Anything that aggregates customer conversations is one careless query away from putting names and emails into a model's context. Bagel puts both levers in the product — which sources are in scope, and what gets redacted on the way out — so the decision is made once, in a settings page, rather than re-made in every prompt. Set them before the first connection, not after.
Bagel's MCP layer over their platform. The connection is per-account rather than a shared address, so you take the URL from their setup rather than pasting one from here.
What Bagel's platform already aggregates from the tools you have connected. The endpoint is per-account rather than a public address, so we could not enumerate the tools ourselves.
A Bagel account and their connect flow. Two controls are worth knowing about before you point an agent at it: integration filters, which limit which sources are in scope, and PII redaction — both configurable in the product.