Connected apps feeding into a team of OpenFactory agents that act on your behalf

Connected-App Agents: Catalog, Scope, and Data Boundaries

Review the currently configured app catalog, managed OAuth and token boundary, account assignment, approval controls, and planned integration patterns.

By the OpenFactory Team · June 16, 2026

← Back to Blog

Production currently exposes managed connections for Gmail, GitHub, Vercel, Facebook, Instagram, LinkedIn, Reddit, and YouTube. A connected account gives an agent tools; it does not remove provider scopes, data processors, approval duties, or the need to verify writes upstream.

Most AI assistants stop at the edge of the conversation. They can tell you what they would write, what issue they would file, or what message they would send - and then hand it back to you to actually do. The gap between “here is a draft” and “it is done” is where the value leaks out.

OpenFactory can close part of that gap with provider tools. In the current catalog, Gmail and GitHub support useful draft and repository workflows; Vercel and the configured social/video providers expose provider-specific actions. The exact tool, scope, and displayed actor must be checked at connection time and again in provider history.

Connect once, then your agents act

The operating model has several explicit boundaries. You start a managed connection from the OpenFactory console and authorize a provider account. Composio Cloud currently performs the OAuth flow and stores the provider token; OpenFactory stores an encrypted account reference. You then assign the exact connection to an agent role and define which writes need approval. Never copy credentials into a prompt.

Connect an app once; your agents act in it under your accountYouyour account & keysauthorize + reviewYour agentsact on your behalfGmailGitHubVercelSocialVideowrites use the connected provider account; revoke access at the provider
Managed OAuth/token storage, OpenFactory account assignment, provider scopes, and human approval are distinct controls. Verify each write in the upstream provider.

What your agents can do

Vercel plus Facebook, Instagram, LinkedIn, Reddit, and YouTube round out the configured set. The current list and status labels live on the integrations hub.

One agent, many apps

The real payoff shows up when a single agent spans several connected apps. A bounded example uses Gmail to prepare a reply and GitHub to prepare a redacted issue draft. Both actions remain pending review, and the workflow re-reads provider state before reporting success:

You are my sales follow-up agent.

I've connected a least-privileged test Gmail account and a test GitHub account.

When a prospect replies to one of my outreach threads:
- Read the thread, then draft a reply that answers their question and proposes two next-step times. Save it as a Gmail draft for me to approve.
- If they report a product issue, prepare a GitHub issue draft with redacted details and the "from-prospect" label. Do not publish it until I approve the title, repository, and body.
- Report the Gmail draft id and the proposed GitHub repository; do not claim either action succeeded until you re-read it from the provider.

Account ownership does not remove the processor boundary

Agents use the connection and provider scopes you authorize. Assign exact accounts rather than broad toolkit names, start with drafts, and preserve approval for consequential writes. When access ends, disconnect it in OpenFactory and revoke the upstream provider grant; verify both changes rather than assuming one control propagated to the other.

The managed integration path is not fully local today: Composio Cloud conducts OAuth and stores provider tokens. OpenFactory retains encrypted connected-account references. Provider content requested during an action may also reach the configured model path, so review the complete data flow rather than equating a self-hosted control plane with local-only processing.

Get started

Open the OpenFactory console, inspect the live catalog, and connect a least-privileged test account. Assign that exact connection to one role, start with a reversible read or draft workflow, inspect upstream audit history, then test disconnect and provider-side revocation. Browse the integrations hub to distinguish configured apps from planned patterns.

Frequently asked questions

What does it mean to connect an app to an OpenFactory agent?

It authorizes a provider account and exposes account-scoped tools to selected agent roles. Available reads and writes depend on the provider's scopes and current tool catalog. A connection is not blanket approval for every action.

Which apps can I connect?

As of August 12, 2026, production is configured for Gmail, GitHub, Vercel, Facebook, Instagram, LinkedIn, Reddit, and YouTube. Slack, Notion, and Linear pages describe planned workflow patterns and are not current production connection choices. The live console catalog is authoritative.

Whose account do the agents act in?

Actions use the connected provider account, but displayed attribution varies by provider, OAuth app, installation, and action. Verify the actor and event in provider-native audit history.

How do I stay in control?

Assign exact connected accounts to roles, use provider-side least privilege, start with read or draft actions, and keep sending, publishing, deletion, deployment, access, and financial actions behind explicit review. Test both OpenFactory disconnection and upstream revocation.

Where does my data live?

The current managed path uses Composio Cloud for OAuth and provider-token storage; OpenFactory stores encrypted connected-account references. Requested app data can traverse the upstream provider, Composio, OpenFactory, and the configured model path. Self-hosting only the OpenFactory control plane does not make that path local.

Choose the next validation step

Compare published self-service limits, or scope customer-controlled deployment and fleet requirements through a technical pilot.