AI agents
Your AI agents run the platform.Under your rules.
graal exposes an MCP server. Claude, or any compatible client, reads the state of your projects and creates, runs and schedules jobs, through a service account scoped to one project. Every call shows up live in the console, and sensitive actions wait for your approval.
- get_run_logsprevision-conso #58✓ read
- run_jobprevision-conso✓ started
- schedule_job0 6 * * *approval required
Service account agent-previsions · project previsions
Live
What an agent does can be read while it does it
The console’s “Agents” panel shows the connected agents, their permissions, and the feed of their calls, tool by tool.


The “Agents” panel: who is connected, with which permissions, and what they just did. Each line of the feed names the tool called.
Real graal console interface, not retouched; fictional demonstration data (tenant energie-demo — people, projects and tokens are invented).
What an agent can do
Read everything that helps it decide, act on what you entrust to it
Fifty tools: 37 read, 13 write. Each relies on an operation of the graal REST API and goes through the same access controls as a user. The four destructive tools (stop, delete) are opt-in only.
Read
Projects, jobs, runs and their logs, catalog, bucket files, costs: the agent understands the state of the platform before acting.
Example tools
- list_jobs
- get_run
- get_run_logs
- list_catalog
- get_costs
Act
Upload code, create a job, run it, schedule it: the everyday moves of operations, in the project opened to it.
Example tools
- upload_code
- create_job
- run_job
- schedule_job
No destructive tool enabled by default.
The path of a call
Where an agent goes, and what it cannot bypass
One service account per project
The agent has its own identity and its own roles, never those of the person who created it. Outside its project, it sees nothing.
Per-agent policies
Allowed operations, open projects, maximum cost, time windows: each agent gets its policy, enforced by the API itself.
Human approval
An action marked sensitive does not run: it waits for a manager’s approval, then replays under the agent’s identity.
No destructive tool enabled by default
An agent that makes a mistake creates or relaunches; it does not destroy. Enabling a delete tool remains an explicit decision on your side.
Every call visible live
Every write by an agent shows up in the activity feed and carries the “Agent” badge on the resource it touched.
Instant revocation, full audit
Removing an agent’s role cuts its access at the next call. Every action stays in the audit trail, with its author.
Human approval
Sensitive actions wait for your approval
You decide, by policy, which of an agent’s actions require approval: scheduling in production, a backfill, a launch above a given cost.
01
The agent asks
The API recognizes an action subject to approval. It does not run it: it holds it, encrypted and with an expiry date, and tells the agent.
02
A manager decides
The request appears on the “Approvals” screen. The approver cannot be the person who created the agent.
03
The action runs, or not
Approved, it runs under the agent’s identity. Rejected, it is dropped. Either way, both actors are in the audit trail.
Built-in agents
Ready-to-use agents, under the same rules
The operations agent
It reads the logs, events and metrics of a failed run, then gives you a diagnosis and a proposal to relaunch.
The data engineering agent
From a plain-language description, it proposes a pipeline that you review, adjust and save.
You choose the model
MCP is an open protocol, handed by Anthropic to the Agentic AI Foundation, a directed fund of the Linux Foundation, on 9 December 2025.
Frequently asked questions
Which AI clients can connect?
Any MCP-compatible client: Claude, an agent you build, or graal’s built-in agents. The MCP server is the same for all of them.
Can an agent step outside its project?
No. Its service account only has a role on the project opened to it, and no tool takes the organization as a parameter: it comes from the session.
How do we stop an agent that runs away?
You remove its role or revoke its account: the next call is refused. You can also cancel its running jobs from the console.
Can we start read-only?
Yes. An agent with a read role only looks at jobs, runs, logs and costs, without being able to change anything.
Does our data go to the model provider?
With a model hosted on your premises, no. With an external provider, it only receives what the tools it calls return.
Watch an agent create, run and schedule a job
A Claude session, the graal MCP server, and the “Agent” badge lighting up in the console.