Governed MCP Endpoint

One MCP endpoint.
Your whole
MSP stack.

Bring your own AI. Connect Claude, Cursor or any MCP client to your PSA, RMM, documentation and security tools through one governed endpoint.

Claude to /api/mcp
Works with
ClaudeClaude CodeCursorAny MCP client
Approval loop

Writes never run without a human

When your AI proposes a change, it does not execute. The call becomes a pending action, method, endpoint and payload included, waiting in your dashboard. A teammate with the right role approves or denies it, and the decision joins the audit trail alongside every call that led to it.

Every write held for approvalRBAC re-checked at executionFull audit trail
0
Connected integrations
Zero
Writes without approval
Every
API call logged
Bring your own
AI

Capabilities

One connection.
Full operational control.

One endpoint, every vendor

Connect your PSA, RMM, documentation and security tools once. Every enabled integration is exposed as tools on a single MCP endpoint.

Bring your own AI

Point Claude, Cursor or any MCP client at your endpoint. No new interface to learn and no separate AI subscription to manage.

Approval-gated writes

Every write becomes a pending action with the exact method, endpoint and payload. Nothing changes until a human approves it in the dashboard.

Role-based permissions per integration

Four roles, enforced per integration and re-checked at execution time. Read-only members can query freely; only permitted roles can propose writes.

Credentials never leave the vault

API keys are encrypted per workspace with a two-layer KMS hierarchy. Your AI provider sees tool results, never a credential.

Every call metered and audited

Every tool call is logged with the calling client, workspace and result, then rolled up for usage review and billing.

Integrations

Connect everything.
Query anything.

13 native integrations for PSA, RMM, security, documentation, networking, and BDR - ready in minutes.

Running something not on the list? Drop in an OpenAPI spec and LayerOps generates the tools automatically. No custom code required.

Explore all integrations
CWConnectWisePSA
NJNinjaOneRMM
HTHuntressSecurity
HAHalo PSAPSA
ATAutotaskPSA
AVAuvikNetwork
DFDNSFilterSecurity
DADatto RMMRMM
SYSyncroPSA + RMM
AXAxcientBDR
IGIT GlueDocumentation
HUHuduDocumentation
P8Pax8Distribution
+Your API

Security

Built to protect
your clients' data.

See our full security architecture

3-Layer Encryption

Managed KMS root keys, per-org key wrapping, AES-256-GCM per credential. Three layers between your secrets and the outside world.

Approval Workflows

Every write action requires explicit approval. RBAC re-validated at execution time. Mass operations blocked by guardrails.

Zero-Trust Isolation

Workspace-scoped data. Credentials never reach your AI provider. Server-side action storage. Nothing leaks between tenants.

How it works

Three steps to clarity.

01

Connect your tools

Add your PSA, RMM, documentation and security tools once. Credentials are encrypted and stored in your workspace vault.

02

Add the endpoint

Point Claude, Cursor or any MCP client at your LayerOps endpoint with an API key. No new interface to learn.

03

Ask, act, approve

Query freely. Every write becomes a pending approval you confirm before anything changes.

Ready to connect
your stack?

Add your integrations, mint an API key, and point Claude, Cursor or any MCP client at the endpoint. Every write stays behind your approval.

Start free