PLATFORM

How it works.

The trust layer, installed inside Outlook, Chrome, Salesforce, SAP and Teams. Every module arrives as a service in your own tenant, deployed and run by KOBIL.

ARCHITECTURE

Four parts, and nothing for the user to assemble.

One service on the device, a thin extension per host, one pane, and a tenant that belongs to you.

1The background service
One signed service on Windows and macOS. It holds the device-bound credential, keeps the session with your tenant, and adds the right-click action that sends any file on disk for signature. It installs silently through your MDM and needs no local admin rights.
2The host extensions
Thin extensions for Outlook, Chrome, Salesforce, SAP and Teams. Each one does a single job: tell the service what the user is looking at, and give the pane somewhere to open. They carry no data of their own.
3The pane
One surface, the same in every host. It reads the current mail or page and starts the action that belongs to it, already filled in. Nothing is retyped, and every step lands in the tamper-evident audit log.
4Your tenant
Your own tenant in an EU region. KOBIL deploys and runs every module in it as a service, so adding a capability is a deployment on our side, not a project on yours.
The service and the extensions are distributed by your own IT through the management tools it already runs. See what that takes.
THE MODULE SET

Every module, and what it leaves behind.

A module is only worth its licence if it produces something a colleague, a customer or an auditor can hold. Here is what each one produces.

Device-bound identity
The credential lives on the device. Binding happens silently through your MDM, or with a single sign-in where there is no MDM.
PRODUCES
A verified person on a known device, in every host.
Single sign-on
Into the applications you already run, from the pane, with no second login.
PRODUCES
An open session in the target application, without a password to phish.
Secure chat
End-to-end encrypted, and external counterparties join without a licence.
PRODUCES
A conversation with a verified identity on both sides of it.
Approvals
Raised and cleared in the pane. Confirmed on a phone, a desktop or a hardware token; a phone is never required.
PRODUCES
A recorded decision, with the policy check attached to it.
Advanced electronic signature
Unlimited, at the advanced level, on KOBIL technology. Qualified signatures come from a certified partner and are billed per signature.
PRODUCES
A signed document with its evidence, back in the thread it came from.
Signed web capture
Seal the page in front of you, exactly as it stood, at the moment you were looking at it.
PRODUCES
A dated, tamper-evident copy of what was on screen.
Workflows
Multi-step processes with approvals routed by rule, not by forwarding a mail.
PRODUCES
A process that finishes without anyone chasing it.
Your apps, in context
Build and publish your own from the App Builder. The platform hands each one the context of what the user is looking at, through a permissioned channel that lands in the audit log.
PRODUCES
An app in the pane, on the same surface as ours.
Backend integrations
Connect SAP, Salesforce and your other systems of record, with published templates.
PRODUCES
A record moved in the system of record, with the user context attached.
Evidence export
Audit log export, SIEM streaming, and the evidence pack auditors ask for.
PRODUCES
The file the auditor asked for, without a project to produce it.
Company AI
Answers from your knowledge base, scoped to what the signed-in role may see, and able to carry out the action it just described.
PRODUCES
An answer, and the action behind it, under the same identity.
Corporate payments
Company cards in the pane, with the spend confirmed by the person making it.
PRODUCES
A paid invoice or ticket, with the receipt already filed.
Which modules are in which edition is set out on the editions page. Identity and single sign-on are in the base edition and never move up a tier.
USE CASES

What teams do with it in week one.

HR
Day-one onboarding
The onboarding checklist lands in the pane on first sign-in. Tasks are completed and approved without hunting for links.
COMPLIANCE
Guideline sign-off in chat
Company guidelines are approved inline in the HR group chat. No digging through Teams threads or mail archives.
LEGAL
Data privacy e-signature
The privacy agreement is signed with a legally binding e-signature without leaving the conversation.
SALES
Salesforce, no password
Verified identity and a known device open Salesforce straight into lead creation. The offer approval goes to the manager's phone.
IT
Helpdesk in the pane
Tickets are raised and resolved with the verified identity attached. Up to 75% fewer password-reset calls.
FINANCE
Travel and invoice approvals
A trip to a key client is requested, approved and logged from the phone. Invoices follow the same trail.
IDENTITY FOUNDATION

Your directory, or ours.

Everything above runs on one identity. It comes from the directory you already keep, or from the one that ships with the platform. Nothing else changes between the two.

MODE ONE
Federate what you already run
Active Directory, Entra ID or any OIDC or SAML provider stays the source of truth. People are added and removed where IT already does it, and KOBIL Enterprise follows in real time.
Active DirectoryEntra IDOIDCSAML
MODE TWO
Or use the one that ships with it
No directory yet, or a frontline population that was never in one? The built-in directory is ready on day one, with the same lifecycle and the same single action to close an account. Federate later without redoing anything.
Ready day oneSame lifecycle

From first day to last, driven by your directory.

Day one, ready
IT adds the employee to the directory group. Identity, apps, chat and onboarding tasks are live before the first coffee. No tickets, no shadow accounts.
Added to Active Directory
Signs in with directory credentials, once
Every connected app opens without a password
Last day, closed
Disable the account in the directory and every session, app grant and signature right is revoked at once. Offboarding is one action, not a checklist.
Disabled once, in Active Directory
Sessions and app access end everywhere
The audit trail stays, tamper-evident
CONNECT EVERYTHING ELSE

Your stack, on one identity.

KOBIL Enterprise is a framework, not a walled garden. Bring the tools you already own, three ways.

FEDERATE
OIDC and SAML
For example, Salesforce over OIDC or Jira over SAML. Your existing apps sign in silently on the verified identity; no passwords to phish.
Single sign-onKnown device
INTEGRATE
REST APIs
Wire backend workflows into the pane. SAP releases, ticket updates and HR events flow both ways with the user context attached.
Two-wayUser context
BUILD
Mini-apps
Small HTML apps for your own processes, built and published from the App Builder. Identity and chat come free over OIDC. Days, not months.
No-code publishRole based
Assembled in the Smart Dashboard: install apps from the Marketplace, publish your own mini-apps, arrange the workspace by drag and drop.
ONE PLATFORM, NOT A SUITE
Every KOBIL module is itself an app on this platform.
There is no privileged inner product. Identity, chat, approvals, signature, workflows, payments and Company AI are apps on the same surface, and KOBIL deploys and runs each of them as a service in your tenant. That is why a new capability arrives as a deployment rather than a migration.
It is also why opening the framework costs you nothing in fidelity. When your own teams build from the App Builder, they build on exactly the surface our modules use: the platform hands each app the context of what the user is looking at, through a permissioned channel that lands in the audit log.
Same surface Same identity Same audit log
No new app. No passwords. No switching. Just trust, built in.

Create trust in the digital world.

See KOBIL Enterprise inside your own tools. A 30-minute demo, on your stack.

Book a demo Read the whitepaper