Product / Tools & Actions
Connect your systems. Control every action.
Let agents look up bills, apply credits and open tickets. Your policies control what runs, when approval is needed and how completion is verified.
Tools
Callables your agent can invoke and the provider connections they depend on.
Account identity verificationReadsUsed by 1 step
billing.verify_identity
via Acme Billing · billing · revision 3f9a2c1e · 1,204 calls · 99% ok · 140 ms p95
Latest bill fetchReadsUsed by 1 step
billing.fetch_latest_bill
via Acme Billing · billing · revision 8b21d0f4 · 962 calls · 98% ok · 210 ms p95
Apply goodwill creditWritesVerified by responseUsed by 1 step
billing.apply_goodwill_credit
via Acme Billing · billing · revision c07e51aa · 118 calls · 97% ok · 380 ms p95
Dispute ticketWritesNo verification policyUsed by 1 step
billing.create_dispute_ticket
via Zendesk · billing · revision 5d1f93b2 · 41 calls · 95% ok · 520 ms p95
Last error 2 h ago: 429 rate limited
Evaluate disputeReadsUsed by 1 step
billing.evaluate_dispute
sandbox · billing · revision 91ac4e07 · 118 calls · 100% ok · 45 ms p95
Every action carries its own rules
A tool is more than an endpoint. Each callable declares what it reads or writes, how completion is proven and when a person must confirm.
Connect your own APIs with an API key or bearer token, or Zendesk, HubSpot, Salesforce and the calendars with OAuth, then bind their operations to steps.
Every callable your agent may invoke, with its reads and writes, its connection, its revision and the steps that use it.
A write declares how success is proven: response evidence, read after write, deferred reconcile or manual. Nothing is reported done on faith.
Read-only logic can run as sandboxed code, like evaluating a dispute, with the same revision history as an API call.
Tools
Callables your agent can invoke and the provider connections they depend on.
- Acme BillingBearer Token3 callablesConnected
- ZendeskOAuthCreate Ticket · Get TicketConnected
- Google CalendarOAuthCheck Availability · Create EventConnected
- HubSpotOAuthCreate Contact · Get Contact · List DealsConnect
- SalesforceOAuthCustom OAuth ProviderConnect
Authentication for your own APIs: API Key, Bearer Token or None. Providers connect with OAuth.
Observe before you enforce
Authorisation runs in log-only mode for fourteen days before it may block anything, and the platform lists what still needs review.
Off, Log only or Enforce, set once for the organisation, with an unmatched-tool decision of allow or deny.
Authorisation decisions and credential reads land in the hash-chained audit log with actor, resource and outcome.
Tool authorization
How the platform treats a tool call that no policy matches, and when it may block one.
Mode
Unmatched tool decision
Enforcement readiness Not ready
- Complete the 14-day observation window.Observation age · 9 of 14 days
- Review all would-deny events.Unreviewed decisions · 3
- Resolve calls with missing authorization context.Missing context events · 0
- Review every dormant authored tool.Dormant tools requiring review · 1
Tools & Actions by the numbers
4
Risk classes: read, reversible, high impact and forbidden
5 min
A fresh login is required before payment, credential or identity changes
0
Writes published without a verification policy
How it works
Up and running in three steps
01
Connect the system
Add the API or connector and enter its credential once. It is encrypted and never shown again.
02
Bind it to a step
Choose the tool on the step that needs it and set confirmation and verification in its policy.
03
Log only, then enforce
Run authorisation in log-only mode, review the decisions, then switch to enforce.
FAQ
Common questions
Can an agent do something it wasn't granted?
No. Tools are pinned to an agent version and every call is checked against policy at runtime, so a prompt injection cannot widen what an agent is allowed to do. A forbidden class is denied outright.
What happens when a system is slow or down?
A timeout is an unknown outcome. The agent tells the customer the action is delayed or awaiting verification, never that it went through, and an operator settles it in Operations with the evidence they checked.
Do you connect to core banking?
Through the APIs you expose. There are no off-the-shelf core-banking connectors; teams add the endpoints they need as custom APIs, with the same risk classes, confirmations and verification.
Can it work in systems that have no API?
Not directly. Ruhu acts through APIs, OAuth integrations and sandboxed code. A system with no API is reached through a service that does expose one, such as a ticketing tool or a wrapper your team runs.
Start with one workflow
Which customer request should we tackle first?
Bring a procedure and the systems it touches. We’ll walk through the agent, the setup and how you would measure the result.
