Mindset AI

Docs / Start here

Overview

We turn the skills, MCP servers and ideas your team has already built into reliable agents your company owns.

Right now that work sits on laptops. Somebody in finance wrote a skill that reconciles invoices. Somebody in operations has an MCP server wired to the ticketing system. Somebody runs a prompt every Monday that everyone now depends on.

Each one helps. Together they are a problem.

  • It is not centralised. It lives with whoever built it.
  • Only one person can fix it, or you pull an engineer off real work.
  • You cannot prove what it did, or what it cost.

Mindset runs that same work somewhere the company owns. One place to build agents, one place to see what they did, one set of connections they are allowed to touch, and no dependency on a single model vendor.

What this guide is. What Mindset sees working across the companies it runs in: how they decide which automations to govern, what policy they write, how they bring them in without stopping anyone building, and what running that looks like week to week. Where Mindset does a part of it for you, the guide says which part.

Eight sections, about twelve minutes for this page. The articles in the sidebar go deeper. Read them when you need them, not now.

Section 01 — Where we fit

Four jobs have to be done before an agent can safely touch a real system. You already own three of them.

The four layers of agent governance
SurfaceWhere people work. The assistants you already licence.You already own thisExecutionWhat a sanctioned agent may do. Named operations, its own identity, recorded, tested.MindsetDiscoveryWhat exists that nobody sanctioned. Tenant admin tooling, data loss prevention, threat detection.You already own thisAccessWho may use which model. Identity provider, licensing, vendor admin consoles.You already own this
You already own three of these four layers. The fourth is what this guide is about.

Access. Who may use which model. Your identity provider, and the admin consoles for Claude Enterprise, ChatGPT Enterprise and Microsoft Copilot.

Discovery. What exists that nobody sanctioned. Your tenant admin tooling, your data loss prevention, your threat detection platform.

Execution. What a sanctioned agent may do once it exists. This is Mindset, and it is the only one of the four standing in the way at the moment something gets written.

Surface. Where people work. Agents reach people through the Mindset Hub, a browser app for colleagues, through your own product as an embedded element, or back inside Claude over MCP. Nobody changes tool.

Discovery and execution do different jobs. Your tenant admin tooling tells you an agent exists. Mindset is the record of what was allowed. An agent that tooling finds, and that Mindset has no record of, reached its system by some other route.

Section 02 — The gaps that sit across a mixed stack

Most companies now run more than one. Copilot for the Microsoft estate, Claude and ChatGPT alongside it, each with its own admin console and its own idea of what a control is. Each product governs its own patch well. None of them governs the others, and five things fall between them.

What each product gives an agent, and what Mindset adds
What your teams have todayMicrosoft Copilot StudioClaude EnterpriseChatGPT EnterpriseMindsetSomewhere to build that isnot livePower Platform environmentsNothing equivalentNothing equivalentMindset environments, withtheir own connectionsAn identity of its ownAgent identities in EntraRuns as the person who ranitRuns as the person who ranitOne service identity peragentLimiting what an agent maydoConnector policy peraction, per Power Platformenvironment. An MCP serveris allowed whole or not atallConnectors allowed or not,for the whole ClaudeorganisationConnectors and skillsallowed or not, for thewhole ChatGPT workspaceOne named operation at atime. Not the system, thesingle callA record of each actionTenant admin and Purview,at prompt and file levelAdmin console and export,at conversation levelCompliance API, atconversation levelEvery operation, againstthe run it belonged toA person before a writeOnly if whoever built theagent added oneNoNoAlways, unless your Mindsetorganisation turns it off
The last column is what Mindset adds on top of whatever each product already does.
  • Nowhere to build that is not live. Copilot Studio has Power Platform environments. Claude and ChatGPT have one organisation or one workspace, so there is no non-production place for anyone to work.
  • No identity for the agent. In Claude and ChatGPT an agent acts as the person who ran it, so every log attributes its actions to that person. Copilot Studio can issue an Entra identity.
  • Limits are all or nothing. A connector is on for everyone or nobody. Copilot Studio can go down to individual actions, but an MCP server is still on or off as a whole. Nowhere can you say this agent may look up a purchase order and may not raise one.
  • The record is at the wrong level. All three record conversations. An investigation needs actions: which agent, which operation, on which system, with what result, in which run.
  • Nothing waits for a person. If an agent can call a tool that changes something, the change happens. Approval exists only if whoever built that agent added it.

Mindset answers all five the same way in every product, so the answer does not change depending on where a team happened to build.

Section 03 — Deciding what to govern

The policy question underneath agent, MCP and skill sprawl. Which of the things your people built are worth governing, and which to leave alone.

Deciding what belongs in Mindset
For each automation your people have already built, ask:1Does the automation change anything?Reads are recoverable. Writes are not.2Can that change be undone?Updating a status and issuing a payment are both writes.3Does anyone but the builder rely on the output?The second person turns it into infrastructure.4Does it run under a person's credentials?This is the one that removes your ability to investigate.5Does it run when nobody is watching?A scheduled agent has nobody to notice it going wrong.6Does it touch data you would have to report on?Personal or regulated data, or anything with a notification duty.Any single yesThe automation belongs in Mindset. Reads run.Writes wait for a person.Six times noSomebody's personal tool. Leave it alone. Donot register it, review it or ask anyone todeclare it.
Any single yes and the automation belongs in Mindset.

Six times no and it is a personal tool. Do not register it, review it or ask anyone to declare it. A policy that governs the agent tidying somebody's meeting notes will not be taken seriously on the agent touching bank details.

A Cloud Security Alliance survey of 228 security and IT professionals in early 2026 found 31 per cent of organisations let agents run under human user credentials, and only 36 per cent assign a dedicated identity per agent.

Section 04 — How this fits the way your teams already build

Nobody moves tool. People keep building where they build today, and the working result comes into Mindset. The word that causes most confusion here is environment, because it means something different in each product.

Is there somewhere to build that is not live?
Microsoft Copilot StudioYesPower Platform environmentsYou probably already have several.Claude EnterpriseNoOne Claude organisationSkills and connectors are on foreveryone or nobody.ChatGPT EnterpriseNoOne ChatGPT workspaceSame shape as Claude.MindsetYesMindset environmentsNormally Test and Production, eachwith its own connections.
For the two that answer no, a Mindset Test environment is the first non-production place those teams have had.

Where Claude Enterprise and ChatGPT Enterprise have nothing equivalent to a test environment, Mindset environments fill that gap. Copilot Studio already has Power Platform environments, which are a separate object with different rules and no relationship to Mindset environments.

How the work moves through Mindset environments
Where people build todayClaude EnterpriseA skill file, or an MCP server on a laptopMicrosoft Copilot StudioAn agent built inside one of your environmentsChatGPT EnterpriseA custom GPT, a skill, or an actionMindset Test environmentMindset connections pointed at your non-production systems. The agent cannot read a real invoice even if its instructions tell it to. Not a Power Platformenvironment, and unrelated to one.You make the same change again. Nothing crosses on its own.Mindset Production environmentThe same agent, pointed at the real systems. Writes wait for a named person in the function that owns the outcome.Where people use the agentThe Mindset HubColleagues, in a browserYour own productAn embedded elementBack in ClaudeOver MCP, where they already work
Build where you build today. The working result comes into a Mindset Test environment, then into Mindset Production once it holds up.

Mindset gives you environments. Named partitions inside your Mindset organisation, normally Test and Production, each with its own connections pointed at its own systems. An agent built in Test cannot reach a real system, because the credentials for the real system are not in that environment.

  • Nothing is copied for you. Promoting means making the same change again in Production once it holds up in Test.
  • You cannot invite somebody into Test only. Membership of a Mindset organisation gives a person every environment in it.

Section 05 — How something gets added

Four steps to bring an automation in, done once. After that the agent runs, and every run is recorded.

From an existing automation to a running agent
Once, per automation1Bring it inA Claude or ChatGPT skill, or anMCP server, pasted into Mindset.It proposes a plan and waits foryou to approve it.2Connect the systemCredentials held by Mindset.Operations discovered from thesystem, then enabled one at atime.3Script and testStages in order, each withsomething it must achieve. Everytest criterion has to pass to golive.4PublishTo colleagues in the Mindset Hub,into your own product, or backinto Claude over MCP.Every time it runsA run startsA person, a schedule, your ownsoftware, another Mindset agent, orClaude over MCP.It readsThe operation runs. The answercomes back straight away.It writesNothing happens yet. A person opensa link and approves it.It is recordedWhat started it, every operation itcalled, what came back, how itended.An agent can never approve a write. Not its own, and not another agent's.
The top row happens once per automation. The bottom row happens every time the agent runs.
Term What it means in Mindset
Connection A link to one outside system, holding its login details. Those details never reach the agent or the model.
Operation One named thing an agent may do on a connection. Not the finance system, but get the purchase order matching this invoice number.
Run One execution, recorded from whatever started it to however it ended.

A Claude skill becomes a Mindset agent. An MCP server becomes a Mindset connection, with each of its tools as a named Mindset operation.

Section 06 — The rules we enforce

Ten rules. Mindset makes seven of them true on its own, whether or not anybody has read the policy. Three are conventions your team has to hold, and those are the three worth writing down.

The ten rules, and who enforces each
Mindset enforces theseSeven rules that hold whether or not anyone reads the policyEverything reaching an outside system goes through a named operationCredentials sit with Mindset and never reach the agent or the modelA write waits for a person, unless your Mindset organisation deliberately turns that offAn agent can never approve a write, its own or another agent'sEvery action is recorded against the run it belonged toWhat you build in one Mindset environment cannot see anotherNothing goes live until every test criterion passesYou enforce theseThree conventions. These are the ones to write downEach agent has a named owner and a backupPersonal tools stay personal and are not registeredAgents nobody uses get archived
A rule Mindset enforces needs no policing. A convention does.

The rule to decide deliberately is rule three. Every Mindset operation is marked read or write.

  • A read fetches information. The agent calls it and the call happens.
  • A write changes something. The agent calls it and nothing happens yet. It records exactly what it wants to send, the run carries on and finishes, and the change waits behind a link a person opens.

Write approval is on by default. It can be turned off, but only for the whole Mindset organisation, never per agent and never per operation. When that setting stands in for a person, the record names the setting rather than inventing an approver. Leave it on for the first month.

Section 07 — Getting started

Two phases. Find what your people already built, then get one thing live with us alongside.

Finding them. Three routes, and most companies need all three.

  • Ask your AI leads and power users. They tend to have a list already.
  • Run one session per function. The question is not what could be automated, but what somebody has already automated and is quietly relying on.
  • Read what your tenant admin tooling and data loss prevention already found. Most is noise. The entries touching a real system are the ones you want.

Qualifying them. Three questions per item, twenty minutes for the whole list.

  1. Can it reach what it needs through an API, a database, a spreadsheet or an MCP server?
  2. Is it acceptable for a person to approve the changes it makes?
  3. Can you describe the work as stages, each with something it must have achieved?

Three yeses and it moves as it is. Start with the biggest, because you already know how it should behave.

The first sprint runs about three weeks with us, then a month of watching.

Section 08 — Running it week to week

Most of the watching is done for you. Mindset holds every write until a person approves it, blocks any version that fails a single test criterion, marks every agent and connection as working, failing, idle or never used, and compares what each agent was granted against what it actually called.

What Mindset holds on its own
Mindset does this on its ownNothing goes live that fails atestEvery agent carries behaviour criteria written when it was built. A new version goes live only if every singleone passes. Not most. Every one.Every resource carries its ownstateWorking, failing, idle or never used. Idle and never used are separate, because an agent that has never run hasa trigger problem and one that stopped has a different problem.Granted is compared with calledWhat each agent was given, against what it actually reached for. Something granted and never called means astage is being skipped. Something called and never granted is worth looking at the same day.Nothing reaches a real systemunaskedA write is held until a person opens the link and approves it. An agent can never approve one.A person does thisTen minutes each morningRead what failed, what is waiting on an approver, and what ran but changed nothing.Thirty minutes each weekRead the new agents and new operations from the week, and the granted against called comparison.One named person, and a backup. That is the whole standing commitment.
What runs without anybody asking, and the two habits a person keeps.

A person does the rest: ten minutes each morning reading what failed, what is waiting on an approver, and what ran but changed nothing; thirty minutes each week reading the new agents and operations, and the granted-against-called comparison. One named person, and a backup — that is the whole standing commitment.

The guide to the record is itself an agent, published to your team over MCP, so the question gets asked from Teams, Copilot, Claude or ChatGPT and answered there — "did the invoice agent run this morning?", "what failed yesterday, and at which step?", "what is waiting on an approver?", "which agents can write to finance?", "what did we spend, and on which agent?" — as a sentence, a number, a table, or over OpenTelemetry into your own tooling.

Name one owner. In the same Cloud Security Alliance survey, responsibility for agent security was split across security, engineering and IT, IAM teams were rarely the primary owner, and some organisations reported no identifiable owner at all. On who is accountable when an agent causes an incident: 28 per cent said security or IT, 25 per cent engineering, 18 per cent the business owner, and 15 per cent did not know.