Anyone builds the agent they need. You approve every action it takes. Everything is on the record.
Not because the models aren't good enough. Because the tools never make it past a security review. Or they clear it, and nobody wants to use them. So AI keeps running in the shadows, on personal accounts, outside your visibility.
Gartner says the root cause is treating agent governance as all-or-nothing: lock everything down and delivery stalls; leave it open and you get an incident.
Source: Gartner · enterprise AI adoption research
Three teams. Three agents running overnight. Three different ways the morning starts.
Marketing opens Slack to a ranked list of yesterday's new leads, scored by fit, with a one-line note on why each one is worth a call.
lead-scoring
Daily · runs at 7:30 AM
Pull yesterday's new leads
HubSpot · contacts · last 24h
Score each lead on fit, intent, account size
Read prior engagements per lead
HubSpot · last 30 days
Rank, draft a one-line 'why call' note
Post ranked list
Slack · #marketing-leads
Everywhere else, these are two systems and two teams. The builders pick a tool IT hasn't approved. IT buys a governance layer nobody wants to build in. The gap between them is where enterprise AI goes to die.
In Lunen there is one path. The same flow that lets someone in accounting describe an agent in plain language is the flow that scopes its data, sets its permissions, and logs its actions. Easy is not the opposite of governed. In Lunen they are the same motion.
Describe the agent. Watch the plan write itself.
No drag-and-drop builder. No YAML to learn. A subject-matter expert types what they want in plain language; Lunen drafts a structured execution plan with named tools, scoped data, and a clear schedule. Review it, save it, run it.
Pull closed-lost deals
HubSpot · deals · last 7 days
Fetch deal notes & call logs
HubSpot · engagements
Cluster objections, draft digest
Post digest to #revops
Slack · #revops
Designed to be defended in a security review.
Every MCP tool becomes a policy decision. Allow it to run unattended, or require a human approval before each call. The same toggles cover every agent and every ad-hoc run, so nothing reaches production data without the rule you set.
HubSpot Remote MCP
com.hubspot/remote-mcp-server
Runs unattended. The agent calls the tool with no human in the loop.
Pauses for a human OK on every call. The reviewer sees the inputs before it runs.
crm_search
Search records across deals, contacts, companies, and tickets
get_campaign_analytics
Get METRICS or REVENUE_ATTRIBUTION for one or more campaigns
crm_create_object
Create deals, contacts, companies, or custom CRM objects
crm_update_object
Update properties on an existing CRM object
create_engagement
Log a call, email, meeting, note, or task on a record
User actions and agent actions roll up in the same audit log. Open any event to see who acted, what was approved, what model ran, and which data it touched. Everything a security review needs, exported on demand.
Monday, May 4, 2026
9:00 AM
Executed MCP tool crm_create_object.
Event summary
Executed MCP tool crm_create_object.
Lunen comes out of REDspace, where we have spent 25+ years building and running enterprise platforms for some of the largest media and technology companies in the world. We built Lunen because we kept watching the same thing happen: AI projects that worked in a demo and died in a security review.
We know what your environment actually looks like, because we have been deploying into it for two decades.
We're working directly with a small group of design partners to shape Lunen. Sign up and we'll schedule a call to understand your AI adoption challenges. No pitch deck, just a conversation.