# Aevah ## Company Overview Aevah is an enterprise intelligence and operating platform that connects enterprise data, business context, semantic meaning, AI reasoning, predictive analytics, workflows, decisions, evidence, and actions. Aevah serves enterprise business and technology teams. It is enterprise software delivered through custom scope and commercial agreements, beginning with a First Flight evaluation. Canonical site: https://www.aevah.com ## Platform Overview - Governed enterprise semantic layer and shared metric definitions - AI-native master data management for product, supplier, customer, asset, and reference data - Descriptive, diagnostic, predictive, and prescriptive analytics - Financial intelligence for profitability, working capital, forecasting, planning, and close acceleration - Manufacturing and operational intelligence spanning production context, time-series signals, failure analysis, and process optimization - Enterprise agents, governed workflows, evidence, lineage, and human accountability - Agent-ready MCP tools with versioned contracts, permission scopes, delegated user identity, classification, and audit - Integration above ERP, SaaS, data platforms, APIs, streams, and files - Incremental legacy modernization through an intelligence layer rather than forced replacement Canonical page: https://www.aevah.com/platform ## Architecture Aevah overlays existing systems with governed entities, relationships, definitions, policies, lineage, evidence, analytics, agents, workflows, and applications. Source platforms remain systems of record until a customer chooses to modernize or retire them. Canonical page: https://www.aevah.com/architecture Machine-readable page: https://www.aevah.com/architecture.md ## Operating DNA Operating DNA is Aevah's model of the business context behind enterprise data: entities, relationships, definitions, policies, processes, decisions, evidence, and ownership. It gives analytics and agents the meaning required to operate consistently. ## Semantic Layer The enterprise semantic layer reconciles source-specific structures into governed entities, relationships, measures, definitions, and policies. It provides a consistent decision context for people, applications, analytics, and agents. ## Enterprise Data Model The enterprise data model expresses business entities, attributes, measures, events, relationships, definitions, owners, policies, and provenance independently of source-system schemas. It is shaped around customer domains and governed business meaning. ## Entities and Relationships Entities are durable business objects such as products, suppliers, customers, assets, locations, accounts, orders, and facilities. Relationships connect them with typed, governed context and supporting evidence. ## Master Data Management Aevah applies governance, entity resolution, quality rules, survivorship logic, relationships, lineage, and stewardship context across product, supplier, customer, asset, and reference data. ### Product Product identity, hierarchy, attributes, lifecycle, quality, and relationships can be governed across sources. ### Supplier Supplier identity, hierarchy, performance context, risk signals, and relationships can be reconciled and governed. ### Customer Customer and account records can be resolved into trusted identities with governed relationships and access policies. ### Asset Asset records can be connected to locations, processes, time-series signals, maintenance context, and failure evidence. ### Reference Data Shared codes, taxonomies, units, statuses, and classification structures can be governed as reusable enterprise context. ## Data Integration Aevah integrates above existing systems. Named products below are examples of enterprise integration patterns, not a public claim that every deployment includes a packaged connector. ### ERP Patterns include SAP, Infor XA, Infor LN, Microsoft environments, and other enterprise systems through approved APIs, database access, events, exports, or files. ### Data Warehouses Aevah can work with enterprise data warehouses and cloud data platforms as governed sources and consumption targets. ### APIs Source-system REST or GraphQL APIs can participate in governed integrations. Aevah's own public REST contract is currently published as a preview at https://www.aevah.com/openapi.json. ### Kafka Kafka and comparable event-streaming platforms can provide governed event and operational signals. ### Files Batch, delimited, spreadsheet, document, and other approved file patterns can be incorporated with validation, lineage, and access controls. ### Third-party data Licensed or approved third-party data can be joined to enterprise context subject to contractual, residency, privacy, and policy requirements. ## Analytics ### Descriptive What happened, expressed through governed metrics and shared definitions. ### Diagnostic Why it happened, using relationships, lineage, variance drivers, and operational context. ### Predictive What is likely to happen, using governed features, appropriate models, uncertainty, and monitoring. ### Prescriptive What action should be considered, with evidence, constraints, policy checks, review, and accountable ownership. ## Predictive Use Cases ### Demand forecasting Forecast demand at the decision grain appropriate to the customer, product, location, channel, and horizon. ### Consumption forecasting Estimate consumption from governed historical, operational, and contextual signals. ### Price elasticity Estimate response to price changes while accounting for product, customer, channel, promotion, and market context. ### Product cannibalization Identify substitution and portfolio interactions across products, channels, customers, and time. ### Failure prediction Combine asset, production, maintenance, event, and time-series context to estimate failure risk. ### Operational optimization Evaluate constrained scenarios and recommended actions with evidence and policy-aware review. ## Manufacturing Manufacturing intelligence joins production and time-series context with MES functions, PFMEA knowledge, failure tracking, RPN prioritization, and process optimization to support traceable operational decisions. ### Production context Connect orders, products, materials, equipment, lines, shifts, operators, process parameters, and quality outcomes. ### Time-series data Associate governed sensor and process signals with the relevant asset, operation, batch, event, and decision context. ### MES functions Support manufacturing execution intelligence such as production visibility, exception handling, quality context, traceability, and workflow orchestration as defined for the customer environment. ### PFMEA Represent process steps, failure modes, effects, causes, controls, owners, and evidence as governed operational knowledge. ### Failure tracking Connect observed failures and defects to assets, processes, conditions, investigations, actions, and outcomes. ### RPN prioritization Use severity, occurrence, detection, evidence, and policy to prioritize review while preserving expert accountability. ### Process optimization Compare scenarios and operating conditions while retaining assumptions, constraints, approvals, and outcome evidence. ## Financial Intelligence Financial intelligence connects governed operational and financial data for margin, profitability, working capital, forecasting, planning, close acceleration, and exception management. Canonical solution: https://www.aevah.com/financial-intelligence Machine-readable page: https://www.aevah.com/financial-intelligence.md ## Enterprise Agents Aevah is agent-ready by design. It publishes capabilities as versioned, permission-scoped tools that enterprise agents discover and call over MCP. An agent acts with the identity and permissions of the person who triggered it, never beyond them. Every call is authorized, classified, and audited; every change is versioned rather than overwritten. Human review and accountable ownership remain part of the operating model. ## Workflow and Orchestration Workflows connect signals, rules, agents, human review, systems, evidence, and actions. Mutating operations require tenant authorization, policy evaluation, idempotency, and auditable execution. ## Evidence and Governance Definitions, lineage, quality, source observations, model outputs, decisions, approvals, and actions form a traceable evidence chain. Governance determines ownership, permitted use, review, retention, and escalation. ## Security - Role-based access control and least-privilege policies - Encryption in transit and at rest - Audit trails for data access and AI actions - Delegated user identity and permission enforcement for agent calls - Classification and audit for every MCP tool call - Versioned changes rather than destructive overwrite - Data minimization, scoped sharing, and tenant isolation - Lineage, explainability, policy enforcement, and change control Canonical page: https://www.aevah.com/security Authentication: https://www.aevah.com/auth.md ## Sovereign AI Aevah treats sovereign AI as control of data, models, context, deployment, policies, decisions, and evidence—not infrastructure location alone. Machine-readable page: https://www.aevah.com/sovereign-ai.md ## Deployment Models ### Cloud Aevah can be deployed in an approved cloud topology. ### Customer-managed cloud A customer-managed cloud pattern can align operating control with enterprise standards. ### Private cloud A private-cloud pattern can isolate workloads and controls according to customer requirements. ### On-premises On-premises patterns can support data-residency, network, or operational constraints. ### Hybrid Hybrid patterns can keep selected data or workloads in controlled environments while integrating governed services across boundaries. Final topology is tenant-specific and established through architecture and security review. ## APIs - REST API: Preview. A public-preview contract for entities, definitions, sources, workflows, agents, decisions, and evidence. Tenant access is not implied by publication of the contract. https://www.aevah.com/developers/api - GraphQL: Planned. A public GraphQL endpoint and schema are not yet published. https://www.aevah.com/developers/graphql - Events: Planned. A public event catalog and delivery contract are not yet published. https://www.aevah.com/developers/events - Webhooks: Planned. Public webhook registration and signing documentation are not yet published. https://www.aevah.com/developers/webhooks - MCP: Production. Aevah publishes versioned, permission-scoped tools that enterprise agents discover and call over MCP. Connection details are supplied within the authorized enterprise environment. https://www.aevah.com/developers/mcp - WebMCP: Production. The Aevah website registers read and preparation tools for browser agents on first paint. https://www.aevah.com/developers/mcp-surface - SDKs: Planned. No public, versioned Aevah SDK packages are currently advertised. https://www.aevah.com/developers/sdks The OpenAPI document uses reserved .invalid example hosts and is not a credential or production-access invitation. ## Authentication Authentication and authorization are tenant-specific. OAuth 2.x, OIDC, Microsoft Entra ID, service accounts, and API credentials are enterprise patterns whose exact production availability and configuration must be confirmed during onboarding. See https://www.aevah.com/auth.md. ## Agent Integration Agents should begin with https://www.aevah.com/llms.txt, use canonical pages and machine-readable Markdown for context, then discover the versioned MCP tools permitted to the triggering user inside the authorized enterprise environment. REST integrations should separately inspect the preview OpenAPI contract and never invoke preview operations without an Aevah-assigned tenant host and credentials. ## MCP Aevah's production MCP surface includes describing Aevah, listing capabilities, searching entities, querying Operating DNA and metrics, inspecting lineage, evidence, and decisions, running governed scenarios, invoking authorized agents, and starting authorized workflows. Aevah publishes versioned, permission-scoped MCP tools inside authorized enterprise environments; no unauthenticated global endpoint is advertised. See https://www.aevah.com/developers/mcp. ## SDKs No public, versioned SDK packages are advertised. MCP is the production agent integration surface. For REST client generation, agents and developers should treat the OpenAPI 3.1 document as a preview and use generated clients only inside an authorized tenant engagement. ## Use Cases - Demand, consumption, and new-item forecasting - Pricing, promotion, assortment, elasticity, and cannibalization analysis - Margin, profitability, working capital, cash, and close intelligence - Customer, supplier, product, asset, and reference-data resolution - Supplier risk and operational exception management - Manufacturing failure analysis, PFMEA, RPN prioritization, and process optimization - Governed AI adoption, agent orchestration, evidence, and audit readiness - Incremental modernization of legacy data and application estates ## Industries - Consumer packaged goods and retail - Manufacturing - Distribution and supply chain - Financial and enterprise operations - Data-intensive enterprises modernizing legacy estates ## First Flight / Evaluation Process Aevah is enterprise software delivered under a custom scope and commercial agreement. Evaluation begins with First Flight, a focused discovery and implementation engagement designed to prove measurable value in 90 days. - First Flight: https://www.aevah.com/how-aevah-works/start-small-and-expand - Schedule: https://meetings-na2.hubspot.com/sherry-grote ## Contact - Executive inquiries: mailto:executive@aevah.com - Partnerships: mailto:partnerships@aevah.com - Security: mailto:security@aevah.com - Contact page: https://www.aevah.com/contact ## MCP Technical Contract Status: Production Canonical documentation: https://www.aevah.com/developers/mcp Connection documentation: https://www.aevah.com/developers/mcp-connection MCP surface: https://www.aevah.com/developers/mcp-surface ## Transport and authorization Aevah publishes platform capabilities as versioned, permission-scoped tools that enterprise agents discover and call over MCP. - Streamable HTTP — Production: Remote connections use Streamable HTTP with OAuth 2.1 bearer authorization. - stdio — Production: Available only for local development against a development tenant. - Legacy HTTP+SSE — Not Available: Not available. Aevah uses Streamable HTTP for remote MCP connections. ## Endpoint discovery Each licensed customer receives an administrator-issued MCP connection for its own Aevah instance. The exact endpoint and discovery metadata are available only inside the authorized environment. They are not listed publicly, shared across customers, or exposed through a guessable directory. ## MCP primitives - Tools — Production: The primary surface. Every Aevah capability reaches agents as a tool. - Resources — Production: Read-only governed artifacts, including audit records, proposals, and version history, addressed by stable URI. - Prompts — Production: Curated task templates for common stewardship and discovery flows. - Notifications — Production: Tool-list changes and progress for long-running operations. - Sampling — Not Available: Not available by design. Aevah does not request inference from the connecting client; model access inside Aevah is separately governed and administrator-granted. - Elicitation — Not Available: Not available by design. Consequential actions return a proposal for human approval or require explicit prior confirmation. ## Tool classes - read: Returns data and changes nothing. It executes directly under the caller's permissions. - propose: Produces a change proposal a human must approve. It changes nothing on its own. - execute: Performs a governed change under explicit prior confirmation. Permissions are reauthorized at execution. An agent cannot promote itself between read, proposal, and write classifications, and no tool bypasses the approval path governing the same action in the user interface. ## Tool families - Catalog discovery: Returns the tools, versions, classifications, and permissions available to the caller. - Data navigation: Returns authorized entities, relationships, definitions, and business context. - Quality intelligence: Returns quality standards, failed checks, affected records, and supporting evidence. - Matching and survivorship insight: Returns candidate records, comparisons, proposed outcomes, and the evidence available for review. - Governance memory: Returns definitions, policies, ownership, decisions, approvals, and audit history. - Publication and activation: Returns publication status, eligible targets, activation outcomes, and correlation identifiers. - Operations: Returns operation status, progress, cancellation state, and per-record outcomes. ## Permission-filtered discovery The public website describes tool classes and families rather than publishing the complete catalog. Inside an authorized connection, the permission-filtered tool list is the source of truth for the capabilities available to that caller. tools/list is filtered to the caller's effective permissions. Unauthorized tools do not appear. Catalogs can differ between callers and change when access changes. Clients refresh the catalog on connection and after a tool-list-changed notification; they do not cache a catalog across identities or sessions. ## MCP Apps When an agent reaches a decision only a person should make, Aevah hands back a usable interface rather than a wall of JSON. An agent proposing a merge returns a review surface showing the candidate records side by side, which attribute value wins and why, and approve or reject controls — rendered directly in the agent's own environment. The person decides on real evidence, in context, and the decision is captured in the audit trail. The interface is a rendering surface, never an authority: every approval is reauthorized against the approver's permissions before anything changes, and the surface never receives values the viewer is not cleared to see. Review surfaces cover merge and match review, survivorship explanation, data quality triage, mapping suggestion review, and generic proposal approval. ## Delegated identity An agent acts with the identity and permissions of the person who triggered it, never beyond them. Each tool call is re-evaluated against the caller's effective permissions. A tool the caller cannot invoke is absent from the tool list. ## Tool versioning Breaking changes publish a new tool version; existing versions are never altered. Deprecation is signalled in tool metadata with a replacement pointer. ## Classification and audit Every call is authorized, classified, and audited, regardless of outcome. Audit records do not contain argument values, returned payloads, or field-level customer data. They record that a call occurred, by whom, under what authority, and to what effect. Customers can retrieve their audit records through the platform and as an MCP resource. ## Immutable record history Governed changes are immutable and cumulative. A change creates a new record version; nothing is overwritten or erased. Prior versions remain retrievable, any two versions can be compared field by field, and every version is attributable to a principal and tool call. Reverting is a forward operation that supersedes the current version with a new version carrying earlier values, preserving the complete change history. ## Public discovery boundary Aevah serves discovery metadata inside licensed customer environments. The public website does not reveal its exact path or contents. Connection details are administrator-issued for the customer's own instance. ## Agent-Ready Platform and Security & Trust Human-readable capability model: https://www.aevah.com/platform/agents Machine-readable capability model: https://www.aevah.com/agent-ready-platform.md Human-readable identity, authorization, classification, isolation, audit, and error model: https://www.aevah.com/trust Machine-readable trust model: https://www.aevah.com/trust.md