Kumo technology

Integration is a protocol,
not a catalogue.

Most platforms decide what you are allowed to connect. Kumo is built the other way round. Embed our Agent, call our platform, or publish the named operations you want Kumo to use. Whatever you already run, there is almost always a way to work with it, and a way to begin without connecting anything at all.

The Kumo technology suite

Four products. One safety model.

A named Kumo user is attached to every request. Credential scopes can narrow that user's live role; they can never widen it.

01Agent runtime

Kumo AI Platform

Kumo’s model, planner, durable run loop, approvals, co-signature, artifacts, memory, credits, and tamper-evident audit in one governed platform.

  • Named user on every request
  • Human gates on commitment
  • Complete correlated trace
Technical reference
02Application surface

Kumo API

Embed the complete Kumo Agent or call individual HR operations through a versioned REST and Agent API with delegated identity.

  • Agent API + REST
  • Resumable SSE + signed webhooks
  • Generated OpenAPI contract
Technical reference
03Universal integration

Kumo MCP

A matched server, client, and outbound Connector. Your systems call Kumo; Kumo calls the named tools you choose to publish.

  • Protocol, not a catalogue
  • No inbound port with Connector
  • Receipts, attribution, idempotency
Technical reference
04Embedding toolkit

Kumo HR Agent Kit SDK

A typed TypeScript client, headless controller, and accessible React panel for putting Kumo inside a customer application.

  • Short-lived delegated credentials
  • Stream reconnect + decisions
  • Webhook verification
Technical reference
Four shapes

Start where it makes sense.

01

Kumo web and mobile

Your people work with the Kumo Agent directly. Nothing else has to connect.

Available today
02

Kumo acts on your systems

The Agent calls a published MCP server or your outbound Kumo Connector.

Available today
03

Your systems act on Kumo

Applications and agents call the Kumo MCP Server or versioned REST API.

Available today
04

Your application embeds Kumo

The complete Agent runs inside your product through the Agent API and SDK.

Available today
The integration ladder

Three levels. You choose.

Each level stands on its own. Moving up does not require replacing what came before.

Level 1

No external integration

Kumo web and mobile operate as the people system in their own right. No inbound port, no credentials to an external system, and no copied database.

Level 2

Your systems call Kumo

Use a scoped Kumo credential with the Kumo API or MCP Server. Your systems are the caller; credentials to those systems never reach Kumo.

Level 3

Kumo calls named tools

Publish an HTTPS MCP endpoint, or keep the adapter and its system credentials inside your network while the Kumo Connector dials out over TLS.

The trust boundary

The tool is the boundary.

Kumo can call only the explicit operations you publish. With the outbound Connector, the adapter and credentials stay inside your network and the session opens outward.

Security architecture
  • No copy of your database
  • No inbound network route
  • No administrative credential to your core system
  • No operational technology or physical-site network
  • No operation you did not explicitly publish
  • No background synchronisation or shadow source of truth

Whatever you run, keep it.

Start with Kumo alone. Connect one named operation, or the whole workflow, when you are ready.