EAG puts one governed, natural-language front door on your entire backend estate β modern or legacy β so any AI agent can reach every system by intent, with every call identity-scoped to the real user and fully audited. Think enterprise service bus, but for the agent era.
Self-hosted: Docker β Azure Container Apps Β· on-prem Β· air-gappedSee how it works — the architecture, end to end ›
discover
The agent asks in plain language; each user sees only the tools their identity is scoped to
govern
Tier policy + per-user identity, and writes above the line park for a named human approver
invoke + audit
Proxied to the right backend as the real user; every call logged, and each outcome signed
Enterprise systems speak REST, SOAP, OData. Agents speak natural language. EAG is the layer in between β one canonical, plain-language tool catalog fronting every backend, governed on every call.
Describe a system in plain language and EAG builds the connector itself β it probes the API, proposes the tools, tests them, and writes the manifest once a human approves. Then it watches every connection and repairs them when a backend shifts underneath you. The engine is Prava Loom, and it is governed by the same gateway it builds for: its own writes are attested in your audit trail as an agent, under the same ceiling as anything else.
A single, stable, natural-language contract agents route on. EAG maps each canonical tool to the right backend call. Descriptions are written for the model, so the agent's LLM matches them from any language. EAG itself never sees the user's language β only the resulting tool call β so execution and governance are language-independent by construction. Eval-verified: a Spanish request routes to the same tool, byte-identical, and returns the caller's own data.
Entra SSO in; OAuth On-Behalf-Of downstream where the backend supports it, so its own row-level security applies. Elsewhere EAG resolves the caller and filters to their rows β the identity on every call is the real user, never an anonymous βthe appβ.
Read / write / privileged tiers with policy gates: confirm-before-write, privileged actions blocked or approval-gated. The agent can't do more than the caller's role allows.
A gated write parks instead of executing. The approver — a group, a named person, or the requester's own manager read live from your directory — decides in the console. Approval unlocks a single-use grant bound to the exact arguments, and the agent re-runs the identical call under the requester's own token: the write lands as them, never as EAG, which holds no credential that outlives a request. Change one argument and it is a new approval.
Every outcome is signed with Ed25519 and written to a database you own — Dataverse, Azure SQL, Snowflake — carrying requester, approver, and a hash of the exact arguments. Alter a row and verification fails against the public key. Agents can certify their own decisions too, and the gateway stamps the requester from the verified token, so the “who” is never self-reported.
The agent's identity comes from the token's azp claim — asserted by your identity provider, not claimed by the caller. A registered agent gets a ceiling intersected with its user's scopes, so a read-only research agent cannot write even when the person running it can. Registration can only ever narrow access, never widen it. Disable an agent and it stops for everyone, at once.
Every call recorded β user, tool, system, outcome, latency. A ready-made compliance trail and seat-metering feed, exportable to your SIEM. The audit is the proof, not a vibe.
REST, Workday RaaS, OData, SQL β modern APIs and legacy systems alike, added with a manifest and the console's Connect dialog (validate before you enable). Federate anything that already speaks MCP with zero driver code.
You license the catalog, not the backends. Swap ServiceNow β Jira or SAP ECC β S/4HANA one tool at a time, with a rollback toggle and an audit trail β and your agents never change.
One signed-in console runs the whole estate: flip systems on and off, connect backends with validate-before-enable, author tool-to-table mappings against live metadata, watch every call stream in, and manage user roles β no YAML required for day-two ops.
Answer "what would this user see?" before they ask. Probe any scope set and get the exact tool list that identity would be served β allowed, gated, or hidden, with the policy reason β governance you can demonstrate, not assert.
No API yet? Model a target system in Dataverse, serve it live and governed through the same canonical catalog, and prove the agent experience on staged data. When you're ready, repoint the manifest to the real backend β and all agent traffic switches in seconds. Model β Stage β Prove β Repoint β Production.
One container, one config-per-customer. A signed key unlocks your tier β verified offline, so it runs air-gapped with no phone-home. When it ships, every install will start with a trial — every feature unlocked.
One image, config per customer. Single-tenant, self-hosted β your systems never leave your cloud.
Docker β Azure Container Apps, App Service, on-prem, or air-gapped. One governed image; the tier is unlocked by an offline license key.
Point EAG at Entra, Okta, Auth0, Keycloak — any OIDC provider; a first-boot wizard discovers it for you. Admins sign in to the console over OIDC; agent callers present real tokens, exchanged per-user via OBO where the backend supports it. Map your existing IdP groups to scopes and access is managed where your people already are.
Wire each backend from the Connect dialog or a manifest β validate before enabling. Federate anything that already speaks MCP. Set gating and rate limits per system.
Register EAG as one MCP endpoint. Copilot Studio is verified end to end with a step-by-step runbook; Azure AI Foundry, Amazon Bedrock, Claude and any other MCP client connect the same standard way. That single entry now fronts your whole governed fleet.
16 native connectors built on 14 drivers, plus 8 federated MCP templates — fronted by 68 plain-language tools. Your agents route on the catalog, so a backend can be swapped, added or retired underneath a tool without touching a single agent.
BambooHR, SAP SuccessFactors, UKG Pro, Workday
Jira Service Management (service desk), ServiceNow (HRSD), ServiceNow (ITSM knowledge), ServiceNow (native MCP Server), Zendesk
Confluence, Notion
Azure DevOps, Jira (work items)
GitHub, Microsoft 365
Dynamics 365 (CRM), HubSpot (CRM), Salesforce (CRM)
Dynamics 365 (Finance & Operations), SAP S/4HANA (ERP)
Databricks, Snowflake, SQL database
Microsoft Entra
See all 24 connectors, what each covers, and how identity flows →
A governed layer beats point-to-point integrations that multiply with every agent.
| Direct Integrations | Prava EAG | |
|---|---|---|
| Identity | β Shared service account β everyone is "the app" | β The caller on every call β OBO where supported, per-user scoping elsewhere |
| Governance | β Whatever the raw API allows | β Tier gates, confirm-to-write, privileged blocked |
| Audit | β None, or scattered per system | β Every call logged with identity + outcome, exportable |
| Adding a backend | β A new integration for every agent | β One manifest β every agent gets it at once |
| Swapping a vendor | β Rebuild every agent that touched it | β Toggle it, one tool at a time β agents unchanged |
| Tool discovery | β Static tool dumps, English-only | β Natural-language catalog β any input language, identical governed call |
| Agent reach | β Tied to one agent platform | β Any MCP agent β Copilot Studio, Foundry, Bedrock, Claude |
Single-tenant and self-hosted. EAG runs where your data already lives and talks only to the systems you connect.