DocumentationConnecting an agent
Browse the guides
CAIRN

Pilot guide · 6 September 2026

Work with Cairn

Connecting an agent

Define your tools, credentials and the boundary that Cairn will govern.

Draft for the planned pilot release. These pages describe the intended customer experience. Administration and hosted-service features are not yet released; no live product URL or support service is claimed.

An agent is governed only when its consequential tool calls travel through Cairn and it cannot reach the same tools using an uncontrolled credential or route.

The current prototype supports MCP over stdio and an in-process Python wrapper. Remote transport, authenticated connector registration and hosted administration are part of the planned release.

Before connecting a workflow, identify:

  • The agent and its execution environment.
  • Each upstream tool and its allowed operations.
  • The credential owner and how access can be revoked.
  • Whether the connector runs beside the agent or in the hosted environment.
  • The active policy, approval contacts and outage behaviour.

Use a sandbox or synthetic environment for the first verification. A valid demonstration includes an allowed call, a denied call, an independently approved call and a direct-bypass attempt that fails.

Do not paste an API key into this hub, a public issue or a screenshot. Credential setup must use the released secure configuration path.

The integration guide for your actual agent will state supported versions, network requirements and exact installation steps once that integration has passed its release tests.

CAIRN INTEGRITYCustomer documentation draft