Platform

Open Platform

The SwiftXEO Open Platform lets external AI assistants and your own systems connect to a governed workspace — able to read approved direction and propose work, never to approve it.

Connect the AI assistants and systems your team already uses. They can work from approved SwiftXEO context and send proposals back into the workspace, while approval stays inside SwiftXEO.

Autonomy proposes. Humans authorize. Governance remains active.

Context can move between tools. Authority stays with the organization.

Why this matters

Your team already uses AI assistants. The open question is what they are allowed to touch.

Leaders want assistants like Claude and ChatGPT working with real company context — approved strategy, live objectives, reviewed lessons. As those assistants connect to more of the organization on their own, the risk shifts: it stops being about what they can reach, and becomes about whether an external tool quietly becomes an authority over what counts as true.

SwiftXEO resolves that tension structurally rather than by policy document. Connected assistants read the same approved record your team works from, and everything they send back enters a review queue. Context flows out; authority never does.

The surfaces

Four ways in. One gate.

MCP, REST API, signed webhooks, and selected connectors provide the integration surface.

Connect supported AI assistants

Supported MCP clients can connect directly to a SwiftXEO workspace using OAuth or workspace credentials, depending on the client — including Claude, ChatGPT, Claude Code, and Cursor.

REST API (v1)

Workspace-scoped API keys drive a versioned REST surface: read approved Business DNA, objectives, active learnings, and history; submit evidence and proposals from your own systems.

Inbound webhooks

Signed, verified push from external systems. Every payload is checked against a per-source secret and stored as material for human review — never executed, never trusted on arrival.

Beta

Gmail connector (beta)

A read-only beta connector that turns recent inbound email into reviewable workspace evidence. It never sends mail, and like every external source, nothing it captures becomes truth without review.

The propose-only invariant

Nothing external can approve itself.

Everything that enters from outside starts as untrusted context. Reviewers decide whether it becomes evidence, approved context, or something the organization should ignore. No external API, MCP tool, or webhook can perform that approval.

There is deliberately no approve, activate, or authorize capability at any scope. The approval path requires a signed-in human with the required workspace role.

Identities are redacted on the way out

Reviewer and author identities leave the workspace as role labels, never as names.

The trust ladder

What external agents can and cannot do

External agents can

  • Read approved Business DNA, objectives, active learnings, and decision history.
  • Search the workspace's approved operational knowledge.
  • Submit evidence and signals for human review.
  • Propose learnings — every proposal lands pending.
  • Create draft content using your approved workspace context.

External agents cannot

  • Approve, activate, or publish anything — no such capability exists at any scope.
  • Write directly into approved context — everything external starts untrusted.
  • Escalate or expand their own access — scopes and plan limits are re-checked on every request.
  • Bypass workspace boundaries — access is always scoped to a single workspace.

Every external item is born untrusted. Each promotion up the ladder — reviewed evidence, then approved context — is a human decision that changes what the material is authorized to do.

Questions

Frequently asked questions

Which AI assistants can connect to SwiftXEO?

Supported MCP-capable clients can connect to SwiftXEO. Current connection options include Claude, ChatGPT, Claude Code, Cursor, and custom agents, depending on the client and authentication method.

Can a connected agent approve or publish anything?

No. External agents can read approved context and submit proposals, but no scope or tool can approve, activate, or publish. Every proposal waits in a review queue until a human workspace admin decides.

What happens to the material an agent submits?

It lands as untrusted context in a server-only review area. A reviewer can promote it to evidence, approve it into active guidance, or reject it — rejected items are retained with their history but never influence future work.

Is the Gmail connector generally available?

Not yet — it is a read-only closed beta, enabled per workspace. The MCP server, REST API, and inbound webhooks are already available to every workspace.

Bring your own agent. Keep your own authority.

Create a workspace API key from Settings, or start with a DNA scan — the open platform reads from the same approved record as everything else in the product.