
Connectuary
Integration
With Dust on Forest: your AI agents run the ops. You keep the controls.
Guillaume Rigal
How Dust connects to your Forest back-office via MCP. Connect Dust AI agents to it and they inherit your permissions, approval gates, and full audit trail. Here is how the architecture works in practice.
AI agents are now past the drafting-and-summarizing phase. Your ops teams are asking a harder question: can they take real actions on production data? Approve a refund. Change a customer's risk tier. Freeze an account. Trigger a payout.
The answer is yes. But only if the right layer sits between the agent and your systems.
Agent platforms reason well. They don't enforce your ops rules.
Platforms like Dust are built to reason, route, and synthesize. They do that well. What they were not built to do is enforce your ops permissions, gate writes behind an approval flow, or produce an audit trail your compliance team can defend.
The moment a Dust AI agent needs to act on a real record, it needs a backend that knows your rules. That backend is Forest.
This is what a headless back-office looks like in practice. Dust becomes the interface. Forest is the governed layer underneath: your data, your permissions, your audit trail, your approval gates. Your team does not need to open Forest to act. Your AI agents do the work through it.
How Dust connects to your back-office with the Forest MCP Server
Forest connects to your databases and SaaS tools as datasources, and exposes your operations as an MCP server. Your Dust AI agents connect to it via OAuth. From there, they can list records, read context, and trigger Forest Actions. Of course, everything goes through Forest's permission model.
An AI agent with read-only access cannot write. An AI agent that can trigger a refund action cannot skip the approval gate attached to it. The permissions your team runs on are the same permissions your AI agents run on. Forest ships actionApproval by default, so it is a primitive you configure, not one you build.
How Forest adds human-in-the-loop controls to Dust AI agents
Not every action needs a human to sign off. Your Dust AI agents can run fully autonomously on low-risk, high-volume tasks. The approval gate kicks in when you define a condition.
An amount above a threshold. A PEP flag returned by your KYC provider. A case manually escalated for review. When the condition is met, the action does not execute. Forest creates an actionApproval record: the full payload is frozen, the requester is attributed, and a human in an authorized role reviews and approves or rejects.
Below the threshold, the agent acts. Above it, your team decides. This is how you let AI agents work at scale on production data without giving up oversight on the cases that carry real risk.
At Forest, we run Dust AI agents on our own back-office in production
Forest runs an internal instance of Forest, called Forest of Forest (FoF). Our own team connects AI agents to it via the Forest MCP server. Customer records, billing, support workflows: every operation runs through the same permission and approval layer we ship to customers.
This is not a sandbox. It is a production back-office, governed by Forest, called by an AI agent in real time.
What running Dust AI agents on Forest gives you: RBAC, approvals, and audit trail
When your Dust AI agents connect to Forest's MCP server, they work within a perimeter where Forest already enforces:
Permissions. AI agents act as credentialed users. Role-based access control applies to every read and every write.
Audit trail. Every AI-initiated action carries the same attribution as a human-initiated one: who requested it, what the payload was, who approved it, what the outcome was.
Approval gates. actionApproval is part of Forest's data model. You attach it to any Action, with the conditions and authorized approvers you define.
Data residency. Forest's backend runs in your infrastructure. Your data does not travel to Forest's servers. It travels only to the provider called at the step that needs it.
Forest is the AI agent harness for fintech, payments, and regulated ops
Forest's MCP server works with Dust, Claude, and any agent runtime that speaks MCP.
You bring the agent layer. Forest governs the execution.
The architecture is the same whether you are running KYC reviews, refund queues, dispute workflows, or account management at scale.
Get one of our FDEs to set up Dust and Forest for scale
Forest has a team of Forward Deployed Engineers ready to deploy this with your team. They design your agent architecture, wire up the approval flows, and get you running at production scale on Forest's MCP server.
This is not just for onboarding. It is a high-touch hands-on program with engineers who know the stack.
We are looking for teams with serious volume: high-frequency ops, multi-agent workflows, large transaction throughput, or regulated environments where the architecture has to be right.
If you are building agentic operations at that scale, talk to us now.
