Build Flows

Free tool · IT

Agent replay: watch a governed agent work

Pick a construction question and step through what happens between the chat box and Procore, P6 or the ERP: which tools the agent finds, what the gateway allows, where a person approves, what gets denied, and what lands in the audit log.

Replay of a scripted example with synthetic data

Pick a question

“Which subs have overdue RFIs on Job 24-101?”

Router mode: the agent searches 2,755 generated tools, narrows to one, calls it read-only, and answers with RFI numbers it can cite.

Keyboard: ← → step, Space plays or pauses, Home and End jump.

User
Agent
Gateway
Procore MCP
Procore

Next step

Want agents like this on your own systems?

We build governed MCP servers and gateways for Procore, Primavera P6 and ERP data: scoped keys, approvals on writes, and a log of every call. Tell us which questions your team asks most and we’ll talk through what a first, read-only agent would look like.

What makes this safe

  • Least privilege

    Each agent gets its own key, and the key is the policy: which servers, which tools, which limits. A tool that isn't in the key can't be called, as the payroll request shows.

  • Approvals on writes

    Tools that change records are flagged. The gateway holds the call, shows a preview, and runs it once, with an idempotency key, only after a named person approves.

  • Audit on every call

    One dispatch path validates, rate limits, checks policy and logs input and output with the org, user, key and server. When an answer looks wrong, you open the call and see why.

  • Per-org credentials

    Upstream credentials stay on the server, provisioned per organization and never shared across them. The model never sees a token, and agents act within the access each org grants.

More on how we run agents in production: governance and security and data handling.

See the real builds

Frequently asked questions

Is this a live agent?

No. Each scenario is a scripted trace with synthetic data: no model or API is called, and the project, companies, RFIs, activities and amounts are made up. Token counts and timings are illustrative. The sequence of steps follows the MCP servers and gateway we have built for Procore and Primavera P6.

What is the gateway in the diagram?

A single MCP endpoint in front of one or more MCP servers. It decides which tools a key can see, injects upstream credentials, enforces rate limits, checks policy, caches safe reads and logs every call. Agents never talk to Procore, P6 or the ERP directly.

Why does the agent search for tools instead of seeing them all?

Procore's API produced 2,755 tools when we generated an MCP server from its OpenAPI spec. Loading all of them into every request costs tokens and makes wrong picks more likely. In router mode the model sees about 25 meta-tools, searches by intent, and only the few matching schemas reach its context.

Can an agent write to our systems?

Only if its key includes the write tool, and then through policy, a preview and approval by a named person. We start with read-only agents and add writes once the read side has earned trust.