Leena AI
Also known as: AI Colleagues, WorkLM
Enterprise agentic platform whose AI Colleagues are persistent digital workers with named job roles, each grounded in a plain-English operating protocol, acting across 200+ enterprise systems under guardrails enforced before execution and permissions inherited from the customer's identity provider.
Leena AI is an enterprise agentic platform for the back office, automating internal employee support across HR, IT, finance and procurement for more than 500 enterprises. Its unit of delivery is the AI Colleague: a persistent digital worker assigned an actual job role — IT Operations Coordinator, HR Operations Specialist, Finance Operations Analyst — with its own identity, its own toolset, and a named Human Manager who handles what it escalates. More than 25 ship pre-built across 200+ use cases.
The design principle is that the language model reasons but does not improvise the process. Each Colleague is grounded in an Agent Operating Protocol, a business-process blueprint written in plain English that a business user can author by uploading an existing SOP or describing the work conversationally. An Orchestrator reads each incoming request, builds a plan rather than following a pre-coded one, breaks it into subtasks, dispatches them to the right Colleagues and hands off between them. It routes across Claude Opus 4.8, WorkLM, GPT-5.5, Llama 4 and Gemini 3.5, picking a model per task.
Colleagues act through 200+ pre-built connectors and 1,000+ deterministic tools into Workday, SAP, ServiceNow, Salesforce and the rest of the stack, falling back to browser-based skills where no API exists. An employee who says they have moved can have the address verified against policy and written across several systems with no ticket raised. Colleagues are always on, firing on schedules and system events as well as prompts, and reach people in Teams, Slack, email, voice, browsers and portals with the same memory on every surface.
Governance is structural rather than added: guardrails enforce before execution, permissions inherit from the customer's identity provider so a Colleague can only act where its user could, every action is identity-bound and audit-logged, and a full trace records what the agent did, why and what it read. Certification spans SOC 1 and 2, ISO 27001, 27017, 27018 and 27701, HIPAA and GDPR, with shared, single-tenant and private VPC deployment across 14+ regions. Pricing is quote-only.
Vendor details
Canonical URL
https://leena.ai
Category
Enterprise operations agent
Subcategory
Enterprise IT/HR — agentic employee service
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
200+ pre-built enterprise connectors carrying 1,000+ tools, spanning HRIS (Workday, UKG, BambooHR, ADP), ITSM (ServiceNow, Jira, Zendesk), ERP and finance (SAP, Oracle, Coupa), CRM (Salesforce, HubSpot), content and identity (SharePoint, Confluence, Okta) and data platforms (Snowflake, Databricks). Tools are deterministic — each knows which system it targets, which fields it may change and how to validate the response — and where no API exists, AI Colleagues use browser-based skills to operate the application as a human would. Connectivity runs over APIs, MCP, A2A and browser/RPA, with MCP and A2A also exposed inbound so a customer's own AI can call Leena AI agents. Permissions inherit from the customer's identity provider with no re-mapping, so a Colleague can only act where the user it acts for could.
In practice
An employee messages in Slack that they've moved and need their address updated. Leena AI's agent verifies it against policy and updates it across Workday, payroll, and the directory at once, with no ticket for HR to clear.
Your IT and HR queues are clogged with password resets and policy questions. Leena AI's AI Colleagues resolve those routine requests in real time inside Teams, so staff handle only what truly needs a human.
You won't deploy autonomous agents you can't govern. Leena AI gives you role-based access, policy guardrails, and a full audit trail, with human handoff for sensitive cases like complex leave or complaints.
Sources & related URLs
Agentic Index coverage score
12.0 / 14 capabilities · 86%
| Integrations & Tool Calling | Full |
|---|---|
|
Leena AI's Colleagues write into named enterprise systems through 200+ pre-built connectors carrying 1,000+ tools. The architecture page states "200+ pre-built enterprise connectors" and separately "1000+ pre-built tools across 200+ enterprise systems", so 200+ systems with 1,000+ tools within them. Named systems span six classes: HRIS (Workday, UKG, BambooHR, ADP), ITSM (ServiceNow, Jira, Zendesk), ERP and finance (SAP, Oracle, Coupa), CRM (Salesforce, HubSpot), content and identity (SharePoint, Confluence, Okta), and data platforms (Snowflake, Databricks). The grade rests on execution, not catalog size. AI Colleagues are "equipped with tools to act in enterprise apps", and tools are deterministic: "each one knows exactly what system it is hitting, what fields it can change, and how to validate responses, so there are no hallucinated API calls." The worked example writes a changed address across several systems at once. Where no API exists, browser-based skills operate the app instead, so the action path has a documented fallback rather than a gap. The access model travels with the action: permissions "inherit from your IdP with no re-mapping", Colleagues only see and do what the acting user's role allows across every connected system, and every action is identity-bound. That inheritance counts under security; here it is context for how the writes are authorized. Sourceleena.ai/agentic-ai-architecture and /integrationsread 2026-09-12 |
|
| Workflow Orchestration | Full |
|
Leena AI's Orchestrator builds a plan for each request and hands work between agents inside it, along process rails the customer writes. It reads the request, builds the plan (the vendor's own bullet is "plans are built, not pre-coded"), "breaks complex asks into doable subtasks", calls the right AI Colleague for each, and "hands off cleanly between agents over A2A". That is agent-to-agent handoff inside one plan. The participants are distinct and named: the employee who asks, the Orchestrator that plans, multiple AI Colleagues assigned to specific job roles (IT Operations Coordinator, HR Operations Specialist, Finance Operations Analyst), the Human Manager each Colleague escalates to, and the systems of record the tools act in. The worked example, an address change verified against policy and written across several systems at once with no ticket raised, spans HR, IT and payroll systems in a single request. The sequence is customer-authored, not fixed: Agent Operating Protocols are business-process blueprints written in plain English, AOP Studio writes the process, Workflow Studio wires the tools, and the vendor frames it as "deterministic process rails", with "explicit graphs, the LLM reasons within them, never invents them". Stateful execution with callbacks pauses at approval steps and resumes with full context. Sourceleena.ai/agentic-ai-architecture and /agent-operating-protocol-for-business-process-automationread 2026-09-12 |
|
| Knowledge Grounding & RAG | Full |
|
Leena AI grounds its Colleagues in the customer's own knowledge and keeps that corpus maintained. Grounding runs on the enterprise's specific material, its handbooks, historic tickets and secure knowledge base, with the Knowledge Studio connecting sources including SharePoint, Confluence and ServiceNow and a federated layer spanning HRIS, ITSM and knowledge management systems. Plugging in existing knowledge sources is step one of the documented go-live, with no migration project, so the customer's material is read where it lives rather than copied into a new store. It persists and is maintained: the platform "closes its own knowledge gaps" by mining resolved tickets for information that was missing, so the corpus improves from operational history as well as curation, and a Knowledge Health dashboard reports where grounding is thin. Structured knowledge steps are cited in the hallucination controls, and the FAQ contrasts generic models that hallucinate policy with grounding in the customer's own documents. That is a maintained retrieval structure over the customer's knowledge, persisting between runs and queried on every request, and it scales well past a context window across an enterprise's full policy and ticket estate. Sourceleena.ai/knowledge-management and /agentic-ai-architectureread 2026-09-12 |
|
| Human Oversight & Guardrails | Full |
|
Leena AI documents three distinct oversight controls, each a mechanism rather than a posture. First, pre-execution enforcement: "guardrails at every layer, enforced before execution", so an out-of-policy action is blocked before it touches a downstream system rather than flagged in a later audit. Second, a named human role: "every AI Colleague is assigned a Human Manager" who resolves exceptions and edge cases, and AOPs "explicitly define when to pull humans in", based on risk thresholds, exception patterns or missing data, and when to proceed autonomously, so the boundary is a configured object the customer writes rather than a disposition the vendor asserts. Third, a hold in the runtime: stateful execution with callbacks "pauses at approval steps" and resumes exactly where it left off with full context intact, and escalation carries what has been done, what is blocked and recommended options so the human decides quickly while the Colleague continues. That is a configurable risk-threshold gate, an approval pause and pre-execution blocking together. Hallucination control adds a multi-layer guardrail stack with primary and evaluator LLMs and deterministic tools that cannot issue an unvalidated call. RBAC and permission inheritance are an access surface and count under security. Sourceleena.ai/agentic-ai-architectureread 2026-09-12 |
|
| Security, Identity & Governance | Full |
|
Leena AI pairs a broad attestation set with a permission model that creates no second authority for its agents. Attestations: SOC 1, SOC 2 Type II, ISO/IEC 27001, 27017, 27018 and 27701, HIPAA with BAAs, GDPR, CCPA, LGPD, VCDPA and CSA STAR, with pentest reports and compliance artifacts in a SafeBase trust center and certification badges rendered in the footer of every page. Access: SSO via SAML 2.0 and OAuth, MFA, and RBAC for staff and customer admins, with AES-256-GCM at rest, TLS 1.2+ in transit, AWS KMS-managed keys including bring your own key for regulated workloads with automatic rotation, and encrypted backups. Leena maintains no parallel access model. Permissions "inherit from your IdP with no re-mapping", AI Colleagues "only see and do what their role allows across every system you connect", and if the user cannot access something then neither can the Colleague acting for them, with every action "audit-logged and identity-bound" to the user it was performed for. That answers the agent-specific question, not who can log in but what an autonomous actor may do and on whose authority, by refusing to create a second authority at all. Customer data is never used to train shared models; WorkLM fine-tuning happens on the customer's data for their tenant only, with explicit opt-in. The three deployment models and 14+ regions count under deployment. Sourceleena.ai/platform/enterprise-agentic-ai-trust-security and /platform/permissions-and-access-controlsread 2026-09-12 |
|
| Observability & Auditability | Full |
|
Leena AI publishes a step-by-step trace of each agent's conduct, including its reasoning and the documents it read. The Observability and Governance layer promises a "full trace" of "what the agent did, why, what it read", and the FAQ enumerates "end-to-end trace logs for every prompt, tool call, document, decision, and fallback". Every reasoning step, tool call, source document and policy check is logged, and teams can "drill into any execution" and monitor token usage and latency by step. Fallbacks are logged as well as successes. Attribution is identity-bound: every action is audit-logged and tied to the specific user it was performed on behalf of, so a trace answers who authorized it as well as what happened. Dashboards sit on top for different readers (execs, ops and risk), covering Knowledge Health, Process and SLA Analytics, Cost and Performance Telemetry, and Helpdesk Insights. This is a retained, reconstructable record of the agent's conduct rather than a score explanation or a live activity view. The Eval Suite counts under testing and the guardrails under human oversight; the operational dashboards are context here rather than the grade. Sourceleena.ai/agentic-ai-architecture and /platform/ai-observability-and-governanceread 2026-09-12 |
|
| Memory & State Persistence | Partial |
|
Leena AI documents a named memory layer whose scope is stated but whose lifetime is not. Context Graph and Memory is listed in the site's architecture navigation alongside the Orchestrator and the Studios. The FAQ describes the Context Graph as "a memory structure that captures decision traces from every interaction" an AI Colleague has with humans, systems, vendors and other agents; it "records exceptions, precedents, and reasoning", letting Colleagues make faster decisions over time on top of the AOP instructions. An AI Colleague is defined as a persistent digital worker that "builds memory over time", and the Touchpoints section states "same agent, same memory, every surface", so the store follows the agent across Teams, Slack, email and voice rather than resetting per channel. Stateful execution with callbacks resumes a paused task with full context intact. It falls short of Full because no page gives a retention period, an expiry, or a customer control to inspect, edit, export or purge the Context Graph independently of the tenant's data. The claim that it "gets smarter with every interaction" is absorbed learning and does not count; the grade rests on the recorded decision traces, which are a store. The Context Graph and Memory page, leena.ai/platform/context-graph-and-memory, was not read and would move this to Full if it states a lifetime or a retention control. Sourceleena.ai/agentic-ai-architecture; leena.ai/platform/context-graph-and-memoryread 2026-09-12 |
|
| Deployment & Data Residency | Full |
|
Leena AI offers three named deployment models across 14+ regions and presents the choice as a residency control. The models are shared public cloud with full logical isolation, isolated public cloud as a single-tenant environment, and private cloud or customer VPC. The FAQ answer opens by saying Leena supports three deployment models "to meet data residency and isolation needs", a selection surface stated as such rather than an option buried in prose. Geography is quantified: deployments are supported "across 14+ regions globally", spanning North America, Europe, APAC and the Middle East, and the Trust and Security section repeats it as "shared, single-tenant, or private VPC across 14+ regions". That gives a named region count with named geographies, named customer environments including a customer-controlled VPC, and a documented selection surface tied to compliance, where any one of the three would suffice. Supporting controls, noted as context rather than counted twice: AWS KMS-managed keys with bring your own key for regulated workloads, encrypted backups, and a stated design assumption that all controls presume processing of PII and PHI, which makes the private VPC path meaningful for healthcare and financial services rather than nominal. Sourceleena.ai/agentic-ai-architecture and /platform/enterprise-agentic-ai-trust-securityread 2026-09-12 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Leena AI publishes a browsable catalog of separate pre-built agents, each a whole digital worker with its own job role. The Agentic AI Use Case Library, promoted from the architecture page, carries "200+ enterprise use cases and 25+ autonomous AI Colleagues, all ready to deploy". The units are agents, not templates or connectors, identified by job role (IT Operations Coordinator, HR Operations Specialist, Finance Operations Analyst, with the blog naming Gavin the HR Expert and Miles the IT Analyst), each with a defined identity, its own AOP, its own toolset and its own Human Manager. Remove the Finance Colleague and the IT Colleague is still a whole working agent with its own protocol and permissions, because they are separate digital workers rather than modes of one engine. The adoption path is documented: "pre-built, pre-integrated, pre-trained", live in 45 days against a stated industry benchmark of 9 to 14 months, with three no-code Studios (AOP Studio writes the process, Workflow Studio wires the tools, Knowledge Studio connects the truth), so a shipped Colleague can be customized by business users without engineering. A catalog to adopt from plus studios to adapt it is the Full shape twice over. Sourceleena.ai/ai-colleagues-platform and /agentic-ai-architectureread 2026-09-12 |
|
| Triggers & Channel Coverage | Full |
|
Leena AI's Colleagues start on schedules, system events, API calls, MCP or human prompts, and reach out across 8+ channels. Per the vendor's FAQ, AI Colleagues are always-on persistent workers and "can be triggered by schedules" (the example given is daily reconciliations), "by system events" (a new employee added in the HRMS), "by API calls, by MCP, or by human prompts": four trigger classes, each with a worked example. The Touchpoints section adds the proactive half, "Talks back. Reaches out. Doesn't wait to be asked", and the AI Colleagues section states "always on, 24/7, no human trigger". Channel coverage spans Teams, Slack, email, voice, browsers and portals, stated as "8+ channels with zero context switching" and "same agent, same memory, every surface", with over 100 languages supported. Each AI Colleague keeps its own Workbench of upcoming tasks and supports stateful execution with callbacks, pausing at approval steps and resuming exactly where it left off, so a schedule-fired job survives a human interruption. Events, schedules and channels, three of the four markers the bar names, are all present in depth. Sourceleena.ai/agentic-ai-architecture and /platform/touchpointsread 2026-09-12 |
|
| Model Flexibility & Routing | Partial |
|
Leena AI routes each task across five named models, but the routing is the vendor's, not the customer's. The architecture page's Orchestrator section reads "model-agnostic by design", running on Claude Opus 4.8, WorkLM, GPT 5.5, Llama 4 or Gemini 3.5, and "routes between models on the fly". The FAQ repeats it: the Orchestrator "leverages multiple LLMs", including WorkLM, GPT-5.5, Claude Opus 4.8, Gemini 3.5 and Llama 4, "picking the best model for each task". A published differentiator page, Avoid Vendor Lock-In, states no OEM money, no vested interest, no vendor lock-in, we connect to all of them. It falls short of Full because the customer chooses nothing: the Orchestrator picks, and no page documents a model picker, an admin setting, a per-Colleague model assignment or a bring-your-own-key path. WorkLM fine-tuning on the customer's data, for their tenant only and with explicit opt-in, is a privacy control over training rather than a choice of model. Sourceleena.ai/agentic-ai-architecture and /why-leena/independent-agentic-airead 2026-09-12 |
|
| APIs, SDKs & MCP Extensibility | Partial |
|
Leena AI ships MCP and A2A, including inbound access for a customer's own AI, but publishes no API reference or SDK for its platform. A named differentiator page, "A2A and MCP built-in", states its purpose as to "unlock seamless integration between your in-house AI and Leena AI agents", which is the inbound direction this axis credits. The Orchestrator "hands off cleanly between agents over A2A", the integration layer runs via APIs, MCP, A2A and browser/RPA, and the trigger FAQ lists API calls and MCP as first-class ways to start an AI Colleague, so an outside system can drive the platform. Product documentation is published at docs.leena.ai and linked from the footer, three no-code Studios give in-platform build surfaces, and a Tool Registry supplies 1,000+ pre-built tools. It falls short of Full because no API reference, endpoint list, authentication guide or SDK was located, and MCP plus A2A plus a marketplace without one sits at Partial. docs.leena.ai is described as a reference for "configuring, deploying, and managing AI Colleagues", which reads as product documentation rather than a programmatic contract, and it was not opened. A published reference at docs.leena.ai or leena.ai/mcp-interoperability would move this to Full. Sourceleena.ai/agentic-ai-architecture and site footer; leena.ai/mcp-interoperabilityread 2026-09-12 |
|
| Testing, Debugging & Optimization | Full |
|
Leena AI names an evaluation suite that checks for regressions and an evaluator model that scores the primary model's output. The Observability and Governance section reads "Eval Suite catches regressions. Quality trends up, not sideways." A regression check compares current behavior against prior behavior, which is a readable comparable result. The hallucination FAQ states that "primary and evaluator LLMs", structured knowledge steps and full audit trails reinforce accuracy, and an evaluator model scoring the primary model's output is a judge verdict. Around both sits a loop: teams can drill into any execution, monitor token usage and latency by step, track automation rates and "capture user feedback for continuous improvement", with a Knowledge Health dashboard reporting where grounding is thin. That is a controlled post-deployment optimization loop. The 70% self-service contractual guarantee is a commercial outcome rather than tooling and does not count. The Eval Suite is one line on an architecture overview, and leena.ai/platform/ai-observability-and-governance was not opened, so no scoring scale, test-set construction or gating behavior is documented; that page would confirm rather than change the grade. Sourceleena.ai/agentic-ai-architectureread 2026-09-12 |
|
| Browser & Computer Use | Partial |
|
Leena AI's agents fall back to operating a browser themselves where no API exists. Integrations run "via APIs, MCP, A2A, and browser/RPA", summarized as "API + RPA + browser fallback, nothing's we can't integrate", and the FAQ gives the mechanism: "where APIs aren't available, AI Colleagues use browser-based skills to operate apps like a human would." The AI Colleague drives the interface, no human decides which page is open, and the purpose is to reach systems that expose no API. That is the product navigating, as distinct from capture extensions where a person navigates and the tool only reads. It falls short of Full because only one modality is documented: browser-based skills, with no desktop session, remote or local computer control, or hosted browser environment. It is positioned as a fallback rather than a capability a buyer selects, and nothing states how sessions are isolated, how credentials are held, or how the skills behave when a target application changes its markup, which is the first question a buyer would ask here. The integrations page, leena.ai/integrations, was not read and may carry more detail. Sourceleena.ai/agentic-ai-architectureread 2026-09-12 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Quote only
flat
What is public
Nothing, verified first-party 2026-09-12. Leena AI publishes no pricing page and no rate card. The site navigation runs Products, Architecture, Why Leena AI, Resources and Company; the footer runs Products, Agentic AI Architecture, Differentiators, Compare, Resources and Company. Neither carries a pricing entry, and every call to action on the architecture page resolves to Request a demo, Book a personalized demo, Talk to sales or a live product tour. What is published in place of price is packaging shape: three deployment models (shared public cloud, isolated single-tenant public cloud, private cloud or customer VPC) across 14+ regions, 25+ pre-built AI Colleagues covering 200+ use cases, 200+ enterprise connectors with 1,000+ tools, and a stated 45-day go-live against an industry benchmark of 9 to 14 months. The one quantified commercial term found is a contractual guarantee of a 70 percent self-service ratio.
Billing mechanics
Enterprise SaaS subscription (sales-led, quote-based; typically per-employee or per-agent + modules); not publicly itemized. No public figures.
Variable cost rationale
Nothing is published about metering, so this is a judgment about shape rather than a reading of terms. The exposure argument is real: Colleagues are always-on and fire on schedules and system events as well as prompts, the Orchestrator routes across five LLMs with cost and performance telemetry tracked by step, and nothing caps volume. Against that, the product is sold as an enterprise platform to organizations replacing ticket queues, which points to a committed annual fee rather than per-action billing, and the 70 percent self-service guarantee implies an outcome-linked rather than consumption-linked frame. Held at medium with the uncertainty named rather than scored as if the terms were known.
Additional watchouts
Ask what the meter is before anything else, because the architecture implies several. AI Colleagues run always-on against schedules and system events rather than only on employee prompts, so consumption is not bounded by headcount asking questions; the Orchestrator routes across five LLMs and reports cost and performance telemetry by step, which means token cost exists somewhere in the commercial model even though no page says whose. The deployment choice is the other lever: a private VPC across a named region is a materially different cost base from shared multi-tenant cloud, and all three are presented as equally available. On the buyer's side, the 70 percent self-service contractual guarantee is a genuine risk transfer and unusual in this lane — worth pinning down in writing, since a guarantee with no stated remedy is a marketing number.
Sales call required
Yes, required for paid access
Commercial notes
Enterprise employee-experience / autonomous-agent vendor; competes with Moveworks, Aisera, ServiceNow, Espressive
Key ambiguities
The commercial unit is unstated and the platform offers at least three plausible ones. Leena AI sells 25+ AI Colleagues, meters nothing publicly, and contractually guarantees a 70 percent self-service ratio — so a buyer cannot tell whether they are charged per Colleague, per employee, per resolved request, or on a platform fee against that guaranteed deflection rate. The deployment choice compounds it: shared cloud, single-tenant and private VPC across 14+ regions almost certainly carry different commercials, and none is priced.
Support SLA / resale
Enterprise support; integrates with HRIS/ITSM/knowledge sources; autonomous agent + workflow automation
Missing data
Every figure, and the billing axis itself. No pricing page exists: the primary navigation carries Products, Architecture, Why Leena AI, Resources and Company with no pricing entry, and the footer's four columns carry none either. Every commercial route resolves to Request a demo, Book a personalized demo, Talk to sales, or a self-guided product tour. Contract length, minimums, the price difference between the three deployment models, and whether the 45-day go-live carries an implementation fee are all unpublished. Whether the 70 percent self-service guarantee is a service credit, a price adjustment or a termination right is not stated.
Related vendors
- 11th Estate — Agentic platform whose AI engine scans markets, matches an…
- Adopt AI — AI CPA firm whose agents run reconciliations, close, AP and AR, and…
- Aera Technology — Decision intelligence platform where an always on agent executes…
- Akro AI — On premise operational intelligence that automates document heavy…
- alfred_ — AI executive assistant that triages the inbox overnight and scores…
- Alloy.ai — Commerce intelligence system for consumer brands that unifies four…
Alternatives to Leena AI
The closest documented capability profiles to Leena AI among enterprise operations agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Atomicwork12.0 / 14Fuller documented coverage on Model Flexibility & Routing
- dSilo12.0 / 14Fuller documented coverage on Memory & State Persistence
- Leah AI11.0 / 14A lighter documented profile than Leena AI
- Tungsten Automation13.0 / 14Fuller documented coverage on Model Flexibility & Routing and Browser & Computer Use
- Adopt AI12.5 / 14Fuller documented coverage on APIs, SDKs & MCP Extensibility and Browser & Computer Use
- Auditoria10.5 / 14A lighter documented profile than Leena AI
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded