Employees act through your real business tools — email, CRM, accounting, shops, social. You connect a tool once; you decide which employees may use it.
Connect from the Integrations page — usually by pasting an API key or completing a sign-in. The catalog spans email & calendar, files, CRM & sales, support, team messaging, project & dev, finance & payments, shops & shipping, marketing, analytics, HR, e-signature and automation.
Credentials are stored encrypted and never shown back in full. The tools you named at signup appear pre-starred.

Employees only use connectors you gave them access to — set per employee in its editor, or let the manager grant access on your go-ahead. Custom connectors let you wire in any tool with an HTTP API, so even an app not in the catalog can be added.
On the Security page you can decide per connected tool — separately for reading and writing — whether employees act freely, must ask a human first, or are blocked. «Read Gmail but never send» is one toggle. Anything you leave alone keeps the default: reads run, writes follow the approval rules.
Swiss needs are first-class: Swiss QR-bills are read deterministically (checksum-verified), not guessed at by a model. The Zefix connector looks up the commercial register — company, UID, legal seat — instead of guessing. Pingen turns a PDF into real postal mail, always drafted first; dispatch needs your approval.
Some tools are visible in the catalog but not yet connectable — either the provider requires partner onboarding, or its API terms require a dedicated sign-in integration rather than a pasted key. Those return once the proper flow ships.