5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Reference · BarzelOps · 2 September 2026

Agents that touch your CRM, your books and your inbox

BarzelOps executes real operational work across five systems, with a human gate on the steps that deserve one and a durable record of every step that ran. Transport and connection are on the docs home.

40Tools at top tier
26On Pro
10On Free
5Connectors

Connectors

Five systems, reached through one action tool each

Each connector fronts a single consolidated action tool rather than a dozen narrow ones, which keeps the surface small enough for a model to reason about. Enumerate after connecting — tools/list before and after an authorisation returns different answers, deliberately, because a tool you cannot use should not be visible for a model to try.

  • HubSpotDeals, contacts, pipeline — the RevOps side.
  • XeroInvoicing and the books. Where order-to-cash lands.
  • GmailOutbound that reaches a customer. Gated by default.
  • Google DriveDocuments in and out, including intake.
  • SlackWhere the approval request actually reaches a human.

Tool surface

40 tools at the top tier, and your plan decides how many you see

Free exposes 10, Pro 26, Team and Enterprise the complete 40. Tools you are not entitled to are absent from tools/list rather than present and failing — so an agent on the free tier never wastes a turn attempting something it cannot do.

Discovery & health · 8
  • list_capabilities
  • search_capabilities
  • describe_capability
  • get_supported_providers
  • get_required_credentials
  • validate_credentials
  • get_server_health
  • test_connector_health
Connector actions · 8
  • crm_action
  • accounting_action
  • email_action
  • document_action
  • storage_action
  • slack_action
  • calendar_action
  • reporting_action
Workflow engine · 9
  • plan_business_workflow
  • preview_business_workflow
  • run_business_workflow
  • get_workflow_status
  • get_workflow_trace
  • resume_workflow
  • cancel_workflow
  • list_workflow_templates
  • save_workflow_template
Prebuilt plays · 7
  • lead_to_invoice
  • invoice_follow_up
  • customer_onboarding
  • monthly_close_prep
  • sales_pipeline_cleanup
  • weekly_ops_briefing
  • customer_account_summary
Approvals · 5
  • request_approval
  • approve_action
  • reject_action
  • list_pending_approvals
  • set_approval_policy
Audit · 3
  • get_action_history
  • export_audit_log
  • generate_compliance_report

Worked example

Closed-won deal to sent invoice, with a gate in the middle

Five calls, and the third is the one that matters. Tool names are exact; argument names are illustrative — read the real schema from tools/list.

  1. get_required_credentials → validate_credentials Ask what this workflow needs, then confirm what you granted actually works. Two calls that cost nothing and save an afternoon of debugging a half-authorised connector.
  2. preview_business_workflow See every step the run would take before any of them happen — which records it touches, which email it would send, where it stops for a human. Read this once per new workflow, always.
  3. set_approval_policy Decide the gate before the first run, not after the first mistake. Invoices above a threshold and anything leaving via email_action are the two most people choose.
  4. lead_to_invoice The prebuilt play: read the closed-won deal from HubSpot, raise the invoice in Xero, draft the email. It pauses at your gate and posts the approval request to Slack.
  5. list_pending_approvals → approve_action → resume_workflow A human approves, the run continues from where it paused. If something went wrong instead, get_workflow_trace tells you which step and why — and cancel_workflow stops it cleanly rather than mid-invoice.

All five of these are inside the Free tier’s 10 tools except set_approval_policy and the prebuilt plays. Check tools/list against your plan before you write the client.

Credential model

Your tokens, your tenant, never pooled

BarzelOps runs on customer-owned OAuth tokens supplied per tenant. There is no shared Barzel service account behind your Xero or your Gmail, which means the blast radius of a problem on our side is your tenant, and revoking us is something you do in your own provider without asking us first.

You grant Standard OAuth consent in each system, scoped to what the workflows you want actually need. Narrow it and the corresponding tools simply do not appear.
We hold as config Tokens are server-side configuration, never placed in a prompt, a tool description or an audit record. Audit entries reference them by identifier and scope.
You revoke Withdraw consent in the source system and it takes effect on the next call. No cached grant outlives your revocation, and you do not need our cooperation.

Approvals and audit

Which steps stop for a human, and what survives afterwards

The useful question is not whether to have a human in the loop but where. Anything irreversible, anything that reaches a customer, and anything above a value threshold you set. Everything else runs and is recorded.

Gate by default Anything a customer will see, anything that cannot be undone, and anything that moves money. A wrong email cannot be recalled, so it is worth a Slack message first.
Let run Reads, internal drafts, reversible updates and anything under your threshold. Gate everything and people route around the gate, which is worse than not having one.
Durable record Every governed action records what was requested, what ran, who approved it and what came back. Retention is configurable and exportable; twelve months by default.

Where the thresholds should sit: Designing Approval Thresholds for AI Agents and Autonomous vs Human-in-the-Loop Operations.

Next

Free tier is 100 calls a day — enough to wire one workflow end to end and watch the approval land in Slack.

Common questions

Questions developers ask first

How many tools does BarzelOps expose?

40 at the top tier. Your plan decides how many you see: Free exposes 10, Pro 26, and Team or Enterprise the complete 40. Tools you are not entitled to are absent from tools/list rather than present and failing, so an agent never wastes a turn attempting one.

Which systems does BarzelOps connect to?

Five: HubSpot for pipeline, Xero for invoicing and the books, Gmail for outbound that reaches a customer, Google Drive for documents, and Slack for where the approval request actually reaches a human. Each connector fronts one consolidated action tool rather than a dozen narrow ones, which keeps the surface small enough for a model to reason about.

Who owns the OAuth tokens?

You do. Tokens are customer-owned and supplied per tenant, never pooled across tenants, and there is no shared Barzel service account behind your Xero or your Gmail. Revoke consent in your own provider and it takes effect on the next call — no cached grant outlives your revocation and you do not need our cooperation.

Which steps should require human approval?

Anything irreversible, anything that reaches a customer, and anything above a value threshold you set. Everything else — reads, internal drafts, reversible updates — should run. Gate everything and people route around the gate, which is worse than having none.

Why did a tool disappear from tools/list?

Either your plan does not include it, or the connector it belongs to is not authorised for your tenant. Enumeration reflects entitlement, so calling tools/list before and after an authorisation legitimately returns different answers.