02 / IN PRACTICE

Keep your CRM, add the decision record

GembaOS is a zero-trust governance runtime for enterprise AI agents: policy-decided access, single-use clearance tokens bound to exact parameters, and accountable human approvals, running on-premises or in a private VPC. This scenario is the existing-CRM case: the CRM stays the system of record for accounts and cases, and GembaOS holds the decision record for what happens beyond it.

How do we keep our CRM and its agent, and still own the decision?

GembaOS leaves the CRM as the system of record and puts itself only where an action leaves the CRM: it reads the case under field-level rules through the capability gateway, composes the cross-system action, routes it by policy, and after the signature executes it once under a clearance token. The decision goes back to the case timeline as a comment, so the CRM shows what happened and GembaOS shows who decided and why.

BeforeWith GembaOS
Routine closureThe CRM agent closes the caseStill passes, on the agent stamps, and is recorded
Escalated or legal-hold caseClosed by whoever has the buttonStops at the CS supervisor, who signs with a passkey outside the vendor
The action beyond the CRMA refund or credit note with no accountable ownerExecuted once, under a clearance bound to this case and this reason
The recordLives with the vendor, in the vendor’s formatThe signature chain and the replayable decision live with you; the CRM gets a comment

What happens, step by step?

StepWhoWhat is recorded
1. Case eventThe CRM or its agent calls GembaOSThe event and its external reference
2. Pre-readThe host reads the case, trimmed to the fields the specialist may seeThe facts on the request
3. RouteThe policy: routine passes, escalated or legal hold needs a personThe route and the rule chain
4. SignThe CS supervisor with a passkeyThe signature chain
5. ExecuteThe host re-reads the case, compares, then closes it once under the clearanceThe precondition check and the execution
6. MirrorThe decision is written back to the case as a commentThe external reference of the comment

Where is the control point?

The control point is the route decision on the pre-read facts, and the human signature for the cases the policy reserves. The CRM agent, the vendor’s own or yours, can call the same gateway the same way; what it cannot do is close an escalated case or move money on its own authority. The same pack serves several CRM wire shapes; the field names and the id formats are the only parts that change between vendors.

What does it look like in the console?

GembaOS approval desk showing an escalated CRM case closure awaiting the CS supervisor
GembaOS approval desk showing an escalated CRM case closure awaiting the CS supervisor

GembaOS work item timeline showing the case re-read, closed once and mirrored back to the CRM
GembaOS work item timeline showing the case re-read, closed once and mirrored back to the CRM

GembaOS audit view replaying the decision records for the case closure
GembaOS audit view replaying the decision records for the case closure

What do we need to start?

Related: refunds and claims, security and deployment, the FAQ.

Last updated: · GembaOS v0.2