Connection check
verified live · 26h ago
catalyst
Governance middleware for AI agents: permission gates, approvals, compliance scanning, audit ledger.
Tools
31
GitHub stars
—
Installs / wk
—
Licence
MIT
Transport
streamable-http, sse
Last checked
26h ago
Tools & capabilities
31 toolsRead from the running server on 26h ago.
catalyst_accept_proposals
ids*
Accept one or more proposals, committing them to the flow cycle. ids: list of proposal `idempotency_key` values from catalyst_list_proposals. Do not pass `task_id`… Accept one or more proposals, committing them to the flow cycle. ids: list of proposal `idempotency_key` values from catalyst_list_proposals. Do not pass `task_id` or `id` — the backend looks up proposals by `idempotency_key` and will silently match nothing if the wrong field is used. Acceptance is the governance commit step: items move from review state into live execution state and are recorded in the immutable ledger.
catalyst_activate_compliance_framework
framework*
Activate a pre-built compliance framework pack for this organisation. framework: one of gdpr, soc2, iso27001, hipaa, pci_dss, eu_ai_act, bribery_act, aml_kyc.… Activate a pre-built compliance framework pack for this organisation. framework: one of gdpr, soc2, iso27001, hipaa, pci_dss, eu_ai_act, bribery_act, aml_kyc. Once activated, the pack's DENY/REQUIRE/ADVISE rules are merged into every subsequent compliance scan — no document upload required. Requires can_scan entitlement.
catalyst_await_approval
read-only
proposal_id*
Check approval status for a specific proposal. Returns approved: true/false and clear guidance on whether to proceed. Call this after catalyst_check_action returns… Check approval status for a specific proposal. Returns approved: true/false and clear guidance on whether to proceed. Call this after catalyst_check_action returns 'proposal_required'. Do NOT proceed with the gated action until approved: true is returned. POLLING vs EVENT-DRIVEN: For interactive sessions, poll this tool. For autonomous long-running workflows, prefer registering a webhook via catalyst_register_approval_webhook(callback_url) so your orchestrator is notified the moment a human acts — no polling loop required.
catalyst_bulk_update_tasks
filter*updates*
Bulk update all tasks matching a filter. Growth/Enterprise plans only. filter keys: domain, priority, stage, owner, tag, group_id. updates keys: owner, priority, d… Bulk update all tasks matching a filter. Growth/Enterprise plans only. filter keys: domain, priority, stage, owner, tag, group_id. updates keys: owner, priority, domain, stage, tags_add, tags_remove. Returns matched and updated counts.
catalyst_check_action
titlecontextcapability*
Check if a capability/action is permitted by your governance policy. Returns decision: 'allow' | 'proposal_required' | 'deny' with guidance. Call BEFORE any conseq… Check if a capability/action is permitted by your governance policy. Returns decision: 'allow' | 'proposal_required' | 'deny' with guidance. Call BEFORE any consequential action (API call, data write, send, deploy). If title is provided and decision is 'proposal_required', the intent is logged automatically and proposal_id is returned — no second call needed. If 'proposal_required' without a title, call catalyst_log_task separately. capability examples: 'send_email', 'write_file', 'deploy_code', 'update_record', 'delete_record', 'external_api_call'.
catalyst_create_tasks_from_findings
classes
Materialise compliance findings as actionable flow tasks. classes: list of finding classes to convert, e.g. ['MISSING_CONTROL', 'PROHIBITED_ACTION']. Defaults to b… Materialise compliance findings as actionable flow tasks. classes: list of finding classes to convert, e.g. ['MISSING_CONTROL', 'PROHIBITED_ACTION']. Defaults to both. Created tasks enter the governance pipeline like any other ingest.
catalyst_decline_proposals
ids*
Decline one or more proposals without committing them. ids: list of proposal `idempotency_key` values from catalyst_list_proposals. Do not pass `task_id` or `id` —… Decline one or more proposals without committing them. ids: list of proposal `idempotency_key` values from catalyst_list_proposals. Do not pass `task_id` or `id` — the backend looks up proposals by `idempotency_key` and will silently match nothing if the wrong field is used. Declined proposals are recorded for audit and learning but are not added to the live flow cycle.
catalyst_evaluate_agent_action
read-only
contextactor_id*capability*
Evaluate whether an agent action is permitted by the governance gate. Returns decision: 'allow' | 'proposal_required' | 'deny'. High-risk actors with allow decisio… Evaluate whether an agent action is permitted by the governance gate. Returns decision: 'allow' | 'proposal_required' | 'deny'. High-risk actors with allow decisions are escalated to proposal_required. The actor must be registered and active for this tenant.
catalyst_export_ledger
read-only
sinceformat
Export the immutable SHA-256 chained audit ledger. since: ISO timestamp to filter entries (inclusive). format: 'json' returns full entries; 'csv' sets entries to n… Export the immutable SHA-256 chained audit ledger. since: ISO timestamp to filter entries (inclusive). format: 'json' returns full entries; 'csv' sets entries to null (use REST API for CSV). The ledger is tamper-evident — any modification breaks the hash chain.
catalyst_export_workflow_audit
read-only
sinceworkflow_id*ai_standards_only
Export audit events for an AI workflow as JSON. since: ISO timestamp filter (inclusive). ai_standards_only: limit to events from workflows opted into Built to AI S… Export audit events for an AI workflow as JSON. since: ISO timestamp filter (inclusive). ai_standards_only: limit to events from workflows opted into Built to AI Standards. Suitable for regulatory submissions and investor due diligence.
catalyst_get_compliance_findings
read-only
Get the latest compliance findings from the most recent scan. Returns findings flattened by category: conflicts, gaps, ok. Each finding includes category, severity… Get the latest compliance findings from the most recent scan. Returns findings flattened by category: conflicts, gaps, ok. Each finding includes category, severity, status, and task linkage. Does not trigger a new scan — use catalyst_run_compliance_scan first.
catalyst_get_dashboard
read-only
Get the governance dashboard snapshot including all views. Returns tenant metadata, execution metrics, and all 5 governance views (execution_flow, ownership_map, c… Get the governance dashboard snapshot including all views. Returns tenant metadata, execution metrics, and all 5 governance views (execution_flow, ownership_map, compliance_web, risk_heatmap, client_influence).
catalyst_get_graph_views
read-only
Get all 7 governance graph views for the tenant. Views: org_snapshot, execution_flow, ownership_map, compliance_web, risk_heatmap, client_influence, catalyst_metri… Get all 7 governance graph views for the tenant. Views: org_snapshot, execution_flow, ownership_map, compliance_web, risk_heatmap, client_influence, catalyst_metrics. Read-only, derived from flow_cycle on demand. Requires governance_dashboard entitlement.
catalyst_get_org_summary
read-only
extra_querytime_window
Get an AI-generated narrative summary of the org's execution state. time_window: 'last_7_days' or 'last_30_days'. extra_query: optional focus bias (e.g. 'complianc… Get an AI-generated narrative summary of the org's execution state. time_window: 'last_7_days' or 'last_30_days'. extra_query: optional focus bias (e.g. 'compliance', 'delivery risk'). Returns a MASC-L3 compliant narrative — no individual evaluations. Requires governance_dashboard entitlement.
catalyst_get_workflow_trust
read-only
window_daysworkflow_id*
Get the four-component trust score for a registered AI workflow. Score = 0.25×ai_declared + 0.25×risk_eval + 0.25×override + 0.25×(1−failure). Range 0.0–1.0. windo… Get the four-component trust score for a registered AI workflow. Score = 0.25×ai_declared + 0.25×risk_eval + 0.25×override + 0.25×(1−failure). Range 0.0–1.0. window_days controls the lookback period (1–365).
catalyst_ingest_task
items*domain
Ingest one or more tasks into Catalyst governance pipeline. Items should include at minimum a 'title'. Optional fields: details, owner, priority (Low/Medium/High/C… Ingest one or more tasks into Catalyst governance pipeline. Items should include at minimum a 'title'. Optional fields: details, owner, priority (Low/Medium/High/Critical), stage, domain, due_at, tags, group_id. Returns ingested count and proposal IDs created.
catalyst_list_compliance_frameworks
read-only
List all available pre-built compliance framework packs. Returns each pack (GDPR, SOC 2, ISO 27001, HIPAA, PCI-DSS, EU AI Act, Bribery Act, AML/KYC) with its name,… List all available pre-built compliance framework packs. Returns each pack (GDPR, SOC 2, ISO 27001, HIPAA, PCI-DSS, EU AI Act, Bribery Act, AML/KYC) with its name, description, rule count, and whether it is currently active for this organisation. Activate a pack with catalyst_activate_compliance_framework.
catalyst_list_compliance_rules
read-only
List all compliance rules currently in effect for the organisation. Returns rules from three sources combined and deduplicated: - Rules extracted from uploaded pol… List all compliance rules currently in effect for the organisation. Returns rules from three sources combined and deduplicated: - Rules extracted from uploaded policy documents - Custom org-level rules (PATCH /compliance/rules) - Rules from any activated framework packs Each rule includes: id, type (DENY/REQUIRE/ADVISE), trigger sentence, severity, scope, remediation guidance, confidence score, and authority citation.
catalyst_list_proposals
read-only
List all pending governance proposals awaiting acceptance or decline. Proposals are work items that have been ingested but not yet committed to the live flow cycle… List all pending governance proposals awaiting acceptance or decline. Proposals are work items that have been ingested but not yet committed to the live flow cycle. They require human (or agent) review. Each proposal contains an `idempotency_key` field — this is the canonical proposal identifier. Always use `idempotency_key` (not `task_id` or `id`) when passing proposal IDs to catalyst_accept_proposals, catalyst_decline_proposals, or catalyst_review_proposal.
catalyst_log_task
title*domaindetailspriority
Log a task or action into the Catalyst governance pipeline. Records work, decisions, and actions for audit and governance. priority: Low | Medium | High | Critical… Log a task or action into the Catalyst governance pipeline. Records work, decisions, and actions for audit and governance. priority: Low | Medium | High | Critical. domain: security | product | operations | compliance | finance | legal | other. Returns ingested count and any proposal_ids created (if a governance hold applies).
catalyst_my_governance
read-only
Show your governance profile, actor registration, and plan capabilities. Returns governance_mode (observe/advisory/proposal/strict), risk_class, declared capabilit… Show your governance profile, actor registration, and plan capabilities. Returns governance_mode (observe/advisory/proposal/strict), risk_class, declared capabilities, and actor_id. Auto-registers you in observe mode on first connection — the lightest governance touch. Also returns plan_capabilities showing which features are active and which require an upgrade — relay any upgrade_required fields to the user so they can unlock compliance scanning or AI workflow governance. Call this first to understand what you are and are not permitted to do.
catalyst_pending_approvals
read-only
List proposals currently awaiting governance approval. Shows proposals with status pending or in review. Use this to check whether an action you submitted is still… List proposals currently awaiting governance approval. Shows proposals with status pending or in review. Use this to check whether an action you submitted is still waiting for human sign-off before you proceed. Returns count and full proposal objects with IDs for catalyst_await_approval.
catalyst_register_approval_webhook
callback_url*
Register a callback URL to receive proposal approval notifications. Subscribes callback_url to proposal.accepted and proposal.declined events. When a human approve… Register a callback URL to receive proposal approval notifications. Subscribes callback_url to proposal.accepted and proposal.declined events. When a human approves or declines any proposal, Catalyst POSTs the event to your URL with the resolved proposal IDs in data.ids. Use this instead of polling catalyst_await_approval for autonomous workflows: register once, let your orchestrator (Temporal, job queue, webhook relay) wake the agent when the relevant proposal_id arrives. Then call catalyst_await_approval once to confirm and proceed. Returns subscription IDs, the expected payload shape, and usage guidance. Returns upgrade_required: true if outbound webhooks are not on your plan.
catalyst_register_machine_actor
notesscopesrisk_classcapabilitiesdisplay_name*runtime_type*
+1
Register a machine actor (agent, automation) with Catalyst governance. runtime_type: zapier_zap | n8n_workflow | openai_assistant | make_scenario | c… Register a machine actor (agent, automation) with Catalyst governance. runtime_type: zapier_zap | n8n_workflow | openai_assistant | make_scenario | claude_agent | custom_agent | internal_worker. governance_mode: observe | advisory | proposal | strict. risk_class: low | standard | high. Requires can_configure_ai_workflows entitlement (Enterprise+).
catalyst_register_workflow
modenotesrisk_levelworkflow_id*ai_standards
Register an AI workflow for EU AI Act compliance governance. risk_level: unacceptable (rejected) | high | limited | minimal. mode: observe | advisory | proposal. H… Register an AI workflow for EU AI Act compliance governance. risk_level: unacceptable (rejected) | high | limited | minimal. mode: observe | advisory | proposal. High-risk workflows are forced to proposal. Sets ai_standards=True to opt into the Built to AI Standards evidence trail. Requires can_configure_ai_workflows (Enterprise+).
catalyst_review_proposal
reasondecision*proposal_id*reviewer_id
Approve or reject a review-required proposal (AI governance hold). proposal_id: the `idempotency_key` field from catalyst_list_proposals. Do not pass `task_id` or… Approve or reject a review-required proposal (AI governance hold). proposal_id: the `idempotency_key` field from catalyst_list_proposals. Do not pass `task_id` or `id` — the backend looks up by `idempotency_key`. decision must be 'approve' or 'reject'. Approved proposals can then be accepted via catalyst_accept_proposals. Rejected proposals are marked review-rejected in the ledger.
catalyst_run_compliance_scan
Run a compliance scan against all loaded compliance documents. Detects compliance gaps, conflicts, and policy violations across the current flow cycle. Requires ca… Run a compliance scan against all loaded compliance documents. Detects compliance gaps, conflicts, and policy violations across the current flow cycle. Requires can_scan entitlement. Returns findings grouped by severity.
catalyst_search_tasks
read-only
qlimitdomainoffsetpriority
Search normalised tasks in the tenant flow cycle. Performs case-insensitive substring match on title/details. Filter by canonical domain (e.g. security, product, o… Search normalised tasks in the tenant flow cycle. Performs case-insensitive substring match on title/details. Filter by canonical domain (e.g. security, product, operations) or priority.
catalyst_send_lite_event
payloadevent_type*request_idworkflow_id*
Send a lifecycle event for a registered AI workflow. event_type examples: run.started, action.executed, approval.requested, run.completed, run.failed. Idempotent v… Send a lifecycle event for a registered AI workflow. event_type examples: run.started, action.executed, approval.requested, run.completed, run.failed. Idempotent via request_id (UUID recommended). Payload is scrubbed of credentials before storage.
catalyst_update_task
patch*task_id*
Update a single task in the governance flow. Ledger-recorded. Patch may include: title, details, owner, priority, stage, domain, due_at, status, tags, done. Normal… Update a single task in the governance flow. Ledger-recorded. Patch may include: title, details, owner, priority, stage, domain, due_at, status, tags, done. Normalisation is applied automatically.
catalyst_weekly_summary
read-only