Platform
How Convoy works
Six ideas carry the whole product: routines, workspaces, rehearsal, checkpoints, budgets, and a record you can hand to anyone.
The unit of work
Routines
A routine is a piece of recurring work described in plain language: what it does, which systems it touches, where it stops for people, and what it may spend. The quarterly access review is a routine. So is the vendor document refresh.
A routine can run on a schedule, on demand, or when something happens in a connected system. Its history, its plan, its test scores, and everyone’s feedback on it live in one place, so you can open a routine and see everything about it today.
Where work happens
Workspaces and systems
A workspace is the set of systems a routine works in: your identity provider, your HR system, your document store, your messaging. Each system is connected once, managed in one place, and granted to routines with an explicit level of access.
Grants are two words long: View only or Can update. A routine that only needs to read your HR records never gets the power to change them, and you can see every grant on one screen.
Practice before production
Rehearsal copies
Every workspace comes with a rehearsal copy: the same systems, the same shape of data, none of the consequences. In rehearsal, emails collect in an outbox that never sends and record changes land on the copy, so you can read exactly what a routine would have done before it ever does it.
Rehearsal also owns the clock. A review that chases sign-offs across two weeks can be fast-forwarded through those weeks in minutes, so you watch the whole story, reminders and all, in one sitting. Rehearsal runs are always clearly marked; nothing about them is ever confused with production.
Where people decide
Checkpoints
A checkpoint is a moment where a run stops and waits for a person. There are three kinds, and each one is a distinct, recorded act:
Approve the plan
Before a run starts on anything real, the plan is laid out as plain sentences for a named person to approve, edit, or send back.
Answer a question
Mid-run, a routine can stop and ask. Does this exception stand? Is this document acceptable? The run waits for the answer, and the answer is recorded with the name of the person who gave it.
Resume a pause
Anyone with the right role can pause a run at any moment. It resumes only when a person says so, and both moments land in the record.
Checkpoints are assigned to people or teams, carry deadlines, and say up front what happens if nobody answers in time. Held items appear in one inbox so nothing waits in silence.
Spending, capped
Budgets
Every run carries a spending cap you set per routine, such as up to $75 per run for the access review. While a run is moving you see three numbers: the cap, what is spent, and what is set aside for work in flight.
As spending nears the cap you get a clear warning. At the cap, the run stops and holds for a person. There is no mode where a routine quietly keeps spending.
Proof on demand
Evidence export
Every run keeps its record: each step, each decision, each file it produced, and the named person behind every judgment call. When an auditor asks, you export an evidence binder from any run: a single archive with the files, a manifest, and checksums.
The binder is built for handing over as-is. No screenshots, no reconstruction after the fact, no asking engineering for a favor.
See a routine run with your own eyes
We will walk you through a live rehearsal, checkpoints and all, in about thirty minutes.