Roll out to your fleet

Tools and models are separate connections with separate rollouts, and you may be running one or both

Agent Handler gives an employee’s AI client your approved tools, over an MCP endpoint. Gateway gives it your approved models, over a base URL and a key. They are separate connections that reach a machine by different mechanisms, so they roll out separately and in either order. Start here to find the pages that apply to you.

Which rollout you are running

ToolsModels
ProductAgent HandlerGateway
What reaches the clientAn MCP endpoint URLA base URL, an API key, and a model name
What the employee getsThe tools their Groups grantThe models their routing policy allows
What puts it on the machineThe AI client’s own enterprise policy layer, or the employeeThe desktop client, the Workforce CLI, or the employee
FollowRoll out toolsRoll out models

Neither rollout depends on the other, and no page in this section assumes you are doing both.

The page to send an employee

Connect employee AI clients covers both connections in one place, per client. Send that link rather than maintaining a wiki entry, whether you are deploying centrally or asking employees to configure themselves.

Verify either one the same way

Configuration pushed is not a connection made, and your MDM cannot tell the two apart. Both rollouts are verified by traffic rather than by deployment reports:

  • Tools: Tool calls shows every call an employee’s client made, with the employee and the Tool Pack it came through
  • Models: the Gateway dashboard shows requests within a few seconds of the first one, attributed to the employee

In both cases, read the result against your SCIM-synced employee list rather than on its own. A client that received your config and never connected looks exactly like a machine you never reached.

Next steps