Governed Connectors · the tool layerEnableable

Every tool. Every worker. One roof — with a provable record

Connect the tools your business runs on — then watch one call pass the gate that governs them all.

The gate machine

Watch one call get governed

It asks, it does not act

gate closedmcp:crm.query · proposed

What you can wire in

  • SlackLive
  • GmailLive
  • GitHubLive
  • Coding CLILive
  • Any MCP serverstreamable-HTTP / SSEEnableable
  • Desktop ReachEnableable
Slack
Gmail
GitHub
Database
Desktop
Governor gatefirst use asks you · policy on every call · fails closed

signed on the chain — mcp:id.tool · params hashed

The connector ecosystem

More than a handful — connect what your business runs on

Four integrations go in with a token and are live today: Slack, Gmail, GitHub and coding CLIs. Everything below is reachable because Pai connects to any MCP tool server — point it at the ones you use, and each becomes a governed action. Live = own-token today. The rest = connect via MCP (enableable) — we don't pre-claim a tested bridge for each.

Comms & inbox

Slack Gmail WhatsAppMicrosoft TeamsDiscordTelegramOutlookIntercom

Dev & code

GitHub Coding CLI GitLabLinearJiraSentryCircleCIVercel

Data & sheets

PostgresMySQLMongoDBSupabaseSnowflakeGoogle SheetsAirtableBigQuery

CRM & sales

HubSpotSalesforcePipedriveZohoAttioApollo

Finance & commerce

StripeShopifyQuickBooksRazorpayZoho BooksXero

Docs & knowledge

NotionConfluenceGoogle DriveSharePointObsidianGuru

PM & tickets

AsanaClickUpMondayTrelloZendeskFreshdesk

Cloud & storage

AWSGoogle CloudCloudflareS3 / object storeDropboxBox

Web & search

Brave SearchFetch / scrapeMapsPuppeteer browserRSSWebhooks

Your desktop

FilesShellLocal appsAnything via a host MCP server

Live own-token, shipping today  ·  plain tag = connect the MCP server (enableable). Whatever you wire in, first use asks you and every call is signed on the chain.

Connectors — FAQ

Two ways in. First, own-token integrations that ship live today: paste your org's Slack, Gmail, GitHub and coding tokens once and every Pie can use them, each use recorded on the chain. Second, any MCP tool server — the open Model Context Protocol standard — which lets you point the pod at your databases, your SaaS, community tools, or a server you wrote yourself. That connector path ships inside the stack and switches on during setup.

The difference is the gate. In most agent products, once a tool is connected the agent can call it freely. In PAI every connected tool becomes a governed action: it's classified by risk, its first use asks you, risky classes park for your approval, and every single call is signed into a tamper-evident audit chain with its parameters hashed. The tool doesn't escape governance by being connected — the gate travels with it.

In the pod's own encrypted vault, on your infrastructure — never in our control plane, not in our cloud and not in yours. Integration tokens are stored write-only: the people whose Pies use them never hold them, and our systems only ever see booleans (configured / not), never the secret. A connector's endpoint credentials are AES-256-GCM encrypted at rest.

Yes, safely — that's Desktop Reach. You run any MCP tool server on your own machine (files, shell, an app), and the pod reaches OUT to it as a connector. Nothing reaches into your machine; the pod calls out over a connection you allow. Because host tools are higher-risk, non-read actions default to a per-call approval, and an org policy can forbid desktop connectors across a whole fleet with one switch.

Several things. Tool descriptions are treated as untrusted and an admin sees them at add-time, before anything runs. First use of every tool asks you. If a server silently changes a tool's shape (a rug-pull), the input-schema hash changes, the tool loses its approval and has to earn it again. Endpoints are checked against an SSRF denylist so a connector can't be pointed at internal infrastructure. And the kill switch still stops everything, instantly.

We label it honestly. Own-token integrations (Slack/Gmail/GitHub/coding) are live and tested today. The any-MCP-tool connector registry and Desktop Reach are enableable — they ship inside the stack and are switched on during setup, backed by tests. We don't call something live until it runs in our stack with machine-checked proof, and the whole capability list on the Possibilities page carries its honest status.

Connect everything — without surrendering control

See every connector capability alongside the rest — each with its honest status — then choose your plan.

Explore the possibilities →