Not RPA.Not a generic AI agent.
RPA is brittle and can't read an inbox. A generic AI agent improvises and leaves you a transcript, not a defensible record. XY Space is the regulated middle: the flexibility of an agent with the control of a mapped, audited process.
XY Space — Reads email, scans and photos the way a person does
Generic AI agent — Often, but nothing stops it acting on a bad read
RPA — Needs the input pre-structured before it starts
XY Space — Every job follows a workflow you mapped and approved
Generic AI agent — It improvises a new path most runs
RPA — Only the exact script it was given, nothing more
XY Space — A hash-chained ledger, entry by entry, exportable
Generic AI agent — A chat transcript: readable, not verifiable
RPA — Action logs capture what ran, not why
XY Space — Every number traces to a versioned rule you own
Generic AI agent — The reasoning is a black box
RPA — Doesn't apply: it moves data without reasoning about it
XY Space — Sensitive steps wait for a named approver by default
Generic AI agent — Rarely built in. Most ship with no approval chain at all
RPA — Can pause for input, but can't weigh a judgment call
XY Space — Piloted under supervision, never sold as finished
Generic AI agent — Sometimes, with nothing stopping a wrong click
RPA — By design, though brittle the moment the screen changes
Where each one earns it.Where it runs out of road.
None of these three are bad tools. Robotic process automation, generic AI agents and iPaaS all earn their keep somewhere. This page is about where that stops for the work we build: regulated back-office processes with a name attached to every decision.
RPA: UiPath, Blue Prism
High-volume, structured processes: the same click-path, run thousands of times, across screens that don't change underneath it. For pure repetition, it's fast to deploy and hard to beat on unit cost.
It scripts fixed clicks against fixed screens. Move a button or change a login flow, and the bot either stops or, worse, keeps going against the wrong field. It also can't open a shared inbox and work out which of a dozen request types just arrived. Every path has to be structured in advance, before the bot ever runs.
We start from the same inbox your team already works. We work out what a message is and how confident we are in that read, then run the mapped steps. A changed screen becomes a judgment call the system can flag, not a silent failure.
Generic AI agents
One-off research, exploratory browsing, a single person moving faster through ad-hoc work. Nothing has to be mapped in advance, because nothing is meant to repeat the same way twice.
An agent decides its next move as it goes, so the same request can take a different path on Tuesday than it took on Monday. What you're left with afterward is a chat transcript: readable, but not something you can hand a reviewer as proof of what happened or why.
Every job runs a workflow we mapped and approved before it ever went live, the same way every time. A named person gates the sensitive steps, and each one lands its own ledger entry.
iPaaS: Zapier, Make, Workato
Wiring modern SaaS together fast: when X happens in one app, do Y in another. Thousands of connectors, live in minutes, cheap for straightforward data-passing between systems that both speak API.
It needs an API on both ends of every step. The systems a regulated back office actually runs on, legacy policy admin, case management, practice systems, either have no usable API or gate it behind a partner programme. The connector chain reaches right up to the moment of real work, then stops.
We're built for the last mile iPaaS can't reach: reasoning over an unstructured inbox, and operating a system of record directly, under supervision, when there's no API to call.
Book a discovery call.Bring the process; leave with the map.
Start with your people or with the work. One job at a time, on probation, measured in hours and money. Everything we build stays yours.