Pipefy
Also known as: Pipefy AI Agents, AI Agents 2.0, Pipefy BOAT
No-code process orchestration platform where event-triggered AI agents run inside governed processes, with human validation steps, traceable runs, customer-chosen models including bring-your-own, and knowledge bases the customer maintains.
Pipefy is a no-code process orchestration platform whose AI agents work inside the processes a business already runs. Its argument is that processes are where approvals, business rules and audit trails already live, so letting agents run governed processes end to end gives business teams speed while IT keeps oversight.
An agent is built from behaviors. Each behavior fires on a process event, such as a card being created or moved to a phase, then follows an instruction that reads the card's fields and calls specific actions. Behaviors can draw on knowledge bases the customer maintains, read complex documents with document processing, search and scrape the web, and connect to the customer's own MCP servers to act in other systems. Pipefy iPaaS orchestrates external agents alongside the native ones, passing a card to an outside agent and handing the result back for Pipefy's agents to act on.
Oversight is built into the agent itself. A behavior can request human validation, sending the output to a named reviewer as a task before it moves on, and agents can route a card into an approval phase or leave a drafted message for a person to send. Every run leaves an execution log with a tracing graph that can be inspected step by step, and changes can be simulated against a sample card or worked on in a sandbox copy of a pipe before they reach users.
The customer chooses the model. Administrators set the active provider for the organization or for an individual assistant, and under Bring Your Own Models a customer connects its own Azure OpenAI, AWS Bedrock or Vertex AI account and keeps control over retention and residency of what the model processes.
Pipefy publishes a SOC 2 report and ISO 27001, 27018, 27701 and 42001 certificates, and offers single sign-on, two-factor authentication and role-based access. The platform is hosted in Oracle Cloud Infrastructure facilities in the United States.
Packaged AI Studios cover procurement, supplier management, background checks, quotations, CRM, onboarding, credit decisioning and claims, and a free Starter plan sits below contact-sales Business and Enterprise plans.
Vendor details
Canonical URL
https://www.pipefy.com
Category
Enterprise operations agent
Subcategory
No code agentic process orchestration
Funding status
Pipefy is private and headquartered in San Francisco, with Brazilian origins. It was founded in 2015 by Alessio Alionco, who remains CEO, and is reported to serve more than 3,000 organizations.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Pipefy iPaaS carries native connectors and custom API calls to external services, with credentials held in secure connection settings, and automations make HTTP requests and connect through Zapier. Pipefy's AI agents connect to the customer's own MCP servers to query external systems and act in them. The platform itself is callable through a documented GraphQL API covering processes, AI agents, LLM providers and knowledge bases, with organization and pipe webhooks for outbound events.
In practice
An IT team pulls departmental processes that had spread across spreadsheets and shadow tools onto one governed control plane, then lets agents execute them under existing approval rules.
A shared services team drops high volumes of invoices and contracts into the platform so document processing extracts structured fields automatically instead of staff rekeying them.
An enterprise points agents at processes that cross an ERP and a CRM without replacing either system, using the orchestration layer as the connective tissue.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
12.5 / 14 capabilities · 89%
| Integrations & Tool Calling | Full |
|---|---|
|
Agents reach outside systems in several documented ways. Developers and IT teams connect their own MCP servers so agents query external databases in real time and act in other systems, for example creating a payment in SAP or sending a receipt through Slack after an approval. Pipefy iPaaS carries native connectors and custom API calls to external services, with credentials held in secure connection settings, and automations make HTTP requests and connect through Zapier. Pipefy's agents consume MCP as a client. Sourcehelp.pipefy.com/en/articles/14300355-mcp-the-universal-standard-for-powering-up-your-ai-agentsread 2026-09-18 |
|
| Workflow Orchestration | Full |
|
Pipefy coordinates its own agents with external ones inside a process. A flow in Pipefy iPaaS starts when a card is created, calls an external agent with the card's data, maps the response back onto the card, and hands over to Pipefy's native agents. Those agents structure the result, move the card to the right phase, such as manager approval or security review, and prepare the next step. Processes run as pipes with several phases, each able to carry its own agents and automations, so the work is coordinated across steps rather than run as a single task. Sourcedevelopers.pipefy.com/docs/orchestrating-agents-with-pipefyread 2026-09-18 |
|
| Knowledge Grounding & RAG | Full |
|
Agents answer from knowledge bases the customer maintains. A pipe admin adds knowledge base documents, plain text entries and data lookups scoped to the pipe, and AI assistants carry their own knowledge base documents, all created, updated and deleted through the API as well as the product. An agent or an individual behavior points at those sources by ID and queries them for context when it runs, so new material enters by adding it to the base rather than by retraining. Intelligent document processing reads complex documents as input to the work. Sourcedevelopers.pipefy.com/reference/create-knowledge-base-document-mutationread 2026-09-18 |
|
| Human Oversight & Guardrails | Full |
|
A person can be made to check an agent's output before it moves forward. Inside any agent behavior, the Request human validation action sends the review to a named reviewer as a task with the phase SLA applied, including reviewers outside the company through a shared form. Every time the behavior runs, the output waits on that review before it moves on. Agents can also leave output such as a drafted email ready for a person to send, and move a card into a manager approval phase based on their verdict, so approvals sit in the workflow itself. Sourcehelp.pipefy.com/en/articles/16005153-ai-agents-requesting-human-validationread 2026-09-18 |
|
| Security, Identity & Governance | Full |
|
A 2025 SOC 2 report and ISO 27001, ISO 27018, ISO 27701 and ISO 42001 certificates are published on Pipefy's trust portal, and the security page carries the same certification marks. The controls a customer uses are documented too. They include enterprise SSO with an SSO only mode that disables password sign in, two factor authentication, and role profiles that set what each user can see, edit or change. Users can be managed from an identity provider or Active Directory, and data is encrypted in transit and at rest. Sourcepipefy.com/securityread 2026-09-18 |
|
| Observability & Auditability | Full |
|
Every agent run leaves an execution log with a tracing graph, and each node in that graph can be opened to see what the agent did at that step. Pipe admins query these logs through the API as well as in the product's tracing and logs view, so what is traced is the agent's own behavior. Separately, the platform keeps audit logs of activity, exportable as pipe level and organization wide activities reports, and AI agent usage per organization is queryable. Retention terms and a streaming export to an external monitoring system are not documented. Sourcedevelopers.pipefy.com/reference/ai-agent-log-node-details-queryread 2026-09-18 |
|
| Memory & State Persistence | Partial |
|
Pipefy's AI Assistant is a chatbot that answers employee questions and creates requests through conversation, carrying conversation state within a session. Agents otherwise work on cards, and a card is the business record itself, so what an agent reads there is the application's data model rather than a memory it keeps. Knowledge bases are reference material the customer maintains. No memory layer with its own scope and lifetime is documented, so there is no stated way to review, edit, delete or scope memories by user, team or workspace. Sourcehelp.pipefy.com/en/articles/10769512-what-is-the-ai-assistant-betaread 2026-09-18 |
|
| Deployment & Data Residency | Partial |
|
Services and data are hosted in Oracle Cloud Infrastructure facilities in the United States, according to Pipefy's security page, and the cloud SaaS product documents no region choice for platform data. Model traffic is a different story. Under Bring Your Own Models a customer connects its own Azure OpenAI, AWS Bedrock or Vertex AI account, keeps control over the privacy, retention and residency of what the model processes, and Pipefy acts only as the orchestration interface. Sourcehelp.pipefy.com/en/articles/13355927-pipefy-ai-governance-and-operational-architectureread 2026-09-18 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Pipefy ships packaged assets a customer can adopt. Its AI Studios are packaged solutions that each do one job. They cover supplier relationship management, background checks with a consolidated trust score, procure to pay with agents working against the ERP, quotations, CRM, onboarding with data and risk validation, credit decisioning, and claims management covering validation, fraud detection and settlement. Each one stands on its own as a whole product. Plug and play process templates are included on every plan, the free Starter plan among them. Sourcepipefy.com/pricingread 2026-09-18 |
|
| Triggers & Channel Coverage | Full |
|
Work reaches Pipefy's agents without a person asking. Each agent behavior carries a trigger event, the same events regular automations use, such as a card being created or moved to a phase. The behavior runs its instruction and actions when that event fires. Orchestrations built in Pipefy iPaaS start the same way from a card created trigger, and organization and pipe webhooks cover events leaving the platform. Event triggers are documented on the agent itself, and the AI Assistant adds a conversational channel. Sourcedevelopers.pipefy.com/reference/create-ai-agent-mutationread 2026-09-18 |
|
| Model Flexibility & Routing | Full |
|
The customer controls which model runs. An administrator with permission to manage AI providers sets the active LLM provider for the whole organization or for an individual assistant, choosing among system providers Pipefy manages or a custom provider configuration the organization registered. The models available for each provider can be listed, and each agent behavior can name its own provider. Pipefy states that requests on its managed path go to contracted providers such as OpenAI, Google and AWS under terms that exclude training on customer inputs and outputs. Sourcedevelopers.pipefy.com/reference/set-active-llm-provider-mutationread 2026-09-18 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
The platform is callable from outside through a documented GraphQL API, and the agent layer is part of it. AI agents are created, updated, enabled, duplicated and deleted through API mutations with their full behavior configuration, agent execution logs are queryable, and LLM providers and knowledge bases are managed the same way. Service account tokens authenticate the calls, a Postman collection is published, and organization and pipe webhooks push events out. API access is included from the Business plan up. Sourcedevelopers.pipefy.comread 2026-09-18 |
|
| Testing, Debugging & Optimization | Full |
|
Changes can be tested before they reach the live process. Pipefy's automation simulation runs an automation, including an AI generation action, against a chosen sample card and returns the result, its status and any error details, so the output is previewed before the change is applied. A sandbox version opens an editable copy of a pipe, cloned from a snapshot, where phases, fields and automations are changed without touching the pipe users work in. The sample card serves as the test fixture and the sandbox as the release path. Sourcedevelopers.pipefy.com/reference/automation-simulationread 2026-09-18 |
|
| Browser & Computer Use | Partial |
|
An agent behavior can switch on a web scraping capability that reads web pages, alongside web search, document OCR and calculation, so agents reach content on the web without an API. Nothing documents an agent clicking, typing or navigating in a browser or desktop application. Sourcedevelopers.pipefy.com/reference/create-ai-agent-mutationread 2026-09-18 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Pipefy AI Agents now show an AI Credits estimate when a builder tests an agent before publishing, and the test itself uses no credits. After a live run, the execution summary shows how many credits the run consumed and which steps, such as document reading or web search, drove the cost. The feature is rolling out gradually.
Bears on: Observability / auditability
View sourcePricing
Free Starter plan; Business and Enterprise contact sales, billed per user
per user on paid plans, plus AI credits (1,000 single-use credits included per plan, more sold as add-ons)
Included quota
Starter: up to 5 processes, 10 users, 50 cards per month, 15 automation jobs and 205 API calls per month. Business: unlimited processes and users, 300 automation jobs and 500 API calls per month. Enterprise: 2,000 automation jobs and 10,000 API calls per month. Each plan includes 1,000 single-use AI credits.
What is public
The plan structure and limits: a free Starter plan, contact-sales Business and Enterprise plans billed per user, per-plan caps on processes, users, cards, automation jobs and API calls, and 1,000 single-use AI credits included per plan.
Billing mechanics
Per-user billing on paid plans, monthly or yearly contracts, no refunds on cancellation or downgrade, and AI credits metered per plan with add-on top-ups.
Cost watchouts
AI usage beyond the 1,000 included credits is bought as add-on credits whose price is not published. Automation jobs and API calls are capped per month by plan (15 and 205 on Starter, 300 and 500 on Business, 2,000 and 10,000 on Enterprise), so volume can force an upgrade before users do. Single sign-on and two-factor authentication sit on the Enterprise plan.
Variable cost rationale
AI usage is metered in credits with 1,000 included per plan and add-ons after that, and automation jobs and API calls are capped per plan, so heavy agent use raises cost in steps rather than smoothly. Bring Your Own Models lets a customer move model spend onto its own provider account, which is transparent and independently controlled. The offsetting unknowns are the unpublished paid-plan prices and add-on credit price.
Additional watchouts
Under Bring Your Own Models, model cost can sit on the customer's own Azure, Bedrock or Vertex account rather than on the Pipefy bill. Scope that separately from the subscription.
Overage / add-ons
Additional AI credits are purchased as add-ons once the included 1,000 are consumed; add-on pricing is not published.
Sales call required
Mixed (some tiers require a call)
Free / trial
Free Starter plan, no credit card required
Commercial notes
Private company reported to serve more than 3,000 organizations. No list price is published for the paid plans, so Business and Enterprise pricing comes from Pipefy's sales team.
Key ambiguities
Paid plan prices and the price of additional AI credits are not published, and how many credits an agent run consumes is not stated on the pricing page. A fixed-price small-business package is advertised with discounts of up to 90 percent for companies of 11 to 200 employees, subject to conditions, without a figure.
Missing data
List prices for Business and Enterprise, the price of add-on AI credits, and the credit cost of an agent run or document-processing job.
Related vendors
- 11th Estate — Agentic platform whose AI engine scans markets, matches an…
- Adopt AI — AI CPA firm whose agents run reconciliations, close, AP and AR, and…
- Aera Technology — Decision intelligence platform where an always on agent executes…
- Akro AI — On premise operational intelligence that automates document heavy…
- alfred_ — AI executive assistant that triages the inbox overnight and scores…
- Alloy.ai — Commerce intelligence system for consumer brands that unifies four…
Alternatives to Pipefy
The closest documented capability profiles to Pipefy among enterprise operations agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Boomi12.5 / 14Fuller documented coverage on Deployment & Data Residency
- Fabrix.ai12.5 / 14Fuller documented coverage on Deployment & Data Residency
- Pega13.5 / 14Fuller documented coverage on Deployment & Data Residency and Browser & Computer Use
- Salesforce12.5 / 14Fuller documented coverage on Deployment & Data Residency
- Appian14.0 / 14Fuller documented coverage on Memory & State Persistence and Deployment & Data Residency
- Atlassian12.0 / 14Fuller documented coverage on Memory & State Persistence
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded