One agent across your entire software.
CRM, documents, data, processes — in one conversation. You describe what should happen. Daedalus is the layer on which an AI agent works across all your systems — not one more tool, the level beneath that connects everything.
We only meant to connect Pipedrive. Then we tried Claude Code and saw how powerful an agent becomes when it actually does things — instead of just talking. We wanted that feeling for the whole company. Every feature was added because it closed a real gap in our workflows.
Building software gets cheap. Connecting gets valuable.
With AI, programming gets cheap — every small company with one developer now builds internal software that was unthinkable before. The markets reflect it: SaaS valuations are softening. But the existing software doesn't disappear. It's needed — as a system of record, a reliable source of truth. We respect that: We don't replace your systems. We activate them.
One layer. All systems beneath. Two doors above.
Daedalus sits as an integration layer over your existing systems and connects them through a meta-protocol — Browse Mode. That lets you connect unlimited systems without overloading the AI. And above it, Daedalus has two entrances that make everything possible:
One layer connects everything below. Two doors above: agents come in via MCP, apps via HTTP.
And the crucial part: every single function on this layer is itself reachable and settable by AI — down to the last screw.
Three tasks. One toolkit.
What turns the agent from chatbot into colleague: it can actually work. Each task combines different capabilities — and it escalates.
We didn't have to program this process ourselves. The integration is so complete that the AI builds it itself — and tests it directly with sample data.
This is Claude Code for your business.
AI in business doesn't fail on capability.
That an agent can read your CRM, draft an email, search a document — that's solved. The real question is different: Can I trust it? Can I control it? Do I see what it does? That's exactly where Daedalus starts. Four pillars.
Monitoring
Complete live monitoring: everything the agent does is streamed to the monitoring in real time — which route, which system, what it searches and writes. You watch live, no black-box trust. Per step: transcript, token and context usage, auditable.
Permissions
Settable per route individually — and per account. Two axes: tier (how reversible an action is) and level (how the agent handles it).
Secrets & sandbox
Credentials never enter the agent context — no prompt injection that leaks secrets. No arbitrary HTTP or file access from the sandbox. And write actions get an undo token: reversible as long as the state hasn't changed.
Organising processes
More than question-and-answer: agentic workflows across multiple steps with persistent state. Time-, event- or webhook-triggered. If a step hits deny, it's rejected; if it hits ask, it's escalated — you get a notification and approve. The run doesn't abort.
Around 40 systems. Seven understandable groups.
Not countable, but extensible: every new system is another door behind which the same agent works. Sorted into bundles — the right altitude to show what Daedalus connects.
Bundles are the unit for distribution and provisioning per user. A bundle that isn't connected is invisible — no half-state. And apps run on the same layer: the Newsletter Studio is the first one running on it today.
Imagine an app that shows you all the buttons first.
Why can we connect unlimited systems where others choke on the tool flood? It comes down to how an AI even „sees“ software today: MCP first shows it the complete list of all functions, then it's supposed to find the right button — which shows something, then the next. With 10 buttons that's fine. Pipedrive has ~120, PostHog ~290. No human would want to use an app like that.
The full button list first, then search. The more the software can do, the less usable the list becomes.
The buttons sit in the content — where they point. The agent browses like a website.
Others ease this with tool loaders and sub-agents — that's roughly how Claude does it. It helps, but doesn't fundamentally solve it. We wrote up the whole background: What is MCP, and why should I care?
Our solution is obvious: Content Interleaved Discovery — the buttons belong in the content, not in a list in front of it. That's exactly what makes the layer possible.
The agent browses your systems like web pages.
Instead of maintaining a custom integration per tool, the agent works with just four tools — and discovers the interface as it goes. That's the trick that allows unlimited systems without overloading the AI.
Go deeper? → Browse Mode: pages, not tools · Why not MCP alone
Your stack. Your data. No lock-in.
Daedalus runs open source and EU-hosted, isolated per user, with an open standard underneath. For customers where data & sovereignty are the core question, that's not an add-on but the basis of trust.
Bring your own agent.
Daedalus speaks the open MCP standard. You don't have to use our agent — the same layer works with what you already use. And the agentic runs are provider-agnostic.
Ask the agent yourself.
Real agent · real-time access across systems · no appointment