+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
● B2B offer — Group & international

Multi-site: each entity isolated, the group supervised

A multi-site group carries a double requirement: each entity must stay in control of its data, and group management must keep an overall view. This system deploys agents site by site with strict data isolation, and a group-level supervision that sees the activity without accessing the content. Hosted in France: each entity's data stays within its own perimeter.

Hosted in France Each entity's data isolated GDPR & AI Act: governed deployment Human oversight

Updated on

Deployed in a few weeks
Multi-agent, multi-site · hosted in France
What are the agents doing across all the sites?
Consolidated group view: active agents per site, volume handled, availability over the period.
This view covers activity, not content: each entity's data stays within its own perimeter.
Any shortfall in availability against the commitments is shown.
🔗 Sourced · activity indicators, with no access to content
Can head office look at the cases handled at a given site?
Isolation by entity rules that out by design: each site keeps its data within its own perimeter.
Opening access between entities is a matter for group governance, with the formalities the GDPR imposes between separate legal entities.
✎ Support · isolation maintained, a governance decision
Local inference · no data outside the EU
Deployment hosted in France
Sovereign by designLocal inference or hosting in France
GDPR & AI Act: governed deploymentTraceability & human oversight
TurnkeyDesigned, installed and operated for you
The group IT department decidesThe agent prepares, never rules
✦ In brief

A Blue Lemon Agent multi-site system deploys agents site by site with strict data isolation by entity, and a group-level supervision covering activity and availability — with no access to content. Opening access between entities is a matter for group governance. Hosted in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.

100%
hosted in France in the target architecture
0
transfer outside the EU in the target architecture
6
uses deployable site by site
0
decision taken without human approval

These figures describe our offer, not results measured at a client. How large the gain is on the number of sites, entities and agents deployed is confirmed by a pilot.

The context

What does a multi-site deployment bring to your group?

A group needs an overall view; each entity needs to stay in control of its data. The two are compatible.

! The issue

A group deployment has to satisfy both data isolation by entity and overall supervision. These two requirements are reconciled by keeping content, which stays within each perimeter, strictly separate from activity indicators, which flow up to the group. That is the architecture we have chosen.

Our answer

The group IT department follows activity, volume and availability across every site, together with any shortfall against the service commitments. Content, for its part, does not cross entity borders: opening access between entities is a governance decision, with the formalities the GDPR imposes. Local inference or isolated resources hosted in France, site by site.

The decisive point

Each group entity's data: sovereignty & compliance

A group deployment touches the data of several legally separate entities. Here is how the architecture keeps them apart.

Local inference

The agent can run on a machine belonging to your organisation: no entity data leaves its site's network.

Hosting in France

Otherwise, a dedicated and isolated resource hosted in France, under French law — your sites, your subsidiaries and their agents: processing and access within the European Union targeted by the architecture.

Reduced extraterritorial exposure

For each group entity's data, the architecture aims to reduce exposure to the Cloud Act and FISA 702; being located in France or in the European Union does not, on its own, guarantee immunity.

Isolated resource

No pooling: an environment strictly dedicated to your group and the way its entities are organised.

Isolation by entity, by design

Content stays within each entity's perimeter; only activity indicators flow up to the group. Encryption, role-based access (RBAC) and logging site by site.

AI Act: governed deployment

The agent is strictly in support; no access between entities is opened automatically; traceability and human oversight from end to end.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • Roles and permissions are configured and accepted for the identities and systems actually connected.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For entities subject to particular local regulation or to sector confidentiality, SecNumCloud and reinforced hosting are options depending on your requirements. A single architecture is designed to answer both the GDPR and extraterritorial exposure. Designed for deployment in line with the GDPR and the AI Act, after the processing, roles and context-specific risks have been assessed.
Demonstration

See the agent at work

5 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The company in this demonstration

Fictional company

Vaudrey Group — water treatment equipment, six legally separate entities

Sector
Water industry — design, manufacture and operation of treatment plants for local authorities and industrial clients
Headcount
1,240 staff across six entities; the group IT department has 14 people, 3 of them assigned to the agent programme
Perimeter served
Six entities: Rouen (industrial head office), Bourges, Orléans, Lyon, Namur in Belgium and Zaragoza in Spain — all inside the European Union
Volume
5,400 documents processed each month across all sites; six use cases deployable per site; a first deployment of 84 person-days
Tools in place
Three different ERP systems, two document management systems, one group mail service and one group directory — the agent plugs into them, nothing is replaced
Who decides
The group IT director arbitrates deployments; each entity director remains in charge of that entity's data; the group data protection officer signs off on any cross-entity access
Room for improvement
The first site took 84 person-days over 22 weeks; the group activity report is assembled by hand, 24 hours a month across six site contacts; verifying isolation absorbs 96 hours of audit a year

The Vaudrey Group is not trying to centralise its data — it is legally prevented from doing so, its six entities being separate — but to deploy the same agents everywhere without doing the same work six times, and to finally see activity as a whole. The agent runs on isolated resources hosted in France, one per entity, and plugs into the three ERP systems, the two document management systems and the group directory: it prepares, the IT department arbitrates, each entity director keeps control of their own data. The exchanges below span two quarters, from scoping to review.

This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.

Multi-agent, multi-site · hosted in France
I have read your six records of processing, your three ERP systems and the 214 application flows your teams declared. I draw a conclusion your programme file did not carry: your entities share 71 % of their document processing and 0 % of their data.
A record of processing is the written inventory every organisation keeps of what it does with personal data: what it is used for, where it comes from, who accesses it, how long it is kept.
What that gap means, and it is the gap that sets the gain: what can be pooled in your group is the architecture, never the data. Your six entities handle the same objects — supplier orders, project files, commissioning reports, complaints — with contents that have no reason to meet, and no right to without formalities.
The figure your own records carry: deploying Rouen cost 84 person-days over 22 weeks. Re-reading the acceptance reports, 73 of those 84 days produced architecture — directory connection, encryption, role-based access, logging, supervision templates, compliance file — and only 11 produced work specific to Rouen.
What that gives you on the five remaining entities: the architecture carries over as is. Deploying a site drops from 65 % to 9 % of a project's workload, i.e. 84 person-days → 12. Across five sites, 360 person-days that will not be spent — at the €520 fully-loaded daily cost your management accounting applies, €187,200.
What I propose: a deployment order that starts with Bourges rather than Lyon. Bourges shares Rouen's ERP: it is the site that fastest proves the platform really does carry over. If the platform holds at Bourges it holds everywhere; if it does not, you find out in three weeks instead of five months. The IT department arbitrates, I build the plan straight after. mapping_six-entities-and-deployment-order.pdf71 % shared processing, 0 % shared data
⛓ Sourced · six records of processing, 214 declared application flows, acceptance reports from the Rouen deployment
Our six entities share neither the same ERP nor the same internal rules. What actually gets reused?
Seven building blocks carry over as is, four are rebuilt at every site. That split is what makes the 12 person-days — and I will also give you the site where it did not hold.
What carries over, and why it has nothing to do with your ERP systems:
· Connection to the group directory — your accounts already exist, the agent creates no identity.
· Encryption in transit and at rest, set once.
· Role-based accessrights follow the job, not the person: a maintenance technician opens commissioning reports, not supplier files or contracts.
· Logging: who asked what, when, and what was approved.
· Supervision templates that feed the group view.
· The acceptance procedure — 34 checks to pass before go-live.
· The compliance file, copied and dated per entity.
What is rebuilt, and rightly so: the ERP connector, the business vocabulary, the document filing plan, and the entity's own approval rules — the only block where the entity director must spend time, and the one that belongs to them.
The figure that does not flatter me, and it matters more than the others: on the third site, Orléans, deployment took 5 weeks rather than 3. The cause is not the platform: Orléans runs the one ERP we had no connector for, and its acceptance testing took 19 person-days instead of 12. What I did with it: the connector is written, tested and added to the platform — Lyon, which runs the same ERP, came back to 12 person-days and 3 weeks. The cost was paid once, not four times.
What I propose next: writing the 34 acceptance checks into your service agreement, site by site. A written acceptance procedure is the only thing that stops a fast deployment becoming a rushed one — and you decide which checks are blocking. platform_what-carries-over-and-what-is-rebuilt.pdf7 blocks reused, 4 rebuilt, 34 acceptance checks
⛓ Sourced · acceptance reports from the first three sites, IT department timesheets
You advertise six use cases deployable per site. Which ones are they, and which pay off most?
All six have been live at Rouen for two quarters, and I rank them by what they returned, not by order of arrival.
· Supplier files and order matching — 1,900 documents a month at Rouen, the heaviest workload and the first gain.
· Commissioning reports: drafted on your templates from site records, reviewed by the works supervisor before signature.
· Replies to operating complaints, drawn from the project file and the contract.
· Document search across drawings, manuals and intervention reports, always pointing back to the source document.
· Preparation of public tender files — the administrative documents, never the technical offer.
· Contract deadline tracking: warranties, contract reviews, renewals.
What they returned at Rouen over two quarters: 1,640 hours of administrative work, 62 % of it on supplier files alone. The ranking matters more than the total: it tells you where to start on the five remaining entities, and it is not the same everywhere.
The nuance that avoids a disappointment: at Zaragoza the supplier workload is three times lighter than at Rouen — 300 documents a month against 1,900 — but operating complaints weigh twice as much. Same platform, different order of use cases. I have built the ranking for each of the six entities.
What I propose: open Bourges on three use cases, not six. Three use cases in three weeks beat six in eight — you measure sooner, and the next three are added without a further architecture acceptance round. The IT department decides, I start with whichever you name. six-use-cases_ranked-entity-by-entity.pdf1,640 hours returned at Rouen, a different order per site
⛓ Sourced · Rouen activity records over two quarters, document volumes of the six entities
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

What does the agent actually do?

A group foundation, agents site by site. All these uses work in support, subject to your approval.

Included in your agent The 3 capabilities essential to this promise are included, at no extra cost.
From 997 € excl. VAT / month

Deployment site by site

Installs the agents suited to each site, within its own perimeter.

Isolation by entity

Content does not cross entity borders.

Group-level supervision

Follows activity, volume and availability, without accessing content.

Controls and safeguards These 3 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Human arbitration of conflicts and irreversible decisions Observability of costs, timescales, quality, failures and safe stop Data protection, rights and human oversight
What the agent must be connected to These 2 connections are required for the agent to work. They concern your information system and are scoped during the audit.
Register of authorised agents and interface contracts Integration with existing tools without double entry
Does your need fall outside this?

In 15 minutes we identify the most relevant agent — without oversizing the project.

Book the free audit Build your agent
The gain

What does a group gain by sharing its foundation across sites?

By reusing the architecture from one site to the next, the effort of each deployment shifts towards its business content. How large the gain is depends on your volume and remains to be confirmed by a pilot.

Deploying on a new site
Today · redone on every project
Architecture reused
Tracking group activity
Today · done by hand
Supervision consolidated
Checking data isolation
Today · done by hand
Isolation by design
Indicative figures, not contractual, to be confirmed by a pilot on the number of sites, entities and agents deployed. Opening access between entities is a matter for group governance, with the formalities the GDPR imposes between separate legal entities.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Pricing

One package, one agent

A multi-site multi-agent system (deployment, isolation, group supervision), installed and operated for you. Prices exclude VAT — annual subscription, the time it takes for the gains to settle in for good.

Agility

Setup + controlled subscription

15,380 € excl. VAT setup
then 997 € excl. VAT/month — you invest at installation and pay a reduced subscription. Ideal for keeping the cost under control over time.
  • Installation, configuration and training for your teams
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, a dedicated and isolated resource
Order →
The simplest Serenity

All inclusive, no setup fee

1,852 € excl. VAT /month
all inclusive, immediate start. No upfront investment: a single subscription. Ideal for starting quickly and simply.
  • Setup included (installation, configuration, training)
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, managed end to end
Order →
100% Sovereign

On site, you own it

20,490 € excl. VAT setup
then 1,274 € excl. VAT/month · + hardware from 5,500 € (one-off purchase, in addition) — a sovereign computer installed on your premises, maintained remotely. Models run locally, your data returned at the end of the contract. 36-month commitment.
  • Hardware installed on your premises (you own it)
  • French / European AI models run locally
  • Secure remote maintenance (Pro support included)
Order →
Not included in the packages: AI consumption (model tokens), re-invoiced at real cost with no margin, and tracked in real time in your client area. Maintenance and supervision subscription for an initial term of 12 months for the Agility package, 24 months for the Serenity package and 36 months for the 100% Sovereign package, renewable; support levels (SLA 72 h / 24 h / 4 h) optional. Bespoke development, additional integrations or exceptional volumes are quoted separately. Support Monday to Friday, 9am to 6pm. Prices exclude VAT.
AI model: none of the AI models offered currently carries a fixed surcharge. When the selected model carries a cost, that cost is shown when you choose it, before you order, and re-invoiced at the cost incurred, with no mark-up; usage is billed at the publisher's price. Publishers' prices are published in US dollars: the amount re-invoiced is the amount in euros actually borne by Blue Lemon Agent on the publisher's invoice, at that invoice's exchange rate, with no commission or mark-up.
Included components and additional components Components included in the base offer: the Blue Lemon Agent software foundation, the AI models listed in the order journey, the standard channels (Microsoft Teams, Slack, WhatsApp Business, email, website chat, calendars, Microsoft 365 / Google Workspace, file storage, market VoIP telephony, professional social-media pages and accounts, Google Business Profile), hosting in France for the package chosen, backups, supervision, updates and support. If adapting the AI agent to your constraints, your needs or your requests requires other paid components — a third-party publisher's software licence, paid API access to one of your applications, hosting of health data, for which French law requires an HDS-certified host (art. L. 1111-8 of the French Public Health Code), SecNumCloud-qualified hosting, a speech synthesis service, particular hardware —, they are offered to you as an option or on quotation and re-invoiced at the cost incurred; nothing is committed without your written agreement. Where the artificial intelligence model you choose entails an additional cost, that cost is shown to you before you order and re-invoiced to you at the cost incurred, with no margin.
What to expect
Go-live 2 to 3 weeks
Agent designed, channels connected, team trained.
Steady state 4 to 7 weeks
After a few weeks of real use, once the agent's behaviour matches what you expect. Indicative estimate, adjusted to the options you keep. It is not a delivery commitment.
Our commitment

Four guarantees that matter to your group

Each entity's data stays with that entityLocal inference or isolated resources hosted in France, site by site; no data entrusted to a third party, no data used to train a model.
Data in France, under French lawEach group entity's data: minimisation and location in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
The group IT department keeps the decisionThe agent produces a multi-site deployment that is isolated and supervised, which can be checked and altered; no approval is automated.
Human oversight & traceabilityOn the number of sites, entities and agents deployed: systematic logging and tracking, in line with the AI Act.
Frequently asked questions

Your questions, our answers

Does group management have access to the sites' content?
No. Group-level supervision covers activity, volume and availability. Content stays within each entity's perimeter.
Can access be opened between two entities?
That is a group governance decision, and it requires the formalities the GDPR imposes between legally separate entities. The system never opens it of its own accord.
How does this differ from the agent platform?
The platform shares one foundation across a single perimeter; this system deploys several isolated perimeters with group-level supervision above them.
What do the service commitments cover?
Availability, response times and follow-up site by site, contracted according to how critical the agents deployed are.
Where is the data hosted?
In France, with local inference or on resources isolated site by site, with the deployment objective of processing and access operated within the European Union and an architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
How long does it take to deploy this system?
Several months as a rule, depending on the number of sites, entities and agents to deploy, after a free audit then phases of design, integration and testing.
Let's talk

Let's size up the potential across your group

15 minutes to frame your sites and your entities — hosted in France, supervised, with no commitment.