Architectural deep dive

Pipelines as Tools

Expose a complete, governed DataZen pipeline as one purpose-built capability that an AI client can discover and invoke through the Model Context Protocol.

Remote MCP JSON-RPC 2.0 Declared inputs Governed outputs
The difference

Give the agent a business capability, not your infrastructure

Generic database and API tools force a model to understand low-level systems and compose many operations correctly. A DataZen pipeline can package connectivity, transformations, validation, policy, and output shaping behind a single tool contract. The pipeline becomes the tool.

Purpose-built contracts

Define a clear tool name, descriptions, sample prompts, timeout, typed inputs, and output fields so AI clients can select and call the capability correctly.

Parameters become inputs

Declared pipeline parameters form the tool's input contract. Values supplied by the AI client are applied to the pipeline execution at invocation time.

Pipeline logic remains authoritative

The model requests an outcome, while DataZen controls credentials, source access, filters, transformations, validations, and the shape of the returned result.

One protocol across deployments

Remote AI clients can invoke exposed tools through MCP over Streamable HTTP, using JSON-RPC 2.0 with both cloud and self-hosted DataZen agents.

Execution model

From pipeline definition to agent tool call

  1. Build the pipeline. Connect to the required systems and implement the business operation, including filtering and output shaping.
  2. Publish its contract. Enable the pipeline as an MCP Tool and describe the inputs, outputs, purpose, and useful sample prompts.
  3. Connect the AI client. Register the DataZen remote MCP endpoint and authenticate with a scoped service token.
  4. Discover and invoke. The client discovers the tool, supplies input values, and receives the pipeline's governed output.

Authentication stays explicit

Remote MCP calls use a service token in the Authorization: Token ... header. The token requires the mcp_all scope. Cloud endpoints include the agent identifier before /api/mcp; self-hosted agents expose /mcp from their configured base URL.

Governance model

Constrain what the model can ask the platform to do

  • Least privilege: issue a dedicated, expiring service token for MCP access instead of sharing administrative credentials.
  • Bounded inputs: expose only the parameters the business operation is designed to accept.
  • Reduced outputs: return the fields required for the agent's task to limit data exposure and token consumption.
  • Observable execution: tool calls run as DataZen pipeline executions, preserving operational status and logs.
  • Stable abstraction: change source systems or internal logic without forcing the AI client to relearn the underlying integration.

Pipelines as Tools turns tested integration logic into a narrow, discoverable interface for agentic workflows.

Back to DataZen