Salus
Agents · MCP-native

Any agent. One governed lane.

Your teams already build with agents. Salus is the platform those agents ship to: every operation is an MCP tool an agent can call — deploy, roll back, read logs, provision a database — under the same RBAC, budgets, and audit trail as a human.

Claude CodeCursorCodexCopilotWindsurfYour own agents

Any MCP-capable agent can target Salus.

agent@governed-lanezsh
How it works

Connect. Scope. Ship.

Three steps from an agent on a laptop to governed deploys in your cloud.

01

Connect

Point your agent at the Salus MCP server. Every operation on the platform — discover, provision, configure, deploy, operate — is a tool it can call. No glue code, no bespoke integration.

02

Scope

The agent works with the access of the builder who invoked it — never more. Whatever that person cannot reach, the agent cannot reach, on every call, without anyone configuring a second set of rules.

03

Ship

The agent builds, deploys, watches the pipeline, reads the logs, and rolls back if it has to — through the same pipeline, gates and scans as a human deploy. Not a sandbox, not a preview: the real thing.

The tools

The whole platform, exposed as MCP tools.

Not a read-only API key bolted on after the fact — the operations themselves, callable by any agent, governed on every call.

Discover

List projects, environments, and services — the agent sees exactly what its role allows, nothing else.

Provision

Create databases, set environment variables, wire up config — with the same permissions its builder holds.

Deploy

Ship from a repo to a running, monitored URL, in the cloud and region you chose for that environment. The same build, scan and deploy stages run whether a person or an agent started it.

Operate

Poll pipelines, stream logs, read metrics and costs, roll back a bad release, take a deployment offline. The full loop.

Why IT says yes

Governance that covers the actor, not just the artifact.

Most platforms give agents a read-only key — or no governed way in at all. Salus gives agents a role: permission to ship, boundaries they can't cross, and a record of everything they did.

Never more than its builder

An agent authenticates as the person who invoked it, so it inherits their roles exactly — it cannot reach a project, space or environment they could not reach themselves.

Isolated workloads

Every app an agent ships runs in its own isolated infrastructure with its own credentials, so a mistake stays inside the app it was made in.

One trail, append-only

Agent and human activity land in the same append-only store — written once, never edited or deleted, isolated per tenant. Giving the agent its own identity in that trail, distinct from its human, is work in progress and we will say so plainly.

An off switch

Any deployment can be taken offline on demand — console, CLI or tool call — and any release rolled back. Autonomy with an off switch is autonomy IT can approve.

Give your agents somewhere governed to ship.

Connect an agent, scope its role, and watch it deploy real apps to your cloud — fast, and inside the rules.