AI agents and MCP
Artificial intelligence that does not decide for you
Workly's agents approve leave requests according to the policies you configure, flag attendance anomalies and answer questions in natural language. The difference from a generic AI assistant: the decision belongs to YOUR rule, auditable, while the language model only understands the question and drafts the answer. Opt-in module, with a switch at every level.
Who decides, when an agent decides
The European regulation on artificial intelligence requires AI systems used in worker management to be explainable and subject to human oversight. In Workly the decision belongs to the policy you configured: every agent decision keeps the rule applied and its parameters, and the employee can request human review of any rejection. The language model does not decide — it drafts.
The agents and the limits of each
The leave agent approves by your rules
You configure the policies — minimum notice, team overlap, available balance, blocked periods. When a request is submitted, the agent applies the rule and approves or rejects on the spot. This is not a model's estimate: it is your policy, executed consistently.
- Policies configurable per company
- Instant decision when the request is submitted
- A challenge sends the request to a human
The attendance agent flags, it does not block
It scans attendance every night against six anomaly rules, with thresholds you set, and flags a clock-in on an approved leave day instantly. What it finds are suggestions to review — they do not stop attendance and they penalise no one.
- Six anomaly rules, thresholds per company
- Clock-in on a leave day, flagged instantly
- Suggestions to review, with no blocking
A conversational assistant on your data
You ask in natural language, and the answer is built from your company's real data through tools that carry permissions. The security layer is the tools, not the instruction given to the model: each person sees only what they are allowed to see, and sensitive data is masked before it leaves the server.
- Answers built from real data
- Permissions live in the tools, not in the prompt
- Sensitive data masked server-side
Write actions require a human confirmation
When an agent proposes an action — an approval, an email — you get a card with a button. Nothing runs without your click, and execution goes through the same checks as the operation performed by hand. For email, exactly the text in the box is sent, and you can edit it.
- The model proposes, the human confirms
- Execution goes through normal authorisation
- The email text stays editable
MCP connectors — your data, in your assistant
You issue a token yourself from the application and connect your preferred AI assistant to Workly data through the MCP protocol. The connector is personal and READ-ONLY by construction: write tools are not exposed at all, and the assistant sees only what you are allowed to see in the application.
- A personal token, issued by you (up to 3)
- Read only — write tools are never exposed
- Runs with your real permissions
A daily summary for managers
Once you enable it, every morning each manager receives their team's activity from yesterday: hours, absences, today's leave, their approval queues and the attendance agent's signals. The figures come from the database; the model drafts only the opening sentence — if it is unavailable, the summary goes out all the same.
- Figures from the database, not from the model
- Hours, absences, approval queues, anomalies
- Nothing is sent on a day with no content
A generic AI assistant vs. Workly's agents
Generic AI assistant
- The model decides, and the reason stays in a black box
- It answers from what it learned, so it can invent a figure
- It sees everything it was given access to, whatever your role
- Actions go out directly, without confirmation
- You can only stop it by switching everything off
Workly agents
- Your rule decides, and it is kept on every decision
- Figures come from the database; the model only drafts
- Tools enforce your real role and mask sensitive data
- Writing requires an explicit human confirmation
- A separate switch per company, agent, channel, action and person
Frequently asked questions
Can the agent reject a request without anyone seeing it?
The decision belongs to the policy you configured, and every decision records the rule applied and its parameters. The employee can challenge any rejection, and the challenge moves the request into a human queue. The feedback of the person who resolves it is saved on the decision, so you can see whether your policy is working.
What data reaches the model provider?
Only what is needed for the question asked, after server-side masking. The medical fields of sick leave — diagnosis, certificate series, indemnity code — are not exposed to the tools at all. Logs keep truncated text, and the MCP connector audit stores a fingerprint of the arguments, not their content.
How do I stop it if I am not happy with it?
At several independent levels: the module can be switched off per company, each agent has its own switch, the MCP channel is off by default and must be enabled explicitly, write actions are disabled individually, and an administrator can block connector issuance for a specific person. The deterministic Modi assistant keeps working in every case.
What happens to the connector of someone who leaves the company?
Deactivating the account cascades to deactivate that person's connectors. They are not deleted, so they remain visible for governance, and reactivating the account does not revive them. On top of that, a token untouched for 90 days expires on its own.
Does Modi still exist?
Yes, and it stays deterministic. Modi answers as before, from your company's rules and data, with no external model. When it is not confident about a question, it offers you a button through to the AI assistant — the escalation is your choice, not a classifier's decision.
Built for HR data, not for demos
Explainable decisions
Every agent decision keeps the rule applied and its parameters, and the employee can request human review of any rejection.
Minimisation and retention
Medical fields are never exposed, logs are kept truncated, and prompt logs are deleted automatically after the configured period.
Off until you switch it on
An opt-in module; the MCP channel and the daily summary are off by default, with an independent switch at every level.
Related modules
Want to see what an explainable decision looks like?
We will show you the agents running on your own policies, in a short demo.
Request a demo