01 What it is // the layer beneath
Daedalus · AI Integration Framework

One agent across your entire software.

CRM, documents, data, processes — in one conversation. You describe what should happen. Daedalus is the layer on which an AI agent works across all your systems — not one more tool, the level beneath that connects everything.

Reach
~40 systemsunlimited, extensible
Two doors
MCP + HTTPfor agents and for apps
Control
auditableevery access live-visible
Location
EU-hostedopen source · GDPR+ · no lock-in
Where it comes from

We only meant to connect Pipedrive. Then we tried Claude Code and saw how powerful an agent becomes when it actually does things — instead of just talking. We wanted that feeling for the whole company. Every feature was added because it closed a real gap in our workflows.

02 Why now // how modern software works

Building software gets cheap. Connecting gets valuable.

With AI, programming gets cheap — every small company with one developer now builds internal software that was unthinkable before. The markets reflect it: SaaS valuations are softening. But the existing software doesn't disappear. It's needed — as a system of record, a reliable source of truth. We respect that: We don't replace your systems. We activate them.

AI makes software cheapsystem of record staysconnecting is the lever
03 The role // Daedalus as a layer

One layer. All systems beneath. Two doors above.

Daedalus sits as an integration layer over your existing systems and connects them through a meta-protocol — Browse Mode. That lets you connect unlimited systems without overloading the AI. And above it, Daedalus has two entrances that make everything possible:

One layer connects everything below. Two doors above: agents come in via MCP, apps via HTTP.

settable by AI

And the crucial part: every single function on this layer is itself reachable and settable by AI — down to the last screw.

04 Operative power // the same toolkit, recombined

Three tasks. One toolkit.

What turns the agent from chatbot into colleague: it can actually work. Each task combines different capabilities — and it escalates.

01 Transfer
Attach the quote PDF from Acme's email to the matching Pipedrive deal.
search mail Mail
read attachment PDF · Word · …
find deal Pipedrive
attach directly file transfer
→ Attachment on the deal — no download, no detour. IngestionFile transfer
VIDEO · Platzhalter Real chat session: task ① — the mail attachment travels to the Pipedrive deal. (Video to follow)
02 Analyse
Which industries and locations are actually in my CRM?
pull all companies Pipedrive
into the database Database
compute statistics Python sandbox
→ Analysis across your whole portfolio — in one run. Python sandboxDatabase
03 Automate triggered · incoming mail
Capture incoming transport orders on your own.
mail comes in Trigger / event
document via OCR Filesystem
defined steps scripted · chat · background
structured order Process
→ A whole workflow that runs on its own. ProcessesTriggers / eventsFilesystem / OCR
the AI builds it itself

We didn't have to program this process ourselves. The integration is so complete that the AI builds it itself — and tests it directly with sample data.

This is Claude Code for your business.

the toolkit
DatabaseFilesystem & ingestionPython sandboxFile transferProcesses
all of it — driven by AI
05 Trust & control // four pillars

AI in business doesn't fail on capability.

That an agent can read your CRM, draft an email, search a document — that's solved. The real question is different: Can I trust it? Can I control it? Do I see what it does? That's exactly where Daedalus starts. Four pillars.

Pillar 01 live in the demo

Monitoring

Complete live monitoring: everything the agent does is streamed to the monitoring in real time — which route, which system, what it searches and writes. You watch live, no black-box trust. Per step: transcript, token and context usage, auditable.

The live monitoring in the demo is really embedded — not a screenshot.
navigate pipedrive://deals 200 ✓
search seafile://playbooks 200 ✓
navigate company-tool://firma/482 200 ✓
submit mail://draft · undo-token 201 ✓
Pillar 02

Permissions

Settable per route individually — and per account. Two axes: tier (how reversible an action is) and level (how the agent handles it).

The check runs before any external service is even touched.
live in monitoring · settable by AI
hidedenyaskinformallow read reversible correctible binding
Tier ↓ · wie umkehrbar Level → · wie der Agent reagiert
Example: a binding action (e.g. send an invoice) → the agent asks once.
Pillar 03

Secrets & sandbox

Credentials never enter the agent context — no prompt injection that leaks secrets. No arbitrary HTTP or file access from the sandbox. And write actions get an undo token: reversible as long as the state hasn't changed.

For sensitive actions: a one-time token the agent presents to you for approval.
Pillar 04

Organising processes

More than question-and-answer: agentic workflows across multiple steps with persistent state. Time-, event- or webhook-triggered. If a step hits deny, it's rejected; if it hits ask, it's escalated — you get a notification and approve. The run doesn't abort.

A triggered run is indistinguishable from a manual one — same check.
FOTO · Platzhalter Screenshot: a process as a diagram in the monitoring — steps, status and branches at a glance. (Screenshot to follow)
06 What it connects // breadth, in seven groups

Around 40 systems. Seven understandable groups.

Not countable, but extensible: every new system is another door behind which the same agent works. Sorted into bundles — the right altitude to show what Daedalus connects.

Sales 6
company-tool · pipedrive · hubspot · twenty · hunter · zerobounce
Office 4
mail · calendar · rocketchat · seafile
AI 2
mistral · openai
Tools 5
sevdesk · plane · figma · umami · metabase
Intel 10
bundesbank · destatis · eurostat · ecb · eur-lex · bundestag · sec-edgar · arxiv · press · hackernews
Prospect 6
arbeitsagentur · arbeitnow · adzuna · himalayas · ats · openregister
Newsletter 3
brevo · cleverreach · newsletter
Company Tool
Company database + AI website deep-dive for enrichment, from 8+ sources.
Custom Bundles
Creatable any time — that's how we connect the very specific software running in your house.

Bundles are the unit for distribution and provisioning per user. A bundle that isn't connected is invisible — no half-state. And apps run on the same layer: the Newsletter Studio is the first one running on it today.

07 Under the hood // Browse Mode · for the technical
For the technical among you

Imagine an app that shows you all the buttons first.

Why can we connect unlimited systems where others choke on the tool flood? It comes down to how an AI even „sees“ software today: MCP first shows it the complete list of all functions, then it's supposed to find the right button — which shows something, then the next. With 10 buttons that's fine. Pipedrive has ~120, PostHog ~290. No human would want to use an app like that.

MCP · all tools first Pipedrive ~120 · PostHog ~290
list_dealsget_dealcreate_dealupdate_dealdelete_dealsearch_dealsget_deal_fieldsupdate_deal_fieldmove_deal_stagelist_personsget_personcreate_personupdate_personmerge_personslist_organizationscreate_organizationupdate_organizationadd_activityupdate_activitylist_activitiesdelete_activitylist_pipelinesget_pipelineupdate_stageadd_notelist_notesconvert_leadlist_leadsattach_product_to_dealget_user_permissionscreate_filterupload_fileattach_file_to_dealcapture_eventquery_eventscreate_insightlist_insightsget_funnellist_cohortscreate_cohortget_feature_flagupdate_feature_flagquery_hogqlget_session_recordingcreate_actionget_trendsget_retentionlist_experimentscreate_annotationlist_dashboardscreate_webhookget_subscription

The full button list first, then search. The more the software can do, the less usable the list becomes.

Browse Mode · one page only what matters here
Deal · Acme Bau GmbH öffnen
Wert 48.000 € ändern
Status Angebot → nächster Schritt
Kontakt Anna M. E-Mail

The buttons sit in the content — where they point. The agent browses like a website.

Others ease this with tool loaders and sub-agents — that's roughly how Claude does it. It helps, but doesn't fundamentally solve it. We wrote up the whole background: What is MCP, and why should I care?

Our solution is obvious: Content Interleaved Discovery — the buttons belong in the content, not in a list in front of it. That's exactly what makes the layer possible.

The agent browses your systems like web pages.

01
Navigate
The agent calls an address in your system — like a URL.
02
Discover
The interface is discovered with the content — no interface pre-maintained per tool.
03
Act
Search, write, compute — within the permissions, every write action with undo.
04
Scale
The same principle applies to every new system. More systems doesn't mean more complexity.

Instead of maintaining a custom integration per tool, the agent works with just four tools — and discovers the interface as it goes. That's the trick that allows unlimited systems without overloading the AI.

navigate
call a route in the system
search
find what's relevant
submit
write — with undo token
python
compute, transform, combine
Technically: CID — Content Interleaved Discovery

Go deeper? → Browse Mode: pages, not tools · Why not MCP alone

08 Sovereignty // and your own agent

Your stack. Your data. No lock-in.

Daedalus runs open source and EU-hosted, isolated per user, with an open standard underneath. For customers where data & sovereignty are the core question, that's not an add-on but the basis of trust.

Open SourceEU-hosted · HetznerGDPR+per-user isolationno vendor lock-inMistral / Scaleway

Bring your own agent.

Daedalus speaks the open MCP standard. You don't have to use our agent — the same layer works with what you already use. And the agentic runs are provider-agnostic.

Claude · AnthropicChatGPT · OpenAIMistralCursor+ any MCP client

Ask the agent yourself.

Real agent · real-time access across systems · no appointment