HR · MCP connections through the gateway

An AI package for the whole HR team

Your recruitment system, your HR system and your policy documents are connected once in the gateway. After that HR asks in its own words, and you have an answer on the AI Act before anyone asks the question.

Your toolsThe Walma gatewayThe modelsYour own agents
121MCP servers we have surveyed
68official, straight from the vendor
14ready to connect for HR
1login for the team
Why Walma

Why go through Walma instead of straight to the model?

One account is fine for one person. The difference shows up when a whole team uses AI, and when somebody asks what it cost or where the data went.

Everyone on their own

Everyone signs up separately. Nobody knows what it costs, who has access, or what has been shared.

With Walma

One way in to every model. One login, one invoice, and you can see what is actually happening.

01 · Freedom

Do not marry one model

Claude today, something else next year. With Walma you use all of them and switch when it suits you, without redoing the work.

  • The same connections whichever model you run
  • Switch model without rebuilding anything
  • Run two models on the same task and compare
02 · Ready

The connections are already built

We have done the groundwork: ready-made connections to the tools you already use, with proven skills and instructions, so the team actually gets going instead of just trying it out.

  • Ready connections to the tools you already use
  • Skills and instructions other teams already run in earnest
  • Nothing for the team to install
03 · Control

You see exactly what the AI does

If you want visibility, you get it: everything the agent does is visible, you get feedback on how the work could be better, and you can put a stop to things it should not do.

  • Every call logged, with person, tool and timestamp
  • Feedback on how the team could use it better
  • Guardrails for what the agent must not touch
How the AI Hub works

Three steps, and then it is running

Walma AI Hub is a layer between your tools and the models. Here is what that means in practice.

01Step 1

Connections are approved once, centrally

IT approves an MCP server once. After that the tool appears for the people who should have it, with the right permissions. Nobody on the team touches an API key.

  • One allowlist instead of config files on every laptop
  • Read or write permissions per role, set in the gateway
  • Revoke access in one place when someone leaves
  • Teamtailorofficial
  • HiBobbeta
02Step 2

Every model behind the same key

Claude, GPT, Gemini and the open models all reach the same connections. You pick the model per task instead of locking yourself in, and if you switch next year the tools come along.

  • One login for the user, whichever model runs
  • Budgets and spend caps per team, not per person
  • One log for model calls and tool calls alike
03Step 3

Your own agents on top, built by us

When the off-the-shelf tools run out, we build. RAG over your own material, bespoke agent flows, and narrow MCP servers for systems the vendor has not covered, all running inside the same gateway and the same log.

  • RAG over your documents, contracts and product data
  • Agent flows that follow your process, not a template
  • Custom MCP servers for systems the vendor has not covered
Your material
Documents and contracts
Product and customer data
Internal systems
The agent we build
Walma agentRAG · tools · your process
Answers in Claude, Teams or Slack, where people already work
Connections

What HR gets to connect

HR systems are where the MCP landscape moves fastest. We write down which ones have an official server and which ones we build the connection to.

Ready to connect

The vendor's own server. Switched on and running the same day.

  • Teamtailorofficial
  • HiBobbeta

Needs review first

Community-built. We review the tool descriptions and pin the version before approving.

  • BambooHRcommunity
  • Personiocommunity

In progress: we build the connection

These we build ourselves, as narrow read-only servers in your tenant. Tell us which you need first.

  • Workdayin progress
  • Deelin progress

Base tools, whatever the department

Included in every rollout.

  • Google Workspaceofficial
  • Microsoft 365beta
  • Slackofficial
  • Notionofficial
  • Atlassianofficial
  • Linearofficial
  • Asanaofficial
  • Boxofficial
  • Dropboxofficial
  • Zapierofficial
  • Makeofficial
  • n8nofficial
In practice

What you actually ask it

Questions HR already asks, minus the spreadsheet export first.

  • → Summarise the last twelve applications for the role and what they have in common.
  • → Who in the organisation has the most unused holiday left before year end?
  • → What does our travel policy say about conferences abroad, and when was it updated?
  • → Draft an ad for the role, in the same tone as our last three.
  • → Which managers have not submitted their performance reviews this period?
  • → Pull the figures for the pay equity review from the HR system.
How it fits together

It all runs in the EU, with a log

The gateway runs in your own Azure tenant in an EU region. Every call is logged with user, tool and arguments. That is the answer when your data protection officer asks where the data goes.

Security

Built for European requirements from day one. Details, subprocessors and policies live in our Trust Center.

Open the Trust Center
  • GDPR
  • EU data residency
  • Encrypted at rest & in transit
  • No training on your data
  • Tenant isolation
  • SSO & SCIM
  • SOC 2 Type IIin progress
  • ISO 27001in progress
  • Custom user roles
FAQ

What HR directors ask first

Does using AI in HR make us high-risk under the AI Act?+

It depends entirely on what the AI does. Annex III names AI that ranks candidates, influences promotion or dismissal, or monitors employees as high-risk. HR staff using AI as a working tool, to summarise, draft or search policy documents, is not high-risk. We help you keep the two apart, and our walkthrough of Annex III covers where it is easy to get the classification wrong.

Can the AI see personal data about our employees?+

Only what you open up, and only for the people who should see it. Permissions are set per role in the gateway and follow what the HR system already allows. HiBob's server also works through service accounts rather than personal logins, which narrows the reach further.

Which HR systems can be connected today?+

Teamtailor has an official server, enabled by your Company Admin. HiBob has one in beta for employee data, absence and tasks. BambooHR and Personio have community-built servers that we review before approving. For Workday and Deel we build our own connection inside your tenant.

What if our HR system is not on the list?+

Then we build one. Usually a narrow, read-only server covering just the fields you need, running in your own tenant, so the AI can answer questions without the whole employee register being exposed.

Can we see what the AI has done with employee data?+

Yes. Every call is logged with person, tool, arguments and timestamp, and the log can be exported. It is the same record you need the day someone requests their data or an audit comes around.

Connections

See it on your own systems

Twenty minutes with an engineer. We go through your HR systems, what can be connected today, and where the line runs against the AI Act.