SPEX · Connect & Share

A SPEX product

Runseal

The cloud automation platform: enterprise automation that runs entirely in your own Azure tenant. PowerShell-native, contract-driven and built for organizations that need control, traceability and operational resilience. Every run is governed: risk-tiered approval before it executes, a record after it completes.

Explore a pilot Visit runseal.cloud

Runseal architecture: ITSM, API, scheduler and AI agent requests flow through contract validation, queues and domain workers to Entra ID, Microsoft 365, Exchange and Azure services, all inside the customer's Azure tenant.

Why Runseal

Most Microsoft 365 organizations automate through one of two compromises. Proprietary SaaS suites can introduce another control plane, another licensing model and workflow logic tied to a vendor-specific designer. Loose scripts avoid all that, right up until they run your business with no owner, no audit trail and no recovery plan.

Runseal takes a different approach: a code-first automation platform deployed as infrastructure as code into your own Azure tenant. Activities are plain PowerShell. Requests arrive as versioned contracts. Runs are designed to be queued, auditable and recoverable, and Runseal runtime and operational data remain in the environment you already govern.

Proprietary SaaS

  • New stack
  • Additional licensing layer
  • Vendor-specific logic
  • External control plane

Loose scripts

  • No governance
  • Fragile
  • Hard to maintain
  • No audit

Runseal

  • Existing Azure estate
  • Consumption-based
  • PowerShell-native
  • Contract-driven

How Runseal works

Runseal request flow in six steps: requests from ITSM, API or AI enter as a versioned JSON contract, queue for buffered recoverable execution, run through a domain worker as an approved enterprise action and record status and audit evidence.

Your tenant, your data

Deployed via Bicep into your own Azure subscription: Container Apps, Service Bus, Key Vault and Log Analytics. Runseal runtime and operational data remain in your environment by design.

PowerShell-native activities

Automation logic is plain PowerShell, so your team extends the platform with skills it already has.

Modular domain verticals

One queue and one worker per domain. Start where the demand is and add verticals as you grow.

Contract-based intake

Every request is a versioned JSON envelope. Any ITSM capable of producing the versioned request contract can submit work, keeping the intake layer replaceable.

Failure recovery and audit

Failed messages park for replay instead of disappearing, and action outcomes are recorded in the execution record.

Where AI fits

An AI agent can only be trusted with operations that are bounded, typed and recorded. Runseal activities are designed to be all three. The Intelligence edition on the roadmap adds an agent gateway on top of the same versioned contracts, so AI joins as a client of the platform rather than a rewrite of it.

Runseal Intelligence: planned

Two models compared: an AI agent with direct access to enterprise systems has no guardrails, no approval boundaries and no audit, while in the Runseal model the agent calls governed, contract-validated actions through an AI action gateway with policy, approval and a full audit trace.
The Intelligence edition model: AI consumes bounded, governed actions rather than receiving privileged backend access.

Editions

Available

Runseal Core

Deterministic ITSM-driven automation, available today.

In development

Runseal Governance

Cross-action policy, approval and advanced audit controls.

Planned

Runseal Intelligence

AI action gateway.

Each edition is additive. Core delivers standalone value and later layers can be enabled without replacing the underlying automation model.

Best fit for

  • Microsoft-centric organizations
  • Azure already in use
  • Critical cross-system workflows
  • Fragmented scripts or Power Automate estates
  • ITSM-driven provisioning
  • Regulated or high-control environments

Pilot examples

Identity & Enterprise Apps

App registrations, owners, credentials, approvals and lifecycle.

Collaboration

Teams, SharePoint, workspace ownership and lifecycle.

ITSM-driven Actions

Service request to governed enterprise execution with status feedback.

Start small

Runseal Core is available today. Start with one domain. Prove one use case. Expand only when value is demonstrated.

  • One Azure tenant
  • One domain
  • One intake path
  • 1 to 3 governed actions
  • Defined proof criteria

A SPEX product

Ten years of automation work, turned into a product

SPEX has spent ten years building and operating automation inside complex European enterprise environments. The same problem kept recurring: the automation that carries real operational risk is the automation nobody can safely delegate, because delegating it means handing over standing privilege.

Runseal is that problem solved as a product rather than as another engagement. It is developed and owned by SPEX S.à r.l. in Luxembourg, and it has its own home.

Go to runseal.cloud

Scope a Runseal pilot

Start with one domain and one high-value use case. We will help you scope a focused pilot in your Azure environment.

Discuss a pilot