Kumo AI Platform
Kumo’s model, planner, durable run loop, approvals, co-signature, artifacts, memory, credits, and tamper-evident audit in one governed platform.
- Named user on every request
- Human gates on commitment
- Complete correlated trace
Most platforms decide what you are allowed to connect. Kumo is built the other way round. Embed our Agent, call our platform, or publish the named operations you want Kumo to use. Whatever you already run, there is almost always a way to work with it, and a way to begin without connecting anything at all.
A named Kumo user is attached to every request. Credential scopes can narrow that user's live role; they can never widen it.
Kumo’s model, planner, durable run loop, approvals, co-signature, artifacts, memory, credits, and tamper-evident audit in one governed platform.
Embed the complete Kumo Agent or call individual HR operations through a versioned REST and Agent API with delegated identity.
A matched server, client, and outbound Connector. Your systems call Kumo; Kumo calls the named tools you choose to publish.
A typed TypeScript client, headless controller, and accessible React panel for putting Kumo inside a customer application.
Your people work with the Kumo Agent directly. Nothing else has to connect.
Available todayThe Agent calls a published MCP server or your outbound Kumo Connector.
Available todayApplications and agents call the Kumo MCP Server or versioned REST API.
Available todayThe complete Agent runs inside your product through the Agent API and SDK.
Available todayEach level stands on its own. Moving up does not require replacing what came before.
Kumo web and mobile operate as the people system in their own right. No inbound port, no credentials to an external system, and no copied database.
Use a scoped Kumo credential with the Kumo API or MCP Server. Your systems are the caller; credentials to those systems never reach Kumo.
Publish an HTTPS MCP endpoint, or keep the adapter and its system credentials inside your network while the Kumo Connector dials out over TLS.
Kumo can call only the explicit operations you publish. With the outbound Connector, the adapter and credentials stay inside your network and the session opens outward.
Security architecture →Start with Kumo alone. Connect one named operation, or the whole workflow, when you are ready.