How it works
From credential to colleague, in an afternoon
Five steps, no migration, and one guarantee: the agent can never do something the credential you handed over could not already do.
Hand over a key, not your data
Give Caterfli an MCP server, a REST API — from an OpenAPI document or endpoints you describe — or a PostgreSQL or MySQL database. It reads what is there: endpoints, tables, relationships, MCP tools.
The credential is encrypted with a key separate from the application key before it is stored, and decrypted only inside the connector at the moment of a call. It never appears in a prompt, a log or a trace. Nobody, including whoever runs the platform, can read it back.
discovery · PostgreSQL
ready- list_customers read
- create_customer create
- update_customer update
- delete_customer delete Approval
Deterministic: the same schema produces the same tools, so a colleague reviewing this next month sees what you saw.
Read the agent it drafted for you
Every discovered capability becomes a tool with a schema, a risk level and an operation type. From those, Caterfli writes an agent: a name, a purpose, instructions describing the system and how to behave in it, and a selection of tools.
Destructive tools arrive switched on but gated. Leaving deletion out gives you an agent that cannot do its job, so people work around it by hand and the audit trail disappears. Leaving it ungated is reckless. On, but requiring a person, is the only honest setting.
approval
waiting- Tool
- delete_customer
- Operation
- DELETE
- Runs against
- Production PostgreSQL
- Agent
- Support Agent
Exactly these values
{
"customer_reference": "100",
"reason": "duplicate record"
}
Your decision applies to these values only. If anything about the call changes, it stops for approval again.
The approval covers this call with these arguments. If the model re-plans, it has to ask again.
Put it where the work already happens
Talk to it in web chat, or put it behind Telegram, Slack or WhatsApp so nobody has to open another dashboard. Save a question as a report and it runs on a schedule. Same agent, same checks, whichever door the request came through.
Chat streams the answer and the reasoning as they arrive, so a run that takes thirty seconds is legible rather than a spinner. A request from WhatsApp goes through the identical policy set as one typed at a desk.
chat
which customers have not ordered since March?
- proposed list_customers
- schema + policy checked
- read — no approval needed
Fourteen, and eleven of them were monthly buyers before they stopped. The largest by past spend is Northwind Trading, at £4,120 last year.
Watch it decide, including when it stops
Every run records its steps in order: what the model proposed, what was validated, what policy said, what actually ran and how long it took.
Refused calls are recorded too. A trace showing only successes would hide the most interesting thing about a run — the moment something was stopped, and the reason. This is also the difference between an agent you can debug and one you can only distrust.
execution trace
refusedthe model proposed
delete_customer(customer_reference: 1)
- Tool resolved exists · owned by this workspace · enabled for this agent
- Arguments validated matches the schema the connector declared
- Permission checked viewer role — tool.execute not held
Refused before the connector was reached. An agent acts on somebody's behalf; it cannot lend them a capability they do not have.
Answer "what changed?" months later
Separately from the run-by-run trace, every record an agent created, updated or deleted in your own systems is written down: which record, which agent, who asked, and whether a person approved it.
This is the question people actually ask weeks afterwards, and a trace is the wrong shape to answer it — you would have to already know which run to look in. Search by the record instead.
changes
- Deleted Deleted customer 100 approved by Sarah
- Updated Updated order 4471 Support Agent
- Created Created refund 812 Billing Agent
Kept for 7 to 90 days, depending on your plan.
Before you start
What reinvention does not mean
It is not a data warehouse
Nothing is copied into Caterfli to be queried later. Every answer is a live call to the system you connected, which is why it is never stale and never a second copy to secure.
It is not smarter than your permissions
An agent acts for a person. If that person cannot delete a customer, neither can the agent, no matter how the request is phrased.
It is not a replacement for backups
An approved deletion is still a deletion. The change log tells you what happened and who agreed to it; it does not put the row back.
It does not learn your data
Your records are used to answer your requests and nothing else. They are not training material, yours or anybody else’s.
It will not invent an integration
If the system exposes no way to do something, no agent can do it. Discovery finds what is there, not what you wish were there.
It does not hide the model
You choose the provider, you see the token cost per call, and you can read exactly what was sent — tool names and schemas, never your credentials.
The first one takes an afternoon
Connect a system, read what Caterfli drafted from it, and decide what it may do on its own.