Integrations
Scoped access to the tools you already use.
Connect a tool once with read scopes. Grant each agent only the subset it needs. Write scopes unlock after one reviewed run, and every token sits in an encrypted vault you can revoke in a click.
Least privilege, by default.
Adapters declare small scope bundles: draft, label, send. The admin approves a union for the connection; each agent receives a subset; the credentials accessor fails closed outside it.
- Gmail, Google Calendar, Drive, Slack, Notion, HubSpot, Stripe and more
- Per-agent grants, revocable individually
- Disconnecting pauses the agents that depended on it
- Gmaildraft, labelMercer, Sol, Ines
- HubSpotread · write after sign-offMercer, Ada
- NotionreadAda, Sol
- StripereadInes, Nico
- Slackread #support · post after sign-offNico
Tokens in a vault, never in a prompt.
OAuth tokens are envelope-encrypted with per-row data keys under a rotating key-encryption key. Plaintext exists only inside the adapter call and never reaches a log, a transcript or the model.
- AES-256-GCM per row, key rotation without re-encrypting
- Refresh five minutes before expiry, single-flight
- Provider revocations pause dependent runs
- 14:02Mercer sent 41 emails · approved by Yasmin
- 13:58Mercer drafted the update
- 13:51Mercer read 3 Notion pages
- 13:50Yasmin delegated the brief
Append-only · hash-chained · exportable
Details
What is in the box.
Gmail and Microsoft 365: read, label, archive and draft. Sending always waits for a sign-off.
Calendar and files
Google Calendar, Google Drive and Notion for the context agents read before they write.
CRM and support
HubSpot, Salesforce, Attio, Intercom and Zendesk: read broadly, write only after approval.
Finance
Stripe, Xero and QuickBooks, read-only until a person reviews the first month-end run.
Work tracking
Linear, GitHub and Airtable for deliverables that land where the team already works.
Anything else
Bring your own tools through MCP servers. Planned for the Business tier.
Questions
Before you hand anything over.
Do you store my passwords?
No. Integrations use OAuth; we hold tokens, not passwords, and the tokens are encrypted at rest in a vault with rotation.
Can I see what an agent read?
Yes. Every tool call is a step on the progress timeline with its scope and result, and it is in the activity log.
What if I disconnect a tool mid-run?
Running delegations that depend on it pause with a reason, and the agents that used it are paused until you reconnect.

Hand it off.
Your first delegation takes a minute. Your first sign-off takes a second.