CUSTOM AGENTS + WORKING MACHINES

Build custom agents on one application layer

Working Machines provides custom agents with a consistent application layer across business software. Your agent can discover actions by intent, use a scoped connection identity, execute validated calls, and process structured results without implementing a separate OAuth and API integration for every provider.

The connection begins with a compact discovery surface rather than the full catalog. Custom Agents loads the action contract it needs, operates through a named account connection, and receives a structured response. Working Machines applies authorization and action policy at execution time, outside the prompt.

REAL WORK ACROSS APPLICATIONS

Work across apps, not inside them.

01

Agentic operations

Coordinate documents, records, tasks, and communication across internal systems with explicit policy boundaries.

NotionGoogle SheetsSlack
02

Customer lifecycle

Research an account, update CRM context, prepare communication, and schedule the next step.

HubSpotGmailCalendar
03

Engineering automation

Connect incident signals to repositories, work tracking, cloud systems, and team communication.

SentryGitHubLinearSlack

CAPABILITY LAYER

Give Custom Agents capabilities, not credentials.

Protocols

  • Remote MCP integration
  • Direct HTTP action execution
  • OpenAPI-based client generation

Runtime

  • Intent-based action discovery
  • Schema validation
  • Structured result envelopes

Control

  • Connection identities
  • Allowed and blocked actions
  • Redacted execution records

SETUP

Connect in five steps.

  1. 01Choose MCP for agent-native discovery or HTTP/OpenAPI for direct integration.
  2. 02Create the runtime identity used by your agent.
  3. 03Connect provider accounts with minimum required scopes.
  4. 04Define allowed applications and actions for the workload.
  5. 05Store execution identifiers with your own task and evaluation records.

BOUNDARIES

What to consider.

  • Your agent remains responsible for planning, confirmation logic, and safe handling of returned data.
  • Treat external text as untrusted input and defend against prompt injection in your agent layer.
  • Use idempotency, retries, and human approval for irreversible or financially sensitive operations.
READ THE SECURITY GUIDE

COMPATIBLE AGENT APPS

Start with a bounded application set.

ONE CONNECTION. REAL WORK.

Give your agent software it can use.

Connect through MCP or explore the Agent App catalog and choose only the capabilities your workflow needs.

EXPLORE AGENT APPS