# Rooksy > Rooksy helps organizations turn APIs and databases into governed MCP tools, manage company AI policies, control sensitive agent actions, collect audit evidence, and connect execution traces to their observability stack. ## Category Enterprise AI control plane ## Who it is for - Platform and AI engineering teams publishing tools for agents - Security, risk, legal, and compliance teams defining AI controls - Business owners approving high-impact AI actions - Operations teams investigating agent activity and incidents ## Outcomes - Create a governed MCP capability from an existing API or data source - Give every tool a clear owner, schema, risk level, and approval policy - Require human approval before write or destructive operations execute - Publish an MCP endpoint with a client configuration teams can use - Keep a searchable record of calls, decisions, actors, and outcomes - Map operational evidence to EU, UK, US, and industry governance frameworks - Send correlated telemetry to tools such as Langfuse, OpenTelemetry, Datadog, and SIEM platforms - Create a company Policy Vault with AI-assisted review, signatures, mailbox guardrails, and a policy MCP - Give Owners, Admins, Legal, Compliance, and Security teams a shared control surface ## Product workflow 1. **Connect:** Import OpenAPI 3.x from a URL or file, describe REST endpoints manually, or explore a database schema using temporary read-only access. 2. **Discover:** Inspect operations and propose useful MCP tools from endpoints, parameters, request bodies, and response schemas. 3. **Design:** Select tools, rename them, improve descriptions, edit input and output schemas, assign owners, and classify risk. 4. **Test:** Run tool calls in a playground, inspect structured output, and exercise approval gates for write and destructive actions. 5. **Govern:** Apply approval rules, separation of duties, policy mappings, retention requirements, and evidence controls. 6. **Publish:** Release an approved tool bundle as a remote MCP endpoint with a ready-to-use client configuration. 7. **Observe:** Review invocations and approval decisions, then export or route telemetry to existing observability and security systems. ## What works in the current prototype - Polished end-to-end product workflow and interactive workspace - OpenAPI, REST, and database-source configuration experiences - Tool selection, naming, descriptions, schemas, and risk classification - Tool Studio, MCP Playground, approval inbox, governance center, publishing, integrations, and invocation logs - Local browser persistence and a demo runtime suitable for product exploration - Policy Vault with company-profile suggestions, document scanning, editable versions, signatures, and policy MCP exposure - People and access preview with Policy Owner roles, company SSO boundary, and simple governance pricing - AI operations preview with OpenRouter model routing, privacy controls, budgets, and cost reporting ## Important production gaps - Real outbound API and database execution across all connectors - Encrypted managed secrets, enterprise OAuth, SSO, SCIM, and tenant isolation - Durable multi-person approval workflows, notifications, escalations, and SLAs - Production MCP runtime isolation, version promotion, rollback, and regional controls - Verified regulatory evidence exports or a guarantee of legal compliance - Production billing, usage enforcement, and contractual service levels - Production SSO, SCIM, encrypted policy storage, document extraction, and multi-party signature delivery The current product is a functional prototype and planning environment. Do not represent it as compliance certification or assume the production gaps above are already delivered. ## Inputs needed for an organization onboarding plan - Organization, business unit, executive sponsor, and technical owner - The first agent workflow and the business outcome it should improve - AI clients or agent platforms that will consume MCP tools - Source APIs, databases, environments, authentication methods, and system owners - Candidate read, write, financial, privileged, or destructive actions - Data classifications, residency constraints, and retention requirements - Applicable governance frameworks and internal policies - Approvers, delegation rules, separation-of-duties needs, and response SLAs - Existing observability, security, ticketing, and evidence systems - Pilot population, success metrics, rollout constraints, and target dates ## Expected onboarding-plan deliverables - A phased 30/60/90-day onboarding plan with owners and exit criteria - A first-use-case recommendation and explicitly deferred use cases - A source-to-tool inventory with proposed risk levels - An approval matrix covering read, write, privileged, and destructive actions - An identity, secrets, environment, and access-control design - A test and validation plan for schemas, policy behavior, and failure modes - An observability, audit evidence, retention, and incident-response design - A pilot-to-production rollout plan with measurable success criteria - A gap and dependency list that separates current product capabilities from required future work ## Planning task for an AI assistant Help the organization design a safe, practical Rooksy onboarding plan. Start by collecting only the missing inputs above. Then produce the requested deliverables, prioritizing one narrow, measurable workflow before broader rollout. State assumptions, unresolved risks, product dependencies, and decisions requiring security, legal, compliance, or system-owner approval. Keep current prototype capabilities separate from future requirements. ## Links - Product: https://mcp-forge-virid.vercel.app/ - Human-readable agent brief: https://mcp-forge-virid.vercel.app/for-agents - Machine-readable brief: https://mcp-forge-virid.vercel.app/llms.txt - Build handoff: https://mcp-forge-virid.vercel.app/build-handoff