StableMindIntegrations
Sign inStart with ActionGate

SIO25 · Integration Studio

Connect the system.
Not the authority.

StableMind sits between AI agents and consequential enterprise action, so integration has to be more precise than “the API works.” This catalog shows the adapters, protocols, connector boundaries, credential infrastructure, SDKs and ecosystem machinery already present in the sealed engineering source, together with the rule that keeps them safe: reachability is capability, not permission.

The integration doctrine

An agent can reach a system and still have no authority to act in it.

01 · DISCOVER

Know what the integration can technically reach.

StableMind separates connector capability from semantic authority. An API scope, MCP tool registration, tenant role, OAuth token, vault lease or network route can describe what software is technically capable of reaching. None of those facts answers whether this machine may perform this consequential action against this target now.

02 · GOVERN

Bind the exact action before capability appears.

Authority Cloud resolves delegated power, ActionGate decides the semantic request, and an exact Action Permit constrains the allowed target, limits and time. Connector configuration therefore remains downstream of a decision boundary instead of becoming an accidental permission system.

03 · PROVE

Keep integration receipts distinct from consequence proof.

A connector may produce an attributable execution receipt. Evidence can later compare expected postconditions with independently observed state. The fact that an integration returned HTTP 200, a tool result, or a vendor success code does not by itself prove the intended consequence.

Source-backed catalog

Search the integration surface.

Every card below maps to source that already exists in the sealed ActionGate lineage. “Engineering ready” means there is source-backed engineering material and testable contracts. It does not mean a legal customer has connected the integration, that an external vendor has certified it, or that StableMind has exercised it in a live customer environment.

12 integration records visible.

Agent & Tool Runtime

MCP Governance

Govern Model Context Protocol tool calls as semantic action requests before consequential tool execution. Exact tool, arguments, target and authority bindings remain subject to ActionGate policy.

SOURCE
AG35
STATE
ENGINEERING_READY
PROTOCOL
MCP
TRUTH
ENGINEERING

Boundary: MCP connectivity does not grant tool authority. A reachable tool still requires current delegated authority and an exact decision.

Enterprise SaaS

Microsoft Enterprise

Source-backed Microsoft enterprise action evaluation with exact profile and authority binding. Designed to govern semantic enterprise actions without equating tenant access, app registration or token possession with permission.

SOURCE
AG38
STATE
ENGINEERING_READY
PROTOCOL
Microsoft enterprise adapter
TRUTH
ENGINEERING

Boundary: Tenant access and Microsoft credentials are capability inputs, never delegated machine authority.

Enterprise SaaS

Salesforce Enterprise

Evaluate Salesforce actions against exact tenant, operation, object and authority bindings before execution. The adapter preserves semantic-action boundaries instead of treating an OAuth scope as permission to perform every reachable mutation.

SOURCE
AG39
STATE
ENGINEERING_READY
PROTOCOL
Salesforce enterprise adapter
TRUTH
ENGINEERING

Boundary: OAuth scopes constrain technical reach; they do not manufacture authority for a consequential Salesforce action.

Enterprise SaaS

ServiceNow Enterprise

Govern ServiceNow enterprise operations with exact instance, domain, role and operation profiles. Source contracts reject encoded-query expansion, dot-walk drift, role supersets and session identifiers at the authority boundary.

SOURCE
AG40
STATE
ENGINEERING_READY
PROTOCOL
ServiceNow enterprise adapter
TRUTH
ENGINEERING

Boundary: ServiceNow role membership or API reach does not authorize an agent to exercise every available operation.

Execution Infrastructure

StableMind Connector Host

A bounded connector-host contract for running certified connector processes with deterministic handshakes, request binding, deadlines and receipts. It is the runtime boundary between an exact permit and an implementation-specific integration.

SOURCE
AG41
STATE
ENGINEERING_READY
PROTOCOL
actiongate.connector/1.0
TRUTH
ENGINEERING

Boundary: The host cannot broaden the Action Permit, invent a semantic action or retain credential material as standing capability.

Execution Infrastructure

Connector Certification

Source-backed certification machinery checks connector packages, publisher signatures, subprocess behavior, credential redaction and deterministic receipts against the StableMind Connector Standard.

SOURCE
AG42
STATE
DEVELOPMENT_CERTIFICATION
PROTOCOL
StableMind Connector Standard v1
TRUTH
ENGINEERING

Boundary: A passing connector certificate proves package conformance to a scoped engineering contract. It never grants tenant-local action authority.

Developer

Connector SDKs

Go, Python and TypeScript SDKs implement actiongate.connector/1.0 framing, invocation binding, credential redaction and deterministic result receipts for custom connectors.

SOURCE
AG42
STATE
ENGINEERING_READY
PROTOCOL
Go · Python · TypeScript
TRUTH
ENGINEERING

Boundary: SDK adoption makes integration easier; it does not bypass connector admission, authority checks, permits or customer policy.

Credential Infrastructure

Credential Broker

Materialize short-lived technical capability only after an exact permit exists. Profiles bind route, target, credential type, scope, TTL and use count, with volatile handling and explicit revocation.

SOURCE
AG21
STATE
ENGINEERING_READY
PROTOCOL
JIT credential lease/injection
TRUTH
ENGINEERING

Boundary: Credential availability is downstream of authority. The broker cannot issue permission and cannot upgrade a commercial identity into machine authority.

Financial Action

Payment Connector

A payment-specific connector contract with preflight, exact action binding, JIT credential handling and reconciliation semantics for consequential financial workflows.

SOURCE
AG23
STATE
ENGINEERING_READY
PROTOCOL
Payment preflight + execution receipt
TRUTH
ENGINEERING

Boundary: Payment rails and bank credentials remain execution capability. Destination, amount and authority must still be independently governed.

Enterprise Data

Supplier Connector

A source-backed supplier-information boundary emphasizing upstream identity, field minimization, freshness and a direct-mutation prohibition. Useful for authority and target resolution without turning read access into mutation power.

SOURCE
AG21
STATE
ENGINEERING_READY
PROTOCOL
Read-minimized supplier data
TRUTH
ENGINEERING

Boundary: The connector is read-oriented by contract and does not create supplier-change authority.

Ecosystem

Extension Gallery

Signed extension manifests, publisher identity, SBOM/provenance digests and declared capabilities support a governed extension ecosystem for connectors and evidence verifiers.

SOURCE
AG63
STATE
DEVELOPMENT_ECOSYSTEM
PROTOCOL
Signed extension manifests
TRUTH
ENGINEERING

Boundary: Gallery publication, publisher verification and extension installation create no standing authority and bundle no credentials.

Ecosystem

Open Authority Ecosystem Lab

An open lab certification bundle exercises authority-aware ecosystem interoperability and conformance without promoting synthetic lab success into third-party production proof.

SOURCE
PT08
STATE
LAB_VERIFIED
PROTOCOL
Open conformance bundle
TRUTH
ENGINEERING

Boundary: Open ecosystem verification is engineering evidence only. It cannot certify a customer workflow or create action authority.

What Integration Studio actually configures

A boundary plan, not a master key.

IDENTITY

External identity sources

OIDC identity can establish who is using the StableMind commercial workspace. That identity remains separate from machine delegation. SIO19 deliberately avoids embedding identity-provider secrets and production authentication still fails closed until a deployment configures a real provider.

OBSERVATION

Shadow and evidence sources

SIO23 can prepare customer-controlled read-only observation paths. Integration Studio can classify a source for observation or evidence, but it does not silently convert a read connection into an execution connector or broaden the seven-field minimized shadow envelope.

EXECUTION

Connector and credential boundaries

Execution connectors sit behind permits. Credential Broker materializes short-lived capability only after permit eligibility exists. The connector SDKs make implementation predictable, while connector certification checks package conformance without granting tenant authority.

Six integration roles

Classify what the connection is for before deciding how it should be built.

The same vendor can appear in more than one place in an agentic architecture. A Microsoft or Salesforce boundary might be used only as a read-only observation source during shadow evaluation, then later as an execution connector for a narrow semantic action. StableMind keeps those roles explicit so a low-consequence connection cannot silently inherit the powers of a high-consequence one.

IDENTITY SOURCE

Who is operating the workspace?

An identity integration establishes an attributable human or service identity for the commercial workspace and can support enterprise sign-in policy. It does not establish what an AI agent may do. That distinction prevents an authenticated administrator, group membership, SSO assertion, or tenant role from becoming an accidental delegation mechanism.

OBSERVATION SOURCE

What facts can shadow mode see?

An observation source supplies minimized, read-only facts about a workflow so ActionGate can compute counterfactual decisions. Observation contracts should specify exact fields, freshness, tenancy, transport ownership and prohibited secret classes. Read access is deliberately narrower than execution, and a shadow source must not acquire mutation capability merely because the integration supports it.

AGENT RUNTIME

Where does the machine request originate?

An agent runtime integration identifies the semantic request coming from an agent framework, tool protocol, orchestration system or custom application. StableMind cares about the meaning of the requested action, the consequential target and the authority lineage behind it. Runtime identity or tool registration alone cannot answer those questions.

EXECUTION CONNECTOR

How does a permitted action reach the target?

An execution connector implements the final system-specific operation only after a valid permit exists. The connector should bind the permit, semantic action, target, request digest, deadline and idempotency state; receive technical capability only when required; and emit an attributable receipt without broadening the decision made upstream.

CREDENTIAL PROVIDER

When does temporary capability materialize?

A credential provider or broker supplies the smallest short-lived technical credential required by the exact permitted action. It should support tight TTLs, bounded use counts, volatile handling and revocation. StableMind treats that credential as capability, not permission, which means no vault record or cloud role can substitute for ActionGate authorization.

EVIDENCE DESTINATION

Where does attributable proof material go?

An evidence destination receives receipts, verifier observations, lineage or other governed artifacts under customer-controlled custody. It does not decide whether the action was authorized and it does not turn a successful connector response into Proof of Consequence. Evidence remains useful precisely because it stays distinct from both the actor and the decision boundary.

Evaluation checklist

Before you connect an AI agent to anything consequential, ask seven questions.

01–03

Action, target, authority.

What exact semantic action can the integration perform? What consequential target does it affect? Which explicit delegation proves that the machine may exercise that power rather than merely reach the API?

04–05

Credential and consequence.

When does technical capability appear, how short-lived is it, and can it be revoked? Which consequence dimensions need reserved capacity before the action is eligible to proceed?

06–07

Evidence and interruption.

What receipt can the integration produce, what independent observation can verify the resulting state, and which Guardian path can interrupt or revoke power before the consequence completes?

Authenticated Integration Studio

Prepare the integration plan without connecting the customer system.

Select a source-backed integration, give it a role in your evaluation, and produce a non-authorizing plan for the Developer Center. No secrets, permits, credentials or customer-system calls are created in SIO25.

Enterprise evaluation

Need a diligence path that keeps approval separate from authority?

Use the source-backed Enterprise Evaluation Room to review security, architecture, deployment, procurement, evidence and pilot design without turning evaluation completeness into production proof.

Open Enterprise Evaluation