Prava EAG icon
πŸ” One governed endpoint Β· Every call as the real user Β· Human-approved writes

The API gateway for AI agents.
Every system, in the language of agents.

EAG puts one governed, natural-language front door on your entire backend estate β€” modern or legacy β€” so any AI agent can reach every system by intent, with every call identity-scoped to the real user and fully audited. Think enterprise service bus, but for the agent era.

Self-hosted: Docker β†’ Azure Container Apps Β· on-prem Β· air-gapped

See how it works — the architecture, end to end ›

Model Context Protocol Entra SSO Β· OIDC Per-User OBO Copilot Studio Amazon Bedrock Azure AI Foundry Any MCP Agent Signed Receipts Agent Registry Language-Independent
discover The agent asks in plain language; each user sees only the tools their identity is scoped to
β†’
govern Tier policy + per-user identity, and writes above the line park for a named human approver
β†’
invoke + audit Proxied to the right backend as the real user; every call logged, and each outcome signed

Any API, in the language of agents

Enterprise systems speak REST, SOAP, OData. Agents speak natural language. EAG is the layer in between β€” one canonical, plain-language tool catalog fronting every backend, governed on every call.

🧡

Build Β· Watch Β· Heal

Describe a system in plain language and EAG builds the connector itself β€” it probes the API, proposes the tools, tests them, and writes the manifest once a human approves. Then it watches every connection and repairs them when a backend shifts underneath you. The engine is Prava Loom, and it is governed by the same gateway it builds for: its own writes are attested in your audit trail as an agent, under the same ceiling as anything else.

πŸ—‚οΈ

One Canonical Tool Catalog

A single, stable, natural-language contract agents route on. EAG maps each canonical tool to the right backend call. Descriptions are written for the model, so the agent's LLM matches them from any language. EAG itself never sees the user's language β€” only the resulting tool call β€” so execution and governance are language-independent by construction. Eval-verified: a Spanish request routes to the same tool, byte-identical, and returns the caller's own data.

πŸ”

Identity-Aware, Per User

Entra SSO in; OAuth On-Behalf-Of downstream where the backend supports it, so its own row-level security applies. Elsewhere EAG resolves the caller and filters to their rows β€” the identity on every call is the real user, never an anonymous β€œthe app”.

πŸ›‘οΈ

Governed by Tier

Read / write / privileged tiers with policy gates: confirm-before-write, privileged actions blocked or approval-gated. The agent can't do more than the caller's role allows.

A Human Signs Off on Writes

A gated write parks instead of executing. The approver — a group, a named person, or the requester's own manager read live from your directory — decides in the console. Approval unlocks a single-use grant bound to the exact arguments, and the agent re-runs the identical call under the requester's own token: the write lands as them, never as EAG, which holds no credential that outlives a request. Change one argument and it is a new approval.

🔒

Signed Decision Receipts

Every outcome is signed with Ed25519 and written to a database you own — Dataverse, Azure SQL, Snowflake — carrying requester, approver, and a hash of the exact arguments. Alter a row and verification fails against the public key. Agents can certify their own decisions too, and the gateway stamps the requester from the verified token, so the “who” is never self-reported.

🪪

Know Which Agent Acted

The agent's identity comes from the token's azp claim — asserted by your identity provider, not claimed by the caller. A registered agent gets a ceiling intersected with its user's scopes, so a read-only research agent cannot write even when the person running it can. Registration can only ever narrow access, never widen it. Disable an agent and it stops for everyone, at once.

🧾

Audited End to End

Every call recorded β€” user, tool, system, outcome, latency. A ready-made compliance trail and seat-metering feed, exportable to your SIEM. The audit is the proof, not a vibe.

πŸ”Œ

Any Backend, Even Legacy

REST, Workday RaaS, OData, SQL β€” modern APIs and legacy systems alike, added with a manifest and the console's Connect dialog (validate before you enable). Federate anything that already speaks MCP with zero driver code.

♻️

Migration Insurance

You license the catalog, not the backends. Swap ServiceNow β†’ Jira or SAP ECC β†’ S/4HANA one tool at a time, with a rollback toggle and an audit trail β€” and your agents never change.

πŸ–₯️

Admin Console Built In

One signed-in console runs the whole estate: flip systems on and off, connect backends with validate-before-enable, author tool-to-table mappings against live metadata, watch every call stream in, and manage user roles β€” no YAML required for day-two ops.

πŸ”Ž

Identity Probe

Answer "what would this user see?" before they ask. Probe any scope set and get the exact tool list that identity would be served β€” allowed, gated, or hidden, with the policy reason β€” governance you can demonstrate, not assert.

πŸ§ͺ

Stage It, Then Scale It

No API yet? Model a target system in Dataverse, serve it live and governed through the same canonical catalog, and prove the agent experience on staged data. When you're ready, repoint the manifest to the real backend β€” and all agent traffic switches in seconds. Model β†’ Stage β†’ Prove β†’ Repoint β†’ Production.

πŸ”‘

One Image, Offline-Licensed

One container, one config-per-customer. A signed key unlocks your tier β€” verified offline, so it runs air-gapped with no phone-home. When it ships, every install will start with a trial — every feature unlocked.

Stand It Up in Your Own Tenant

One image, config per customer. Single-tenant, self-hosted β€” your systems never leave your cloud.

1

Run the Container

Docker β†’ Azure Container Apps, App Service, on-prem, or air-gapped. One governed image; the tier is unlocked by an offline license key.

2

Connect Your Identity

Point EAG at Entra, Okta, Auth0, Keycloak — any OIDC provider; a first-boot wizard discovers it for you. Admins sign in to the console over OIDC; agent callers present real tokens, exchanged per-user via OBO where the backend supports it. Map your existing IdP groups to scopes and access is managed where your people already are.

3

Connect Your Systems

Wire each backend from the Connect dialog or a manifest β€” validate before enabling. Federate anything that already speaks MCP. Set gating and rate limits per system.

4

Point Your Agents at It

Register EAG as one MCP endpoint. Copilot Studio is verified end to end with a step-by-step runbook; Azure AI Foundry, Amazon Bedrock, Claude and any other MCP client connect the same standard way. That single entry now fronts your whole governed fleet.

24 connectors, one catalog

16 native connectors built on 14 drivers, plus 8 federated MCP templates — fronted by 68 plain-language tools. Your agents route on the catalog, so a backend can be swapped, added or retired underneath a tool without touching a single agent.

HR and human capital

BambooHR, SAP SuccessFactors, UKG Pro, Workday

ITSM, cases and policy

Jira Service Management (service desk), ServiceNow (HRSD), ServiceNow (ITSM knowledge), ServiceNow (native MCP Server), Zendesk

Knowledge and content

Confluence, Notion

Dev and delivery

Azure DevOps, Jira (work items)

Productivity and collaboration

GitHub, Microsoft 365

CRM and sales

Dynamics 365 (CRM), HubSpot (CRM), Salesforce (CRM)

ERP, finance and operations

Dynamics 365 (Finance & Operations), SAP S/4HANA (ERP)

Data and analytics

Databricks, Snowflake, SQL database

Identity and access

Microsoft Entra

See all 24 connectors, what each covers, and how identity flows →

EAG vs. Wiring Agents to Systems Directly

A governed layer beats point-to-point integrations that multiply with every agent.

Direct Integrations Prava EAG
Identity βœ— Shared service account β€” everyone is "the app" βœ“ The caller on every call β€” OBO where supported, per-user scoping elsewhere
Governance βœ— Whatever the raw API allows βœ“ Tier gates, confirm-to-write, privileged blocked
Audit βœ— None, or scattered per system βœ“ Every call logged with identity + outcome, exportable
Adding a backend βœ— A new integration for every agent βœ“ One manifest β€” every agent gets it at once
Swapping a vendor βœ— Rebuild every agent that touched it βœ“ Toggle it, one tool at a time β€” agents unchanged
Tool discovery βœ— Static tool dumps, English-only βœ“ Natural-language catalog β€” any input language, identical governed call
Agent reach βœ— Tied to one agent platform βœ“ Any MCP agent β€” Copilot Studio, Foundry, Bedrock, Claude

Your Tenant. Your Systems. Your Rules.

Single-tenant and self-hosted. EAG runs where your data already lives and talks only to the systems you connect.

βœ“ Runs in Your Tenant βœ“ Per-User OBO βœ“ Entra / OIDC SSO βœ“ Air-Gap Friendly βœ“ Full Audit Trail βœ“ Role-Based Console (Admin / Read-Only) βœ“ Secrets Never in the Image

Built With

Model Context Protocol TypeScript Node.js Microsoft Entra ID OAuth 2.0 On-Behalf-Of Azure Container Apps Docker OIDC Ed25519 Licensing Streamable HTTP + stdio