Skip to content

braXos Maestro - Overview

Secure AI-Enablement. Force-Multiplied.

braXos Maestro is a remote Model Context Protocol (MCP) server. It lets an MCP client - Claude for Work, Claude Desktop, or any MCP-compatible agent - securely call your organization's systems of record through a single governed gateway.

What you can do with it

Once connected, Claude can work across the systems your organization has enabled:

System Examples
Google Workspace Search Gmail, read/append Docs, read/write Sheets, manage Drive files, calendar events, and directory (users/groups/OUs)
Jira Find issues by JQL, read/create/update issues, transitions, comments, components
Salesforce Accounts, contacts, cases, opportunities, contracts, assets, TaskRay projects/tasks, and ad-hoc SOQL
Physical access control People, credentials, clearances/access levels, doors/readers, sites, access history, threat levels, and elevator dispatch - across systems such as S2, OpenPath, Genetec, C-CURE 9000, Brivo, Otis, and ThyssenKrupp
MediaWiki Search, read, create, and edit wiki pages
Everbridge Critical-event management - contacts, groups, incidents, and sending mass notifications/alerts
HR systems Worker records, IDs, reports, photos, and time entries (e.g. Workday)
Conferencing Users, groups, meetings, and workspace reservations (e.g. Zoom)
RDBMS Ad-hoc SQL against a configured relational database - read queries and writes (e.g. ODBC data sources)

The full, per-tool breakdown is in the tool catalog.

The exact tools you see depend on what your administrator has enabled for your organization and your group memberships.

How it's different

  • One connection, many systems. You connect to braXos Maestro once; it fronts every system your organization has configured.
  • Per-organization isolation. Your identity and organization membership are derived server-side from your sign-in - you only ever see and act on your own organization's data. See Security & tenancy.
  • Governed and auditable. Every call is authenticated, authorized against your group permissions, and audited.
  • Fine-grained access control - even for systems that can't tell your users apart. Some connected systems can act as the individual signed-in user; many others are reached through a single shared service account and have no way of knowing which of your people is behind a request. braXos Maestro closes that gap by enforcing its own per-user, per-group permissions at the gateway: an administrator decides which tools - or even which specific pre-approved actions - each group may use. Those actions can be narrow: one HR team might read only the Workday worker records for employees in their own region, while another reads only workers within a specific department - even though both reach Workday through the same single shared service account.
  • Read/write aware. Every tool is annotated so your client knows a lookup from a change: read-only tools can run smoothly, while writes and deletes are gated for your confirmation.

Next steps