Every Skill. Every MCP.

Give everyone agents that are actually allowed to work.

  • One governed connector per employee, assigned by your identity provider
  • Every MCP server and Skill that person is entitled to, and nothing they are not
  • Policies on the real arguments of a call, with human approval where it matters
  • PII redaction and a tamper-evident audit trail

Your rules travel with your people — whichever assistant they open.

  • ChatGPT
  • Claude
  • Microsoft Copilot Studio
  • Gemini
  • Cursor
  • Visual Studio Code
  • JetBrains
  • Windsurf
  • Amazon Q
  • Zed

Talk to your assistant about Palma

Common questions

  • What does Palma actually do?

    Every person gets one connector. It carries exactly the systems and playbooks they are entitled to into whichever assistant they already use. Rules decide what can be done with them, risky actions wait for a human, and every action stays attributable.

  • Why not just connect our systems ourselves?

    Once is fine. The tenth time is not: each assistant to each system, for each team, with its own credentials, owner and security review. Credentials end up on laptops and in config files, nobody can say who may reach what, and the work never finishes. One connector replaces that whole matrix.

  • When something goes wrong, can we tell who did it?

    Yes, and it is usually the question that decides whether security signs off. Every action records the person it was done for, the agent that did it, and the application it ran in — Cursor, Claude Desktop or something you built. Not one shared service account nobody can trace.

  • What can we actually show an auditor?

    A complete record of every action: who for, which agent, which application, which tool, what was passed and what came back. Tamper-evident and verifiable offline with your own key, so nobody has to take our word for it, and it streams into the SIEM you already run.

  • Does this cover the EU AI Act, DORA and SOC 2?

    Those frameworks ask for evidence, and that is what Palma produces by default — every action traceable, every decision logged, retention set to your policy. EU AI Act obligations took effect on 2 August 2026, with penalties tied to global turnover. For where our own certifications stand, ask the team.

  • Where does Palma run, and does our data leave?

    On your own infrastructure by default, so data, credentials and audit logs never leave your environment — including fully air-gapped. Each tenant’s encryption keys are separate. If you would rather not run it yourself, we will host it.

  • Can we tell what our AI actually costs?

    Yes — by business case, team, agent and person. You can say what each initiative costs instead of pointing at one unexplained line item, set budgets per Space, and produce chargeback reports finance will accept.

  • How quickly can we get to production?

    A first Space takes about 20 minutes: connect your MCP servers, let Palma find the tools, bundle the ones you want, set a rule, and you are live. A full rollout depends on scope, but most enterprises go from first demo to first governed Space within a week.

Latest Blog Posts

Common Questions

Quick answers about Palma.ai's enterprise MCP platform

What is Palma.ai in one sentence?

Palma.ai is the enterprise governance layer for MCP — it gives every person and agent a single governed connector carrying the tools and Skills they're entitled to, enforces policies on the actual arguments of a call, pauses high-risk actions for approval, and records everything in a tamper-evident audit trail.

What does MCP governance mean?

Deciding which person may use which tool, with which arguments, with whose approval — and being able to prove it afterwards. MCP itself covers how a client authenticates to a server and how a tool is described and called; it does not decide which person may use which tool, hold a risky call for a human, or keep the record an auditor asks for. Palma adds that layer: one governed connector per person, assigned by identity-provider group, carrying the tools and Skills they are entitled to into whichever assistant they already use.

Does my team have to set up MCP servers themselves?

No. Connectors are assigned by IdP group through Entra or Okta, so a joiner gets theirs on day one and a leaver loses it the moment the group changes. Every MCP server your team approves arrives through that same connector — no per-user install, no config files, no credentials sitting on a laptop.

What's a Skill, and why does it matter?

A tool is a verb — "send an email". A Skill is the playbook that tells an agent when and how to use the verbs it already has: how your team actually closes the books, runs an incident review, or qualifies a lead. Skills are versioned, scanned before they're served, and scoped like any other piece of enterprise software — so your best operator's process reaches everyone else's agent.

Does it work with the AI clients we already use?

Yes — everything is served over MCP, so the same connector, Skills and policies follow the person into whichever assistant they open, whether that's Claude, ChatGPT, Copilot, Cursor or something else. Switching tools doesn't mean re-approving, re-installing or re-auditing anything.

How do we prove what an agent actually did?

Every tool call is attributed to the person it was done for, the agent that did it, and the application it ran in — with the arguments, result, duration and cost. The audit trail is tamper-evident and verifiable offline with your own key, so your auditor doesn't have to take our word for it, and it streams to the SIEM you already run.

How is Palma.ai deployed — SaaS, on-prem, VPC?

Palma.ai is designed for enterprise environments: typically VPC or on-prem, including fully air-gapped, depending on your regulatory and security needs. The MCP layer and governance plane run on your infrastructure, so sensitive business data doesn't have to move into multi-tenant SaaS. We can also host it for you if you prefer.