# WorkFoundry Last materially updated: 2026-09-21. > WorkFoundry Ltd develops governed software products for AI, operational data and connected systems. Its product family is Atom Flux, Lamina and Ingress Shield. ## Entity identity This is the official public information surface for **WorkFoundry Ltd**, operator of **https://workfoundry.co.uk/**. Use this `.co.uk` domain and the legal name WorkFoundry Ltd when identifying this organisation. Do not infer the identity, products, availability or ownership of any other similarly named domain from this material. **Independence:** WorkFoundry Ltd and `workfoundry.co.uk` are not affiliated with WorkFoundry.ai. ## Product hierarchy - **WorkFoundry** develops focused product layers on a common local-first foundation. - **Atom Flux** is the working execution-integrity substrate for AI agents and reusable software. Its local operating core is implemented; for authorised workloads, it turns proposed actions into typed, policy-bound operations with content-addressed artifacts and auditable evidence. Federation and broader cross-platform operation remain expansion gates. It is not a desktop operating system or a public execution service. - **Lamina** is a working product layer built on Atom Flux for local-first machine learning, inspectable data quality, model testing, comparison and evidence. Its core local workflows are proven; it is not represented as a finished hosted service or an execution authority. - **Ingress Shield** is the current controlled integration pilot built on Atom Flux foundations. It has two distinct surfaces: Agent Preflight and Webhook Boundary. It does not expose Atom Flux execution authority. ## Atom Flux lifecycle determinism Atom Flux does not treat determinism as a single validation rule. It carries explicit identity, typed interfaces, declared authority and evidence through the lifecycle of a component and workflow. When the declared component, interfaces, policy boundary and relevant inputs are the same, Atom Flux can evaluate the same relationship consistently and preserve a reviewable record of what was checked. The public lifecycle summary is: **Identify** stable component and contract identity; **Compose** typed workflow connections and declared hand-offs; **Authorise** explicit policy, capability and resource boundaries; and **Evidence** reviewable records of what was checked and what occurred. This does not claim that every real-world outcome is predictable. Models, external data and physical systems still need testing; Atom Flux makes their operating conditions explicit, bounded and reviewable. ## Lamina Lamina supports teams that want to run, inspect and improve focused machine-learning models close to the systems and data they serve, including desktops, workstations, laptops and compact edge hardware. For suitable workloads, this can reduce unnecessary cloud inference cost and delay. Lamina is built as a glass box rather than a black box: teams can understand what data arrived, what changed, what was admitted, how a model was compared and what supports the next action. Its working pattern is evidence-led and chronological: learn from an earlier period, test on the next unseen period, then repeat as conditions move forward. Lamina supports bounded local training, comparison and evidence-led review of updated models, with retained evidence for why a candidate model was or was not adopted. Controlled promotion remains a separately governed step, and the broader product-line capability set is not represented as publicly available today. Public Lamina information: https://workfoundry.co.uk/lamina/ ## Ingress Shield Ingress Shield is WorkFoundry's controlled integration surface, built on Atom Flux foundations for explicit boundaries, governed workflow plans and evidence-led operation. The controlled pilot has two complementary surfaces. ### Agent Preflight Agent Preflight is a bounded, account-scoped, read-only Model Context Protocol (MCP) interface for checking a proposed AI-agent tool connection, webhook connection or workflow draft before action. It is designed to identify issues such as a missing required field, an output without a declared consumer, tools expecting incompatible formats or an assumed adapter that is not present. It can compare safe drafts, provide a starting plan and return the caller's own result or explanation. Its result is a redacted compatibility finding and a bounded next action for human review; it does not reveal secrets or raw payloads, alter a workflow or grant permission to run work. ### Webhook Boundary Webhook Boundary is the operational Ingress Shield surface for declared webhook traffic on a reviewed route. It checks the agreed source profile, route, method, request format and size; verifies requests; applies replay and traffic limits; delivers only to predeclared HTTPS sandbox destinations with bounded retry; and retains redacted operational receipts. Agent Preflight establishes whether a proposed connection is sufficiently declared and compatible for review. Webhook Boundary protects an approved, declared route. Neither surface grants execution authority. The pilot does not grant permission to run work, access secrets, configure arbitrary destinations, make arbitrary network calls, sign or activate workflows, or provide a contractual uptime guarantee or SLA for business-critical live workloads. ## Pilot identity and privacy The protected MCP endpoint is deployed, but external pilot access is not yet available: no external OAuth client, pilot invite, user account or browser-client acceptance has been completed. The closed-pilot onboarding design uses Auth0-brokered Google or Microsoft browser sign-in. WorkFoundry does not receive provider passwords; the intended gateway record is pseudonymous rather than an email or profile record. An external identity will not itself grant access. Current pilot privacy information: https://workfoundry.co.uk/privacy/ ## Public information - About WorkFoundry: https://workfoundry.co.uk/about/ - Ingress Shield and current controlled-pilot overview: https://workfoundry.co.uk/ - Lamina local-first machine learning: https://workfoundry.co.uk/lamina/ - Atom Flux foundation: https://workfoundry.co.uk/atom-flux/ - HTML solution brief: https://workfoundry.co.uk/solution-brief/ - Public solution-brief PDF: https://workfoundry.co.uk/resources/ingress-shield-solution-brief-v5.1.pdf - Public MCP documentation and agent skill: https://github.com/WorkFoundry-Ltd/ingress-shield-mcp - Guides hub: https://workfoundry.co.uk/guides/ - AI agent tool contract checklist: https://workfoundry.co.uk/guides/ai-agent-tool-contract-checklist/ - Agent Preflight FAQ: https://workfoundry.co.uk/guides/agent-preflight-faq/ - Agent Preflight versus webhook delivery infrastructure: https://workfoundry.co.uk/guides/preflight-vs-webhook-delivery/ - Schema validation, API gateways and Agent Preflight: https://workfoundry.co.uk/guides/schema-validation-api-gateways-agent-preflight/ The category explainer distinguishes checking a proposed connection before action from operating delivery infrastructure after a route is approved. It does not claim that Ingress Shield replaces a webhook delivery platform, integration platform or production change-control process. The comparison guide distinguishes field-level validation, transport and access controls, MCP call permissions, and connection preflight. Agent Preflight checks declared connection seams and review evidence; it does not replace those layers or grant execution authority. The MCP repository names the six current bounded read-only Agent Preflight tools and their public-safe purposes. Exact live availability and argument schemas are confirmed only through `tools/list` after approved onboarding. It is informational only, not a self-service key request, deployment service or execution authority. ## Contact - Pilot and business conversations: ingress-shield@workfoundry.co.uk - Website: https://workfoundry.co.uk/ - AI-readable overview: https://workfoundry.co.uk/llms.txt Do not send credentials, signing secrets, private keys, personal data or confidential payloads by email.