FlowplaneBook a pilot
Blog
TeamZero trust tunnel, Unified MCP endpoint, Memory, Watchtower

How Gigflow put its support agents, its staging database and its memory behind one gate.

We are nine people. We had a VPN, a shared admin login and three agents with more rights than any of us. Six weeks later we run all four Flowplane products and the log is the first thing I open.

Gigflow is nine people. We build a product, we support it, and we do not have anyone whose job is security. What we had instead was a VPN everyone shared, an admin panel with one login, a staging database that two agents could reach because someone had pasted a connection string into a Cursor config, and a support agent on Claude that had, technically, the rights to delete customers.

None of that was a decision. It was nine people moving fast. When a customer asked us, in a security questionnaire, which AI systems had access to their data, I wrote "none" and then went to check. This post is what happened after I checked.

Before

What we run now

All four. I did not plan to; we started with the tunnel and kept finding the next thing on the same console.

The tunnel. A connector next to the staging database and one next to the admin panel. The VPN is gone. People sign in with Google Workspace, the admin panel checks the group, and our two contractors get exactly the admin panel and nothing else. The train laptop story cannot happen again because there is nothing on a laptop that opens a door.

The unified endpoint. The support agent connects to mcp.flowplane.eu/gigflow as the support person using it. We uploaded our own backend's OpenAPI spec and got tools with names like orders.get and orders.refund. Get is allowed for support. Refund is allowed for two people and needs the agent to be acting as one of them. Delete is not a tool. It was one afternoon, and it was the first time I read our own API spec end to end.

Memory. This is the one I was sceptical about. We made a team vault for support: product quirks, known issues, the way we phrase things. Every support agent reads it, as the person running it, and writes to it only when that person confirms. Then each of us got a personal vault. Cursor on my laptop remembers my conventions and nobody else's. The staging connection string lives in none of them, because it does not need to; the database is a tool now.

Watchtower. We switched it on in week four, mostly out of curiosity. In week five it sent this.

time2026-09-04 16:20:41 UTCprincipalagent:support for tom@gigflow.bepattern612 orders read in 4 minutes usual: about 20 an hoursignalsuspiciousalertedaxel@gigflow.be, Slack #opsmodelFlowplane Watchtower our own models, EU

It was Tom, testing a new prompt that told the agent to "review recent orders" without saying how many. Nothing malicious. But it was the first time an AI system in our company did something odd and a human found out within a minute, from a system that had read nothing but the log.

The questionnaire asked which AI has access to what. Now I export a CSV and attach it.

What it cost us

If you are a small team with agents and no security person, my advice is not "buy this". It is: go and check what your agents can actually do right now. Then you'll know whether you need one gate, and if you do, this is the one we picked.