Padoflow

How it works

An agent that touches your mail and your books has to be easy to check. That shapes most of how Padoflow is built.

Fig. 1Who talks to what. Facts move from your systems toward you; plans go the other way.
People Plans and writes Reads and checks MCP connectors Your systems
Youask, review, decide
Coordinatorplans the job, reads findings, writes what you see. No access to your systems.
Workersone per job. Read-only queries, evidence saved.
Mailreads, writes drafts only
Filesreads, adds new files
ERPread-only
Databaseread-only
Mail server
Shared drive
ERP system
SQL database
The recordoriginals as they arrived · one page per topic · a log entry for every run

hand-offs between you and the agentsreads from your systems

Built on Claude

Padoflow’s agents run on Claude, the AI model made by Anthropic. Claude reads the mail, the documents and the ledger, and writes the drafts and notes you review.

Coordinator and workers

Work is split in two. The coordinator plans a job, reads what comes back and writes what you see. It never queries your systems itself.

Workers do the querying. Each one gets a written plan, runs read-only queries, saves what it found as evidence and reports back with a conclusion, at most three lines of reasons, and where the evidence is kept. A finding without a conclusion isn’t accepted.

Connectors

Agents reach your mail, files and ERP through MCP (Model Context Protocol) connectors. Each connector exposes only what its job needs. ERP and database connectors are read-only, and every query carries a date range and a row limit, so a check never slows down the system your team is working in.

The record

Originals are kept exactly as they arrived and are never edited. Each topic has one page that holds the current facts, and every run adds a short log entry: what came in, what was done, what is waiting for a person.

People decide

Agents read and draft. People send, sign and post. The model decides what something is; anything that can’t be undone, such as moving mail once a reply has gone out, is done by a plain script with its own checks.

Quiet by default

Before an agent is woken, a small check counts what is new. If nothing is, the model isn’t called at all.

Credentials

Passwords and keys stay in a local secrets file on your side. They never appear in chats, logs or commits. When a step needs an admin permission the agent doesn’t have, it stops and asks. It doesn’t look for a way around.

Your data

We use your data only to do the work you ask for. We do not use it to train models.

Example setup

Padoflow connects to the systems a company already has. One way it can be set up: Outlook for mail, SAP S/4HANA as the ERP (read-only), a Microsoft SQL Server database (read-only), Google BigQuery for reporting, and Excel, PowerPoint and Word files on a shared drive.