchestrator or your own vault, never written into code or config.

Queues and triggers

Feed agents from work queues, schedules, webhooks or API calls, with retries and business errors handled like any other job.

Contained execution

Each run is a separate process inside a Windows Job Object with memory and process limits, under a run-as account you choose.

Signed, versioned packages

Agents ship as packages that are hashed, can be signed and are verified by the Robot before anything runs.

One audit trail

Every job, secret read and change is recorded alongside your RPA, in the same Orchestrator.

Python agents

An AI step in twenty lines of Python

This automation claims support emails from a queue, asks a model to classify each one and records the result. The model key is leased from the vault for this job only. Swap in LangGraph or CrewAI for multi-step agents; packaging, scheduling and audit stay the same.

  • Typed inputs and outputs from type hints
  • Queue items, secrets and assets from the runtime client
  • Runs locally with velophex run before you publish
Python SDK
import anthropic
import velophex
from velophex import runtime


@velophex.entrypoint(id="triage")
def run(model: str = "claude-sonnet-5-5") -> dict[str, int]:
    # The key comes from the Orchestrator vault, leased for this job only.
    client = anthropic.Anthropic(api_key=runtime.secret("AnthropicApiKey"))
    routed = 0
    while not runtime.stop_requested():
        item = runtime.claim_queue_item("SupportEmails")
        if item is None:
            break
        reply = client.messages.create(
            model=model, max_tokens=300,
            system="Classify the email as billing, outage or other. Reply with one word.",
            messages=[{"role": "user", "content": item.payload["body"]}],
        )
        runtime.complete_queue_item(item.id, output={"label": reply.content[0].text.strip().lower()})
        routed += 1
    return {"routed": routed}

Beta

Managed agents with guardrails built in

The VeloPhex Agents service runs on a preview Orchestrator and is open to Design Partners. It moves the controls out of agent code and into the platform.

See the roadmap

Approvals for tool calls

Mark a tool as needing approval and the run pauses until a person approves that single call. Each approval can be used once.

Limits per run

Caps on model calls, tokens and time for every run, plus capacity limits per agent and tenant.

Prompt-injection fencing

Tool output and retrieved documents reach the model as untrusted data, and calls outside the run's grant are refused.

Bring your own model

OpenAI, Azure OpenAI, Anthropic or an OpenAI-compatible endpoint such as Ollama or vLLM, behind one AI gateway with budgets.

Tools: robots, MCP and APIs

Published automations, MCP servers, HTTP calls, vector search and human tasks, each inside an allow-list.

Evaluations and traces

Score versions against datasets before publishing, and trace every model call, tool call and approval in a run.

Compare

RPA, AI agents or both?

Choose by the kind of work, not by the technology.

RPA robotsAI agentsAgentic automation on VeloPhex
Best forKnown, repeatable stepsUnstructured input and judgement callsEnd-to-end processes that need both
How it decidesRules you writeA model choosing the next stepAgents decide, robots execute, people approve
PredictabilitySame input, same resultVaries; needs limits and evaluationBounded by grants, limits and approvals
GovernanceCredentials, audit, RBACOften left to the agent codeOne vault, audit trail and RBAC for both
Where it runsWindows RobotsWherever the code is deployedWindows Robots and Orchestrator, on-premises or cloud

Agentic automation questions

What makes VeloPhex an agentic automation platform?

It runs AI agents, which decide the next step and call tools, together with deterministic robots, and governs both: credentials, approvals, limits, audit and deployment. Python AI agents run on Robots today; managed agents with approvals and guardrails are in beta.

Can I run LangChain, CrewAI or OpenAI SDK agents on VeloPhex?

Yes. A VeloPhex Python automation can depend on any PyPI package that ships a wheel, pinned in a uv lock file. The Robot builds an isolated environment per package, so LangChain, LangGraph, CrewAI or the OpenAI and Anthropic SDKs run like any other dependency.

How do agents get API keys and credentials?

Through the runtime client. Your code asks for a secret or credential by name and the Robot redeems it from Orchestrator, or from Azure Key Vault, HashiCorp Vault, AWS or GCP, for that job only. Keys never sit in the package.

What is in beta?

The managed Agents service: agent definitions and versions, approvals for tool calls, per-run limits, the bring-your-own-model AI gateway, MCP tools, vector search, evaluations and traces. It runs on a preview Orchestrator and is open to Design Partners.

Is VeloPhex still an RPA platform?

Yes. Studio, Robot and Orchestrator cover attended and unattended RPA on Windows. Agents use the same Robots, packages, queues and audit trail, so you can add AI steps to existing robots instead of running a separate stack.

Which models can I use?

Python agents can call any provider your code supports. The beta AI gateway supports OpenAI, Azure OpenAI, Anthropic and OpenAI-compatible endpoints such as Ollama and vLLM, including models you host yourself.

Read more about AI agents

MCP enterprise security: Model Context Protocol in production

The Model Context Protocol makes it easy to give AI agents tools. That is exactly why it needs controls. What MCP is, the four risks that matter, and the controls that address them.

AI & Agents

VeloPhex Security

Agentic automation vs RPA vs IPA: which fits which work?

RPA follows rules, IPA adds models to fill in the gaps, and agentic automation lets an AI agent choose the steps. Three worked examples show where each one belongs.

VeloPhex Product

Human in the loop AI agents: designing approvals that hold up

Approvals are the most effective control for AI agents, and the easiest to get wrong. Which tool calls need one, why each approval should be single-use, how timeouts behave, and what auditors will ask for.

Try governed agents on your own process

Join the Design Partner program for beta access to managed agents, or book a technical session.

Become a Design Partner Request a demo