Every tool. Every worker. One roof — with a provable record
Connect the tools your business runs on — then watch one call pass the gate that governs them all.
Watch one call get governed
It asks, it does not act
gate closedmcp:crm.query · proposed
What you can wire in
- SlackLive
- GmailLive
- GitHubLive
- Coding CLILive
- Any MCP serverstreamable-HTTP / SSEEnableable
- Desktop ReachEnableable
signed on the chain — mcp:id.tool · params hashed
More than a handful — connect what your business runs on
Four integrations go in with a token and are live today: Slack, Gmail, GitHub and coding CLIs. Everything below is reachable because Pai connects to any MCP tool server — point it at the ones you use, and each becomes a governed action. Live = own-token today. The rest = connect via MCP (enableable) — we don't pre-claim a tested bridge for each.
Comms & inbox
Dev & code
Data & sheets
CRM & sales
Finance & commerce
Docs & knowledge
PM & tickets
Cloud & storage
Web & search
Your desktop
Live own-token, shipping today · plain tag = connect the MCP server (enableable). Whatever you wire in, first use asks you and every call is signed on the chain.
Six connectors, every tool and its gate
Four are live today; two switch on at setup. Each page lists the tools, the gate on every one, what it cannot do, and where the credential lives.
Slack
LiveYour own bot token, pasted once, reaches every Pie its role allows.
Every tool, and its gate →Gmail
LiveDrafting is free; sending is a gate.
Every tool, and its gate →GitHub
LiveIt opens issues and proposes changes.
Every tool, and its gate →Coding CLI
LiveA terminal on the same leash as everything else.
Every tool, and its gate →Any MCP server
EnableableBring your own tools.
Every tool, and its gate →Desktop Reach
EnableableThe pod drives your machine for the things that have no API.
Every tool, and its gate →Keep reading
Connectors are the reach. These are the controls that make the reach safe.
Founder OS — the organization control plane
Where the connected work lands: a private operating plane per venture, authored by your governed AI.
Managed AI agents that don't get stuck
The Supervisor watches every run — including tool calls — with a Monitor and kill switch in your pocket.
Security at PAI
Where tokens live, what leaves your premises, and how the audit chain is signed and verified offline.
Connectors — FAQ
Two ways in. First, own-token integrations that ship live today: paste your org's Slack, Gmail, GitHub and coding tokens once and every Pie can use them, each use recorded on the chain. Second, any MCP tool server — the open Model Context Protocol standard — which lets you point the pod at your databases, your SaaS, community tools, or a server you wrote yourself. That connector path ships inside the stack and switches on during setup.
The difference is the gate. In most agent products, once a tool is connected the agent can call it freely. In PAI every connected tool becomes a governed action: it's classified by risk, its first use asks you, risky classes park for your approval, and every single call is signed into a tamper-evident audit chain with its parameters hashed. The tool doesn't escape governance by being connected — the gate travels with it.
In the pod's own encrypted vault, on your infrastructure — never in our control plane, not in our cloud and not in yours. Integration tokens are stored write-only: the people whose Pies use them never hold them, and our systems only ever see booleans (configured / not), never the secret. A connector's endpoint credentials are AES-256-GCM encrypted at rest.
Yes, safely — that's Desktop Reach. You run any MCP tool server on your own machine (files, shell, an app), and the pod reaches OUT to it as a connector. Nothing reaches into your machine; the pod calls out over a connection you allow. Because host tools are higher-risk, non-read actions default to a per-call approval, and an org policy can forbid desktop connectors across a whole fleet with one switch.
Several things. Tool descriptions are treated as untrusted and an admin sees them at add-time, before anything runs. First use of every tool asks you. If a server silently changes a tool's shape (a rug-pull), the input-schema hash changes, the tool loses its approval and has to earn it again. Endpoints are checked against an SSRF denylist so a connector can't be pointed at internal infrastructure. And the kill switch still stops everything, instantly.
We label it honestly. Own-token integrations (Slack/Gmail/GitHub/coding) are live and tested today. The any-MCP-tool connector registry and Desktop Reach are enableable — they ship inside the stack and are switched on during setup, backed by tests. We don't call something live until it runs in our stack with machine-checked proof, and the whole capability list on the Possibilities page carries its honest status.
Connect everything — without surrendering control
See every connector capability alongside the rest — each with its honest status — then choose your plan.