<!-- Generated from the rendered page by scripts/write-llm-mirrors.mjs. Do not edit by hand. -->
Canonical: https://molo17.com/ai-hub/enterprise-brain/skills-and-company-tools/
Markdown mirror: https://molo17.com/ai-hub/enterprise-brain/skills-and-company-tools/index.md
Title: Skills and company tools · Gluesync Enterprise Brain · MOLO17
Description: Extend the Gluesync Enterprise Brain with agent-written skills and approved company tools: publish procedures as immutable skills and register GitLab, Notion, or any HTTPS MCP server as a governed tool bundle.

[Gluesync Enterprise Brain](/ai-hub/enterprise-brain/) · Extend

# It starts with your databases. It ends wherever you plug in.

The brain grows in two directions. Skills capture the procedures your agents discover and make them reusable, versioned, and immutable. Company tools bring GitLab, Notion, and any approved MCP server into the same governed loop, registered while in platform, refused everywhere else.

[Book a demo](/book-a-demo/) [Read the docs](https://docs.molo17.com/gluesync/latest/gs-modules/enterprise-brain.html)

1.  01 An agent answers a question
2.  02 It publishes the procedure as a skill
3.  03 The next agent, and the next tool, start from there

How it works

## From one good answer to a company capability

1.  01
    
    Discover
    
    ### The agent finds the route
    
    Grounded in the schema graph and shared memory, a Spark agent works out which tables, joins, and filters answer the question, and which approved tools it needed along the way.
    
2.  02
    
    Publish
    
    ### The route becomes a skill
    
    With the publish\_skill capability the agent freezes that procedure as an immutable, versioned skill. The transcript links to it; the Build & publish workspace highlights it for review.
    
3.  03
    
    Reuse
    
    ### Attach without a new version
    
    Attach the skill to any published agent without cutting a new agent version. Managers, Super admins, and keys with the skills:publish scope decide what the company keeps.
    

Capabilities

## Skills you write, skills agents write, tools you approve

Everything the brain learns stays inspectable: a skill is text and contracts, a tool bundle is a named list of remote tools, and both carry provenance and a version.

Skills

### Immutable, versioned procedures

Instruction, knowledge, and tool-bundle skills are referenced by slug and version from one or more published agents.

-   Instructions, input and output contracts, required capabilities, provenance
-   Published by a person in Build & publish, or by an agent through publish\_skill
-   Every chat reply and run result lists the skills it produced under skillRefs

Company tools

### Approved remote MCP servers

Register GitLab, Notion, or any HTTPS MCP server while in platform. Discover its tools, choose the ones you want, and publish them as a tool bundle.

-   HTTPS only, and the host must be on the allow-list you typed; unregistered hosts are refused
-   Optional vaulted secret reference sent as a bearer token; the secret never lands in the brain
-   Remote calls are treated as writes and wait for a signed-in approval

Memory

### Location and procedure, not rows

When a run or a conversation completes, the input and the tool trace are sedimented into a memory candidate and queued off the request path.

-   Shared by default across everyone who uses the agent; "keep this private" makes it yours
-   Password, token, secret, and API key assignments are redacted before anything is stored
-   Background ingestion keeps chat and runs fast while the brain keeps learning

FAQ

## Skills and company tools: questions we hear

Can an agent publish a skill without anyone noticing?

No. publish\_skill requires the caller to be a Manager or Super admin, or a platform key that carries the skills:publish scope. The published skill appears in Build & publish with a version, a content hash, and the run or conversation that produced it.

Which company tools can I plug in?

Any MCP server reachable over HTTPS: GitLab, Notion, an internal ticketing system, a document store. You register the URL and its allowed hosts, discover the tools it exposes, and bundle the ones you want. Nothing outside the allow-list can be called from a run.

How do remote tools stay safe?

They are always treated as writes. A run that wants to call one parks until a signed-in user approves it; API keys, personal tokens, and schedules cannot approve on their own. The bearer secret comes from a vault reference, and unregistered hosts are refused before any request leaves Core Hub.

What if a memory is wrong or should not have been shared?

Anyone who can see a shared memory can forget it, and every user can forget or make private their own. Memory never contains result rows or credentials, so the worst case is a stale route, not a leaked value.

Enterprise brain

## Keep exploring

[Overview **Gluesync Enterprise Brain**

The foundation for every AI tool your company uses, built on the databases Gluesync already integrates.

Explore →](/ai-hub/enterprise-brain/) [Connect **Connect your AI tools**

Point Claude, ChatGPT, Grok, Meta Muse, Hermes Agent, OpenClaw, or Cursor at Core Hub and let them ask the brain under the caller's permissions.

Explore →](/ai-hub/enterprise-brain/connect-your-ai-tools/) [Own **Ownership and privacy**

A dedicated brain database on your infrastructure, memory shared by default and private on request, never rows, never secrets, never SaaS.

Explore →](/ai-hub/enterprise-brain/ownership-and-privacy/)

Gluesync Enterprise Brain

## Plug in the tools your company already runs on.

Skills make one good answer repeatable. Company tools make the brain reach beyond the database. Both stay versioned, approved, and yours.

[Book a demo](/book-a-demo/) [Get Gluesync](/get-gluesync/)
