GOVERNED INTEGRATIONS

Connect business tools without giving Agents blanket authority.

RYTHM separates connection, capability, Agent permission, human approval, execution, verification, and audit so a connected account does not automatically become an unrestricted AI action channel.

CURRENT GATEWAY

The execution layer models real tools and explicit operations.

The current gateway includes governed capability contracts for GitHub, Vercel, Supabase, Cloudflare, Stripe, Google Workspace, Microsoft 365, Resend, and internal validation. Customer availability still depends on provider configuration, entitlement, verified credentials, scopes, and rollout state.

Productivity and communication

Google Calendar, Gmail, Microsoft Calendar, Microsoft Mail, and Resend email capabilities are represented in the governed execution layer.

Software operations

GitHub repositories, Vercel deployments, Supabase database operations, and Cloudflare DNS use operation-specific contracts.

Commercial operations

Stripe read/refund operations and other financial actions carry explicit financial and Human CEO approval requirements.

CONNECTION LIFECYCLE

Connected does not mean authorized for every action.

1. Authenticate

Use provider OAuth or a restricted provider-issued credential; RYTHM does not request the user's personal provider password.

2. Grant minimum scope

The organization connects only the scopes needed for the intended capability.

3. Grant Agent capability

An Agent needs a matching integration grant and permission before it can propose or execute the operation.

4. Apply policy

Risk, environment, entitlement, side effect, financial impact, approval, and kill-switch rules are evaluated.

5. Verify and record

Execution results and supported compensating actions are recorded in the tenant-scoped ledger.

PLANNED CONNECTOR FAMILIES

Some capability contracts exist before production adapters do.

Accounting/ERP, CRM, CMS, analytics, legal, HRIS, project work, file storage, generic business APIs, and advertising connectors are represented as disabled contracts until hardened provider adapters and verification are complete. They must not be interpreted as currently available integrations.

DIRECT ANSWERS

Frequently asked questions

Which integrations are available today?

The gateway contains the providers listed above, but availability is deployment- and customer-specific. The authenticated Integrations workspace is the source of truth for what a particular organization can connect now.

Does connecting a tool let every Agent use it?

No. Organization connection, granted scopes, Agent capability grants, user permissions, entitlement, risk policy, and approval are evaluated separately.

How are credentials stored?

Provider authorization or restricted credentials are handled by the governed integration layer; supported secret material is stored through the configured secure credential boundary rather than exposed to Agents.

Can integrations run without human approval?

Bounded low-risk read operations may run where policy permits. Publishing, spending, deployment, data changes, communication, and other consequential writes require the applicable approval path.

RELATED RYTHM CONCEPTS

These pages define the adjacent concepts, product boundaries, architecture, and platform comparisons used across RYTHM Company OS.

NEXT STEP

See the governed operating model before you choose a plan.

Reviewed and updated 2026-09-01.

VERIFIABLE EVIDENCE

Check implemented integration contracts separately from partnership claims.

The public evidence register lists current provider families, implemented operations, official provider API references, source-code evidence, and the explicit boundary between technical integration and official partnership.