Query your database
An agent connects to Postgres, runs analysis, and reports findings to Slack. Read-only enforced. Every query policy-checked.
Mycelium connects AI agents to your databases, tools, channels, and documents through MCP — then governs every action they take. Every tool call checked. Every dollar capped. Every secret protected. Agents work autonomously. You stay in control.
▸ Summarize Q3 customer feedback and flag urgent issues.
Most teams keep agents on a short leash — limited tools, limited data, constant supervision. Mycelium changes the math. When every action is governed, you can afford to let agents do real work.
An agent connects to Postgres, runs analysis, and reports findings to Slack. Read-only enforced. Every query policy-checked.
Five agents fan out across the web, GitHub, and your internal docs. Results converge into a report. Untrusted sources flagged automatically.
A graph pipeline: collect, analyze, draft, verify, publish. Versioned. Replayable. Each step under full trace.
Upload documents, sync Confluence and Google Drive. Hybrid retrieval with reranking. Agents answer grounded in your data — not hallucinations.
An agent that can't reach your data is useless. An agent that can reach your data without limits is dangerous. Today, teams choose one or the other.
API keys passed as environment variables. One exposed log line, one misconfigured container — and your credentials are public.
An agent stuck retrying burns through LLM tokens at scale. No budget guardrail means you find out on the invoice.
An agent reads a web page with a hidden instruction. Now it's emailing customers or modifying records — with your credentials, through your tools, without your knowledge.
Mycelium sits between your agents and everything they touch. Not logging after the fact. Not alerting when it's too late. Intercepting — before the action happens — and checking it against your rules.
A running agent has exactly two ways to reach the outside world. Both pass through Mycelium. Both are checked. The agent holds no keys, no tokens, no credentials.
Every tool call — database query, Slack message, API request — passes through policy before it executes. Allowed tools only. Correct arguments only. And if the agent has touched untrusted data, dangerous actions stop until a human says yes.
Every LLM call routes through the proxy. Tokens metered in real time. Budget exceeded? The proxy returns 402 — the agent stops generating, mid-sentence if it has to.
Credentials live in an encrypted vault. They're injected at the exact moment a tool needs them — into the upstream, never into the agent. The agent doesn't know your keys exist.
Agents need data, humans need access, and everything needs governance. Mycelium handles all three through one unified layer.
Agents reach databases, APIs, repositories, and external services through MCP — the Model Context Protocol. 16 curated templates ship with governance-safe defaults: egress allowlists, credential refs, taint and sink rules. Any custom MCP server — stdio or HTTP — connects in minutes.
Read-only queries, egress allowlist, credential injection
Read queries by default, writes require approval
Scoped tokens, create_issue gated as external_comms
Merge requests require approval after untrusted input
post_message gated as external_comms
send_email requires approval, read is open
Output marked untrusted — taints the session
Geocoding and directions, no write surface
Search and read, no delete or modify
create-event gated as external_comms
Directory allowlist, path validation
Egress allowlist only, output untrusted
16 curated templates — plus memory, git, time, and any MCP server you bring.
Any MCP server — stdio or HTTP — connects in minutes. Define the tools, set the policy, deploy.
Channels are how humans talk to agents. Connect a Telegram bot, a Slack workspace, or embed a chat widget on your site. Bot tokens are injected out-of-band from the vault — never exposed to the agent or stored in its environment. Every channel inherits the same governance: policy-checked, budget-capped, fully traced.
Users reach agents through channels. Agents reach systems through MCP. Both are governed.
Upload PDF, DOCX, HTML, CSV, images with OCR. Sync external sources — Confluence, Google Drive, Notion. Hybrid retrieval: dense vector + lexical, fused with reciprocal rank fusion, optional reranker. KB results are untrusted by default — consuming them taints the session.
Every agent is one of three types. But they're not isolated — they compose into teams that tackle work no single agent could.
One agent, one task.
An autonomous agent that reasons step by step, calls governed tools, and streams the answer in real time. Simple, fast, effective.
Many agents, one goal.
A self-organizing mesh. Tasks land on a shared board and are claimed by the best-matching agent — based on capability, reputation, and load. Complex tasks auto-decompose into subtasks. Results roll back up. No central dispatcher. No single point of failure.
A workflow you design.
Build versioned workflows in the visual Graph Studio. Parallel branches, map operations, conditional edges, subgraphs. Deploy, run, replay. Each node is a governed step — LLM call, tool call, or decision.
Because every agent type shares the same governed task board, they compose into teams — any combination, any hierarchy.
One team. Mixed types. Shared board. Durable delegation. Every interaction governed — every subtask policy-checked, budget-capped, and traced. Just like the parent.
Not after. Not in parallel. Before. Every tool call, every generation, passes through these gates — in order, every time.
Only declared tools. Only for the caller's role. The agent can't discover or invoke anything you haven't explicitly approved.
Per-parameter rules: regex match, max length. The agent can't pass a DROP TABLE through a tool that expects SELECT.
When the agent consumes untrusted data — web pages, KB results, external API responses — the session is tainted. A tainted session calling a dangerous sink (payment, external comms, code execution) is blocked until a human approves.
Output from untrusted servers is withheld behind an opaque reference. The agent gets only structured fields — extracted by a sandboxed model. Raw, potentially injected text never reaches the agent's context.
Every LLM request is clamped to the remaining budget. Streaming included — the provider stops mid-generation if the budget is exhausted. The proxy returns 402. No surprise invoices.
Every tool call, every generation, every policy decision — recorded with timing, tokens, cost, and outcome. Stream to the Trace Explorer, export to OTLP or Langfuse. Nothing happens in the dark.
Three agent modes, one governed platform. Toggle the trace to see every policy check, tool call, and token — accounted for in real time.
One autonomous agent: it reasons, calls governed tools and streams the answer token by token.
Connect Postgres (read-only). Agent analyzes weekly signups, detects anomalies, posts findings to Slack. Every SQL query validated. Budget capped at $5. No write access — ever.
Five agents research across Brave Search, GitHub, and your KB. Tasks distribute across the mesh by capability. Results converge. Web data is tainted — the swarm can't email anyone without approval.
A graph: collect changes → draft → verify links → publish. Each step traced. Publishing requires approval. The graph is versioned — roll back or replay any run.
A graph coordinates the pipeline. One node dispatches a swarm to research the market. Another triggers a single agent to pull historical metrics from Postgres. Results converge — the graph compiles the launch report. Three agent types, one team, every step governed.
Deploy your way — self-hosted, managed cloud, or on-premise. With the isolation, identity, and supply-chain integrity a business needs.
Connect a data source. Deploy an agent. Watch every action get policy-checked — in minutes, not weeks.