Platform · Integrate · The hands

Tools & Integrations

Giving AI hands in an enterprise stack is normally a quarters-long integration project — and every connector it produces is another placecredentials leak and actions go unlogged. Here the stack is a catalog: 70+ systems connected once at the org level, any internal REST API wrapped as a governed tool, every call policy-checked against a function catalog, and every credential in an encrypted vault a model never sees.

Connect your stack How it's governed
At a glance
  • Out of the box70+ SaaS integrations
  • Your systemsany REST API · Postman / OpenAPI · MCP
  • Policy-checked1,095 fns · 50 integrations
  • Grantedper agent, least-privilege
  • Secretsvaulted, decrypted at request time
  • Trailevery call logged, config-pinned
IN A SOLUTION PACK

In a pack, tool access arrives scoped: each agent gets exactly the integrations it needs, nothing more.

See Solution Packs →
app.turtlecoworker.com/tools
The Tools & Integrations page: Connected systems with health badges and usage stats on top, the Available library below with category rail and search
The catalog: what's connected and healthy on top, the library to connect below.
Why it's built this way

Every integration is a liability
until it's a governed tool.

The standard playbook — one connector per system, credentials in config files, logging as an afterthought — produces exactly what a security review fears: secrets in too many places and actions in none of the logs. And it takes quarters to build.

So the module inverts it. Systems connect once, at the org level; agents are granted least-privilege slices of them; every call passes thepolicy engine on its way out; every credential lives in an encrypted vault, decrypted only at request time; and every action lands in the audit trail. The integration project collapses into an afternoon — with more control at the end of it, not less.

Why teams switch

The shift is from a pile of hand-built connectors to one governed surface: 70+ apps and any internal system, connected once, granted per agent, policy-checked on every call, with every secret vaulted.

What most AI tools give you
  • One connector per system: a quarters-long backlog with an owner per API
  • Secrets pasted into prompts, config files and a dozen workflows
  • Actions in live systems with no unified log of what the AI did
  • No way to scope what a tool can reach, or test it before ship
What Turtle AI Coworker gives you
  • 70+ integrations connected in a click, granted per agent
  • Any REST API becomes a governed tool, no glue code
  • Every call policy-checked against a 1,095-function catalog
  • Credentials vaulted, decrypted at request time, never in a prompt
Time to configure
~2 min
Connect a SaaS app once at org level; import a whole Postman/OpenAPI collection into governed tools in ~10 min.
Cost to run
metered
Every tool call and credential read is logged: usage, failures and auth health, per agent.
Effort to operate
Connect once
Reuse everywhere with least-privilege: grant each agent only the tools its job needs.
See it work

Six ways your workforce acts in your stack.

Update a CRM, wrap an internal microservice, expose a whole product API, vault a finance key, fire on an in-house event, or test before you ship — each one scoped, policy-checked and vaulted.

Your agents already read deals. Now you want them to write back: log the touch, move the stage, update the amount, not hand a human a to-do.

01One authorization, org-wide

The CRM is authorized once at Organization scope; OAuth issues a revocable token, encrypted the moment it lands, reusable by every agent you grant it to.

02Write scope for one agent

The CRM-writer agent is granted Read + Update; every other agent keeps read-only. Least-privilege, per agent.

03The agent acts, not asks

It updates the deal in place. The write is policy-checked, executed, and logged — no copy-paste, no swivel-chair.

0
copy-paste between the AI and your CRM: the action happens where the work lives.
How it's embedded

Give your workforce hands in your stack.

Connect your apps and internal APIs once; every agent, team and employee calls only the scoped actions you grant. Credentials stay vaulted.

You connect
70+ SaaS appsAny private REST APIPostman / OpenAPIMCP serversWebhooks
internal & external: your systems
Tools & Integrations
the hands your workforce acts with, scoped & vaulted
Your workforce uses it
Agentscall scoped actions per task
Teamsone specialist holds the risky tool
Employeestake live actions across your stack
What's inside

Connect once. Grant precisely. Govern every call.

Eight surfaces between your stack and your workforce — each one closing a hole the hand-built version leaves open.

01 · Catalog

The integration project, already done.

The usual way to give AI hands is a backlog: one connector per system, each with its own auth dance, error handling and owner. Here the stack is a catalog — 70+ systems your workforce can act in, from CRMs and comms to docs, trackers and dev tools. Each card names the system, its category and the auth flow it will run; connecting one is a single authorization, not a sprint.

  • 70+ systems: data & CRM, communications, docs & files, project management, sales & marketing, dev tools
  • Each card shows the auth type before you commit: OAuth 2.0 or API key
  • Search and category rails narrow Connected and Available at once
The Available library: category rail with per-category counts, integration cards showing system name, category and auth type
The catalog: the stack as a library, not a backlog
02 · Connect

Authorize once, at the org level.

Every ad-hoc integration is another place a credential gets pasted, copied and forgotten. Connecting here is deliberately separated from granting: you authorize a system once, the credential and its scope live at the workspace level, and it becomes a reusable tool. OAuth 2.0 issues a revocable, refreshable token for user-facing apps; a pasted API key covers metered account-level services. Either way, the secret is encrypted the moment it lands.

  • OAuth 2.0: a revocable, auto-refreshing token — never a stored password
  • API key: pasted once, encrypted at rest, never shown again in full
  • Organization or Personal scope, chosen at connect time
The Connect modal for an OAuth integration: requested permissions, Organization/Personal scope selector, Authorize button
One authorization per system, scoped and revocable
03 · Grant

Connected is not the same as reachable.

A connected system doesn't automatically reach every agent — that default is how integrations turn into liabilities. Each agent is granted only the tools its job needs, with the scope that job requires: an outreach agent can draft and send email; it cannot touch the CRM it was never given. Access stays least-privilege by construction, and removing a tool from one agent touches nothing else.

  • Tools granted per agent, read-only where write isn't needed
  • An agent reaches only what it's handed — never every connected system
  • Revoke from one worker without disturbing the rest
An agent's Tools tab: the specific integrations granted to this agent with their scopes, out of a larger connected set
The grant: this agent, these tools, this scope — nothing else
04 · Policy

Every call answers to the policy engine.

A grant says an agent may hold a tool. The policy engine decides what happens each time it's used. Every tool call is resolved against a catalog of 1,095 named functions across 50 integrations, each classified read or write, and evaluated against your rules before it executes — allow, deny, require approval, alert, or log. 'Hold every external write' is one rule, and a held send waits for a human, not a timeout.

  • 1,095 functions across 50 integrations, named and read/write-classified
  • Verdicts enforced before execution, with approval holds routed to one queue
  • The same gate covers native integrations, custom tools and MCP servers — see Governance
A tool call held by policy: the function name resolved from the catalog, the rule that held it, and its require-approval verdict
The gate: a write, resolved to its function, held by the rule that names it
05 · Extend

Your internal systems become tools too.

The systems that actually run your business aren't in anyone's catalog: the pricing service, the ops microservice, the ERP behind the firewall. Custom tools turn any REST API into a first-class, governed tool your workforce calls by name. Import a documented Postman or OpenAPI collection and expose a whole product API at once, or define a single endpoint by hand — method, URL, input schema, output mapping. MCP servers register the same way.

  • Postman / OpenAPI import: a whole collection becomes tools in minutes
  • Manual endpoint: full control over method, schema and output mapping
  • MCP servers attach through the same registry, permissioned like any tool
The custom tool builder: an endpoint defined with method, URL template, input schema and output mapping, linked to a vaulted credential
A private endpoint, on its way to being a governed tool
06 · Vault

Credentials a model never sees.

The classic integration failure mode is a secret in a prompt, a workflow, a log. Here tool definitions and secrets are separated on purpose: definitions live in the registry, credentials live in an encrypted vault. A credential is encrypted at rest, decrypted only at the moment a request fires, injected server-side — never exposed to an agent, a prompt or a log — and every read of it is written to the audit trail.

  • Encrypted at rest, decrypted only at request time, injected server-side
  • Never in a prompt, never in a log, never shown to a model
  • Every credential read is itself an audit event
The Credentials Vault: one card per stored credential with auth type and token health, values masked
The vault: secrets apart from tools, reads on the record
07 · Verify

Dry-run any tool before an agent holds it.

Shipping an untested tool means debugging it inside a live run. The built-in test runner feeds a synthetic, LLM-shaped input to the endpoint, injects the vaulted credential, and shows the resolved request, the live response with status and latency, and the mapped output side by side. A green run marks the registry row OK; a failure records the exact code. Dry runs are tagged as tests and never count as real mutations.

  • Sample input · resolved request · live response · mapped output, side by side
  • Registry rows carry last test state: OK or the failure code
  • Test calls are tagged source: test — logged, never counted as mutations
shot: tools-test-runnerThe tool test runner: synthetic JSON input, the resolved request, a live 200 response with latency, and the mapped output
The dry run: proof it works before an agent ever calls it
08 · Record

No action without a row.

The question a security review asks about integrations is simple: what did the AI actually do in our systems? Here every tool call lands in the audit trail — the integration, the function, the operation classified read or write, inputs and outputs sanitized, secrets redacted — joined to the run that made it and pinned to the config version it ran under. Unlogged action is not a risk you manage; it's a thing that can't happen.

  • Every call logged: integration, function, read/write classification, sanitized payloads
  • Joined to the run, the worker and the immutable config version
  • Filterable by worker, integration, user and date; exportable for review
The audit trail filtered to tool calls: rows showing integration, function name, read/write tag, sanitized input and result
The trail: every call your stack received, on the record
The integration directory

Everything your workforce can plug into.

Connect once at the org level, then scope per agent. Two auth methods cover it: OAuth 2.0 or a pasted API key. Every credential is encrypted at rest, decrypted only at request time, and never shown to a model. Below is a selection of the 70+ connectors, grouped by category. And when a system isn't here, any REST API or MCP server becomes a tool.

Data & CRM

6
AirtableData & CRM
AttioData & CRM
AffinityData & CRM
AviatoData & CRM
HubSpotData & CRM
Google SheetsData & CRM

Communications

7
SlackCommunications
GmailCommunications
Google CalendarCommunications
Google MeetCommunications
CalCommunications
CalendlyCommunications
FirefliesCommunications

Docs & Files

7
NotionDocs & Files
Google DriveDocs & Files
Google DocsDocs & Files
Google SlidesDocs & Files
BoxDocs & Files
DropboxDocs & Files
PDFDocs & Files

Project management

4
JiraProject management
AsanaProject management
ClickUpProject management
LinearProject management

Sales & Marketing

7
ApolloSales & Marketing
HunterSales & Marketing
Company EnrichSales & Marketing
ContactOutSales & Marketing
CoresignalSales & Marketing
WordPressSales & Marketing
GoDaddySales & Marketing

Dev tools

9
SerperDev tools
ExaDev tools
Google SearchDev tools
Web ScrapingDev tools
ApifyDev tools
Bright DataDev tools
GitHubDev tools
ElevenLabsDev tools
CloudinaryDev tools

Custom HTTP & MCP

Anything with an API becomes a first-class tool. Import a documentedPostman or OpenAPI collection to stand up a whole product API at once, hand-define a single endpoint with full control over method, schema and output mapping, or attach an MCP server. Secrets live apart in the encrypted Credentials Vault, permissioned and policy-checked like any native integration.

Showing 40 named connectors of 70+ · any REST API or MCP server can be added as a custom toolSee all integrations
A real use case, worked

An SDR workflow, wired in an afternoon.

A mid-market B2B sales team gives one agent hands in four systems — HubSpot, Gmail, Slack, and an internal pricing API — and every call it will ever make is governed before the first one fires. This is what the system does, not a click-path.

Connect
Three systems, three authorizations
HubSpot, Gmail and Slack are each authorized once at Organization scope. OAuth issues a revocable token per system — encrypted the moment it lands, auto-refreshing, reusable by any agent the org later grants it to. No passwords stored, ever.
Extend
The pricing API becomes a tool
The internal pricing service isn't in any catalog, so its REST spec is imported: each endpoint becomes a named tool with a typed input schema and a mapped output. Its API key goes into the vault — encrypted at rest, and from here on decrypted only at the instant a request fires.
Grant
One agent, four tools, least privilege
The SDR agent is granted HubSpot read, Gmail draft and send, Slack post, and the pricing lookup — nothing else. A policy rule holds every external write for approval, so outbound email cannot leave without a human. The rule binds to the exact send function from the catalog, not a wildcard.
Run
Every call crosses the gate
In flight, each call resolves against the function catalog and gets a verdict. CRM reads and pricing lookups are reads: they flow, logged. The Gmail send is a write to an external system: the run pauses, the draft lands in the approval queue with the rule that held it, and one approval releases exactly one send. The credential behind each call is decrypted only for that request — the model never sees it.
Record
The afternoon's work, on the record
Every read, the held send, the approval, and each credential read land in the audit trail — sanitized, classified read or write, pinned to the config version the agent ran under. When security asks what the AI did in the CRM this quarter, the answer is a filter, not a forensics project.
An outreach email draft held for approval: the Gmail send call, the policy rule that held it, the sanitized draft payload, and approve/deny controls
The held send: outbound email waits for a human, by rule
What you can build

If it has an API, an agent can use it — governed.

Connect your CRM

Read, enrich and update records org-wide: granted read-only to sources, write to targets.

Wrap a private microservice

Turn an internal lookup, calc or notify endpoint into a tool an agent calls by name.

Import a whole API

Drop a Postman or OpenAPI collection and stand up a dozen governed tools in minutes.

Gate a payments action

Expose a charge or refund endpoint with a policy rule that holds it for human approval.

Attach an MCP server

Bring an MCP server's tools in through the same registry, vault and policy gate.

Fetch reference data

Pull rates, catalogs or tables from a read-only endpoint at run time, un-gated.

The payoff
70+
integrations out of the box, plus any REST API or MCP server as a custom tool.
1,095
catalogued functions across 50 integrations, read/write-classified, so policy binds to exactly what you mean.
1
encrypted vault holding every secret, decrypted only at request time, never shown to a model.
100%
of tool calls and credential reads logged, sanitized, and pinned to the config that made them.
From the live catalog

Built on Tools.

All templates
Procurement Ops Control Tower Pack
Solution Pack · Operations

End-to-end procurement operations solution pack with vendor registry, purchase request review, contract path assessment, embedded review team, and AI employee coordination.

3 agents3 tables1 employee
Official · ~35 min
CA Firm: Compliance & Practice Pack
Solution Pack · Professional Services

Complete operating system for a Chartered Accountant practice. Tracks clients, engagements, statutory deadlines, and IT/GST notices. Includes AI agents for notice triage, GST reconciliation, filing reminders, and client communication. Comes with an AI Employee (Priya) who coordinates compliance work end-to-end.

4 agents5 tables1 employee
Official · ~15 min
Recruiting and Staffing Ops
Solution Pack · Recruiting

Move candidates faster without cutting corners on fair hiring. Riley, your AI recruiting coordinator, screens each new candidate against the job's must-haves with must-have-by-must-have reasoning, coordinates interview scheduling by drafting availability requests, drafts honest candidate outreach and status updates, builds submittal packages for hiring managers or clients mapping experience to requirements, and gives the team a daily pipeline read. Screening never considers anything beyond skills and qualifications, and it never rejects a candidate or extends an offer; those stay human decisions. Everything else is draft-and-approve: candidate messages are prepared for a human to send, and interview times are proposed, never confirmed, by the agent. Four tables hold your job orders, candidates, interview scheduling, and pipeline metrics. A knowledge base holds your screening standards, submittal format, communication voice, and compliance guardrails, which every assessment and message follows. Automations included: new candidates are screened on arrival, plus an optional daily pipeline digest. Works out of the box with the roles and candidates you add; connect an ATS or job board later to sync candidates, and Gmail and Calendar to send outreach and confirm interviews from the platform. Best first step: replace the placeholder screening standards and compliance rules with your own and add an open job.

5 agents4 tables1 employee
Official · ~20 min
Sales Engine
Solution Pack · Sales

A complete outbound-to-pipeline sales engine for a small team. Define your ideal customer profile once in the ICP Profiles table and paste your product details into the Product Knowledge Base, then Sasha, your AI SDR, discovers and vets target accounts, enriches prospects, researches companies, scores leads, and drafts outreach, all grounded in your data. Inbound leads and your deal pipeline live in tables the founder can watch. Automations included: new prospects are auto-enriched on arrival, and an optional daily discovery run finds fresh accounts from your Active ICP. Requires an LLM provider plus the Apollo, Serper, Exa, and Google Search connectors. Replace the sample knowledge base content and the example ICP row with your own.

6 agents5 tables1 employee
Official · ~20 min
Customer Support Ops
Solution Pack · Support

Answer more support tickets, faster, without losing the human touch. Sam, your AI support specialist, classifies every incoming ticket by category, sentiment, and priority, drafts an accurate reply grounded only in your knowledge base, and escalates anything it is not confident about instead of guessing. It matches recurring problems to approved canned responses, mines new tickets into known issues so answers stay consistent, tracks the feature requests buried in tickets, and produces a weekly insights digest of volume, deflection, and top drivers. Everything is draft-and-approve: replies are prepared for a human to review and send, and sensitive tickets (anger, churn, refunds, account deletion, legal or privacy) are always escalated. Four tables hold tickets, known issues, feature requests, and daily metrics. A knowledge base holds your help-center content and support voice, which every reply cites. Automations included: a reply is drafted the moment a ticket arrives, plus an optional daily sweep of anything still unanswered. Works out of the box with no external tool; connect Gmail later to send from the platform and Slack for the digest. Best first step: replace the placeholder knowledge base with your real help-center articles or URLs.

5 agents4 tables1 employee
Official · ~20 min
Sales Engine Pro
Solution Pack · Sales

A complete, full-lifecycle sales engine for a growing team, spanning outbound prospecting and account management across one shared data layer, with a companion inbound concierge. Outbound: Sasha, your AI SDR, discovers and vets accounts, enriches prospects, scouts buying signals, researches companies, scores leads, and drafts cold email, LinkedIn, and nurture outreach. Account management: Maya, your AI Account Manager, qualifies opportunities, drafts and reviews proposals, flags pipeline risk, forecasts renewals and expansion, and keeps the CRM clean. Seven tables hold ICP profiles, target accounts, prospects, website leads, CRM contacts, opportunities, and customer accounts. Automations included: new prospects are auto-enriched on arrival, and an optional daily discovery run finds fresh accounts from your Active ICP. For the inbound engine, install the companion Website Sales Concierge team template, which routes visitor questions to product, pricing, and objection specialists and captures leads into the Website Leads table. Requires an LLM provider plus the Apollo, Serper, Exa, and Google Search connectors. Replace the sample knowledge base content and the example ICP row with your own. Outreach and proposals are drafted for a human to review and send.

15 agents7 tables2 employees
Official · ~25 min
Questions

The details, up front.

How long does it actually take to wire a working stack?
Catalog systems connect in about two minutes each: one OAuth authorization at the org level, and the credential is encrypted and reusable across every agent you grant it to. A documented Postman or OpenAPI collection imports as a set of ready-to-run tools in roughly ten minutes. The quarters-long part of an integration project — per-system glue code, credential plumbing, logging — is what the platform replaces.
Where are my credentials stored, and who can see them?
In an encrypted vault, separate from the tool definitions in the registry. Credentials are encrypted at rest, decrypted only at the moment a request fires, and injected server-side — they are never exposed to an agent, written to a prompt, or captured in a log. Every read of a credential is itself recorded in the audit trail. OAuth systems never hand over a password at all: they issue a revocable token.
What's the difference between connecting a tool and granting it?
Connecting authorizes a system once at the workspace level: the credential and its scope live there. Granting gives one agent access to that tool with only the scope its job needs. The separation is what keeps access least-privilege: an agent reaches only the tools you hand it, never every connected system by default.
How do you stop an agent from doing something destructive?
Every tool call is resolved against a function catalog — 1,095 functions across 50 integrations, each classified read or write — and evaluated by the policy engine before it executes. A rule can hold every external write, one named function, or one integration's writes for human approval; approvals are single-use grants enforced at runtime. A write that was never approved doesn't run, even if it made it into a plan. The full mechanics are on the Governance page.
What can I connect if it isn't in the catalog?
Anything with a REST API, plus MCP servers. Import a documented Postman or OpenAPI collection, hand-define a single endpoint with full control over method, schema and output mapping, or attach an MCP server's tools. Custom tools live in the same registry, use the same vault, and answer to the same policy engine as native integrations.
What's the difference between Organization and Personal scope?
An Organization connection is a shared resource: every member's org-scoped agents can use it — a shared CRM, drive or workspace. A Personal connection is private to you, tied to your identity or your own metered quota, and never appears in another member's agents. You choose the scope at connect time; Organization is the default.
Can we see everything the AI has done in our systems?
Yes — that's the point of routing every call through one runtime. Each tool call is logged with its integration, function, read/write classification and sanitized payloads, joined to the run that made it and pinned to the immutable config version it executed under. The trail filters by worker, integration, user and date, and exports for review.
Next rung on the ladder

Tools are the hands. Models are the engine.

Models Governance