The data gateway · under human control

Give agents access. Keep people in charge.

Connect systems, approve access, inspect agent runs, and answer security questions from one control surface. SDK workflows and MCP assistants use the access and execution history governed here.

Controlled · Governed · Contextual access, under review

Grant it, watch it, answer for it.

Agents still need human workflows around them. Someone has to connect Salesforce, approve a service account, complete OAuth, share access, inspect a failed run, and answer security's questions. The web app gives those workflows a durable place to live.

connectionslive
Caller · your admins
amina@acmeadmin console
granted once in the web app
MarcoPolo gateway

Provisioned here · inherited by every surface

approved systems
Salesforcesales_read
Snowflakeanalytics_ro
Postgresapp_read
Jiraissues_read
01

Secure Connections

Create connections, complete consent, test readiness, rotate credentials, and control who can use each connection. One approved connection can support an SDK app and an MCP assistant.

Secure connections
workspace · web applive
# Saved once. Re-run by anyone approved.$ run "Slipped deals · Q2"→ salesforce_opportunities  18 rows→ jira_issues               64 rows✓ slipped_deals_joined      14 rows$ share result#7c21 --with revops# Reviewed in the web app · same trail.
02

Managed Database Execution Environment

Review saved operations, inspect workspace runs, preview result handles, and understand which query or command produced an output.

Governed workspace
auditlive
tenantacmeadminamina@acmeconnectionsalesforcegrantsales_readshared withrevops
connection.grantwebapp

Who approved what, and when · reviewable in the console

req#a91csealed to your SIEM
03

Governance & Auditing

Trace activity by actor, connection, operation, execution, result, or effect. Admins can see how access is being used across every agent surface.

Trust and governance
Who holds the controls

The gateway is configured before agents touch it.

Give teams a place to approve access before agents use it, then inspect what happened after the work runs. Setup, sharing, review, and audit stay visible to people.

  1. People approve

    Users and admins handle credential setup, consent, sharing, service-account access, and review before agents start using the access.

  2. Agents use what is approved

    SDK workflows and MCP assistants consume the same approved connections and execution environment.

  3. Runs remain visible

    Execution history, result handles, errors, and exports remain inspectable after an agent finishes the task.

  4. Controls remain

    When access changes in the web app, the boundary changes for every consuming surface.

Scenarios

Owned by admins, analysts, and security.

Admin provisions once

An admin connects Salesforce, shares it with a service account, and verifies readiness. A customer-facing agent then uses that connection through the SDK.

Webapp provisioningSDK product flow

Analyst reviews an agent run

An assistant runs a query through MCP and returns a result-backed answer. Later, a human opens the web app to inspect the execution history and preview the result.

MCP executionWebapp review

Security investigates access

A security lead filters audit activity by connection, actor, and execution, then exports the relevant trail for an internal review.

Shared auditWebapp investigation
For admins, security, and ops

When setup, review, and governance need somewhere durable to live.

Book a demo
FAQ

What teams ask before they roll out.

Is the web app separate from the SDK and MCP surfaces?

No. It manages the same connections, operations, executions, results, identities, and audit events that SDK and MCP use.

Can the web app be the only provisioning surface?

Yes. Many teams will provision and govern access in the web app, then let SDK applications or MCP assistants use only approved runtime capabilities.

Can admins revoke access for agent workflows?

Yes. Access changes in the control surface apply at the shared platform boundary, not inside one individual agent integration.

Give the data gateway a control surface.

Provision, review, and govern the data gateway your SDK applications and MCP assistants use.