braXos Maestro - Overview¶
Secure AI-Enablement. Force-Multiplied.
braXos Maestro is a remote Model Context Protocol (MCP) server. It lets an MCP client - Claude for Work, Claude Desktop, or any MCP-compatible agent - securely call your organization's systems of record through a single governed gateway.
What you can do with it¶
Once connected, Claude can work across the systems your organization has enabled:
| System | Examples |
|---|---|
| Google Workspace | Search Gmail, read/append Docs, read/write Sheets, manage Drive files, calendar events, and directory (users/groups/OUs) |
| Jira | Find issues by JQL, read/create/update issues, transitions, comments, components |
| Salesforce | Accounts, contacts, cases, opportunities, contracts, assets, TaskRay projects/tasks, and ad-hoc SOQL |
| Physical access control | People, credentials, clearances/access levels, doors/readers, sites, access history, threat levels, and elevator dispatch - across systems such as S2, OpenPath, Genetec, C-CURE 9000, Brivo, Otis, and ThyssenKrupp |
| MediaWiki | Search, read, create, and edit wiki pages |
| Everbridge | Critical-event management - contacts, groups, incidents, and sending mass notifications/alerts |
| HR systems | Worker records, IDs, reports, photos, and time entries (e.g. Workday) |
| Conferencing | Users, groups, meetings, and workspace reservations (e.g. Zoom) |
| RDBMS | Ad-hoc SQL against a configured relational database - read queries and writes (e.g. ODBC data sources) |
The full, per-tool breakdown is in the tool catalog.
The exact tools you see depend on what your administrator has enabled for your organization and your group memberships.
How it's different¶
- One connection, many systems. You connect to braXos Maestro once; it fronts every system your organization has configured.
- Per-organization isolation. Your identity and organization membership are derived server-side from your sign-in - you only ever see and act on your own organization's data. See Security & tenancy.
- Governed and auditable. Every call is authenticated, authorized against your group permissions, and audited.
- Fine-grained access control - even for systems that can't tell your users apart. Some connected systems can act as the individual signed-in user; many others are reached through a single shared service account and have no way of knowing which of your people is behind a request. braXos Maestro closes that gap by enforcing its own per-user, per-group permissions at the gateway: an administrator decides which tools - or even which specific pre-approved actions - each group may use. Those actions can be narrow: one HR team might read only the Workday worker records for employees in their own region, while another reads only workers within a specific department - even though both reach Workday through the same single shared service account.
- Read/write aware. Every tool is annotated so your client knows a lookup from a change: read-only tools can run smoothly, while writes and deletes are gated for your confirmation.
Next steps¶
- Connect Claude to braXos - the setup and sign-in flow
- Tool catalog - what's available, by system
- Example prompts - things to try first
- Security & tenancy - how isolation and auth work