Built to connect with the stack you already run
LLM providers, identity providers, a REST API, and our own MCP server — Evum plugs into your AI and identity stack instead of asking you to rebuild around it.
Connect once, track everything
Evum doesn't bet your AI program on a single vendor. Connect OpenAI, Anthropic, and Gemini directly, and every dollar spent is automatically tied back to the use case that spent it.
Paste an admin API key from OpenAI, Anthropic, or Gemini — scoped to usage and billing data, revocable any time.
Usage automatically maps back to the AI use cases, initiatives, and systems calling that provider.
Daily usage and spend sync straight into the AI Cost & License Tracker — no manual entry, ever.
Find the shadow AI IT doesn't know about
Connect your identity provider and Evum automatically surfaces every AI tool employees have already granted access to.
- Connect Okta or Microsoft Entra ID as a read-only connector — no agents to install
- Evum syncs every enterprise app and service principal in your tenant, along with the OAuth scopes each one has been granted
- A four-tier cascade classifies AI tools — catalog match, domain match, keyword heuristic, then an LLM fallback for anything left over
- Each discovered app gets a transparent, additive risk score from grant type, grant breadth, scope sensitivity, and publisher verification
- Triage from a single inbox — approve into the Systems Registry, reject, merge duplicates, or undo — every decision is reversible
Bring your own identity provider
Enterprise SSO lets your organization sign in through the identity provider you already run, instead of app-local passwords — available today on the Enterprise plan.
Connect any OIDC-compliant identity provider with an issuer URL, client ID, and secret.
Connect via a metadata URL or pasted XML — works with Okta, Microsoft Entra ID, Google Workspace, and most enterprise IdPs.
Domain-based routing sends each user straight to your organization's login, and just-in-time provisioning creates their Evum account on first sign-in.
Build on Evum
A REST API for programmatic access to your organization's data, and our own MCP server for agents — both authenticated with the same personal token from Profile → API Access, scoped to your org and revocable any time.
The Evum API
Programmatic access to every resource in your organization's workspace.
Evum has its own MCP server
Connect Claude Desktop, Claude Code, or any MCP-compatible client directly to your Evum workspace — around 40 tools mirroring the API, so an agent can read and write your systems, use cases, talent, policies, prompts, and more.
Connecting an MCP client grants it full read/write access to your workspace data — only connect clients you trust.
See your integrations in action
Spin up a workspace, connect your identity provider, and watch your AI estate populate itself.