Integrations
PRAE meets agents where they execute.
Start from the agent environments you already use. PRAE sits at the runtime boundary underneath them and decides which consequential actions may run, then keeps verifiable evidence of each decision.
The agent remains autonomous. The execution remains protected.
-
01 · Agent surface
Where the agent operates: Cursor, Claude Desktop, Windsurf, GitHub Copilot, MCP-connected and custom agents, and agent workloads in your cloud.
-
02 · PRAE runtime enforcement
At the execution boundary, before a consequential action runs: evaluate, enforce, steer, prove.
-
03 · Enterprise systems
What the agent can reach: repositories, tickets, chat, cloud accounts, databases, production systems, sensitive data.
Every integration, at its real status
Shipping means engineering has the path working today. In part means some of the surface is governed, and the page says which part. On the roadmap means no integration exists yet.
| Surface | Integration type | Status | Enforcement path today |
|---|---|---|---|
| Cursor | Developer workflow | In part | PRAE MCP server · instruction ingest |
| Claude Desktop | Agent surface | In part | PRAE MCP server |
| Windsurf | Developer workflow | In part | PRAE MCP server · instruction ingest |
| GitHub Copilot | Developer workflow | In part | PRAE MCP server |
| Slack AI | Enterprise AI surface | On the roadmap | None yet · SDK for agents you build |
| Microsoft 365 Copilot | Enterprise AI surface | On the roadmap | None yet |
| AWS ECS / EKS / Lambda | Cloud runtime | In part | prae-gate judge() in your workload’s code |
| Cloud agent services | Managed agent platform | On the roadmap | None yet · SDK for agents you run yourself |
| MCP & MCP servers | Protocol / tool layer | In part | PRAE MCP server (files) · MCP Gateway in development |
| Node / TypeScript SDK | SDK / runtime | Shipping | prae-gate judge() |
Agent surfaces
Where your agents already operate
- Cursor In part File access through PRAE’s MCP server, and .cursorrules read as policy. Cursor’s built-in tools are not intercepted yet.
- Claude Desktop In part Claude Desktop mounts MCP servers; PRAE’s MCP server gates the files it reaches. Not yet validated end to end.
- Windsurf In part File access through PRAE’s MCP server, and .windsurfrules read as policy. Windsurf’s built-in tools are not intercepted yet.
- GitHub Copilot In part Copilot’s agent mode can use MCP servers; PRAE’s gates the files it reaches. Not yet validated end to end.
- Slack AI On the roadmap No Slack AI integration yet. Agents you build on Slack’s APIs can call PRAE from their own code today.
- Microsoft 365 Copilot On the roadmap No Microsoft 365 Copilot integration yet. Listed so the roadmap is visible.
Cloud runtimes & infrastructure
Where production agents execute
Extend runtime governance from the developer environment into the cloud infrastructure where agents access production systems, services, and data.
- AWS ECS / EKS / Lambda In part Agent workloads in Node or TypeScript on ECS, EKS or Lambda judge each tool call through the SDK. No AWS-specific integration yet.
- Cloud agent services On the roadmap Managed agent platforms and automated cloud workflows. No integration yet; listed so the roadmap is visible.
Protocols & SDKs
How any agent connects to the runtime
The architecture, top to bottom
- Agent surfaces Where your agents operate: coding agents, MCP clients, custom agents and cloud workloads
- Runtime Where the agent executes, and how a decision reaches its action: the SDK, the MCP server
- PRAE control plane What agents may do — decided before each call, and changed while they run
- Guardians Policy grouped by what it protects: files, secrets, processes, egress, budgets, data
- Execution / evidence The action runs only if PRAE allowed it; every decision and intervention is sealed in the ledger
The MCP server and the SDK are how a decision reaches an action. They are parts of the runtime, not the product: the same pack and the same ledger govern every path.
Custom / homegrown agents
Application→ Agent runtime→ PRAE governance boundary→ Tools · APIs · infrastructure
Your framework and model stay as they are. The app calls prae-gate’s judge() before each tool or API call runs — deterministic rules, no model and no proxy in the path — and every decision is sealed in the ledger. How it mounts →