Glean

Live

BEARER TOKEN

ENTERPRISE SEARCH

Search

Glean gives your agent enterprise search across your company's indexed content: search and summarize documents, chat with Glean Assistant, run Glean agents, and manage collections, answers, shortcuts, and custom datasources.

  • Per-user credentials: each call uses the actual user's access token, never a shared bot.
  • Encrypted per-tenant vault: AES-256, resolved at request time, never in LLM context.
  • Scoped before every call: pre-call scope check, 90-day SIEM-exportable audit chain.
Glean
agent · Acme Q3
Run
Find our latest PTO policy.
S
glean_search
118ms
Workplace agent
The current PTO policy is in the People Team handbook, updated last month. It covers accrual, carryover limits, and how to request time off.
Sources: Glean search, 3 documents
glean
3 documents
18:29
Message Claude...

Tools your workplace agent reaches for on Glean, scoped per user.

CALL ANY TOOL
137 tools for enterprise search: search, summarize, and chat over indexed content, run agents, manage collections, answers, pins, and shortcuts, and index custom datasources.
glean_add_collection_item
Add collection item
Add one or more items (indexed documents, external URLs, or text notes) to an existing Glean Collection. Returns the updated Collection object with its full item list, or an error such as EXISTING_ITEM or CORRUPT_ITEM if an item couldn't be added. Use this to append items to a Collection you already created; use glean_create_collection to create a new, empty Collection first. Requires the target Collection's ID from glean_create_collection or Glean's Collections UI.
Parameters
Name
Type
Required
Description
collection_id
number
Required
The ID of the Collection to add items to. Example: 12345.
items
array
Optional
The items to add, as a JSON array of item descriptors. Each descriptor needs an itemType of DOCUMENT, TEXT, or URL, plus the matching identifier: documentId for an indexed DOCUMENT, url for a URL item, or just a name/description/icon for a freeform TEXT note. Every descriptor can also carry an optional name, description, and emoji icon, and an optional newNextItemId to insert it before a specific existing item instead of appending it to the end. Example: [{"itemType": "URL", "url": "https://example.com/roadmap", "name": "Roadmap"}].
locale
string
Optional
The client's preferred locale in RFC 5646 format (e.g. en, ja, pt-BR). If omitted, the Accept-Language header is used; if that's absent or unsupported, Glean defaults to the closest match or en.
glean_admin_search
Search admin
glean_authorize_action_pack
Authorize action pack
glean_bulk_index_groups
Bulk index groups
glean_chat
Chat
glean_create_agent
Create agent
glean_create_collection
Create collection
glean_debug_get_datasource_status
Debug get datasource status
glean_delete_all_chats
Delete all chats
glean_delete_chats
Delete chats
glean_delete_document_custom_metadata
Delete document custom metadata
glean_delete_shortcut
Delete shortcut
glean_get_agent_schemas
Get agent schemas
glean_get_custom_metadata_schema
Get custom metadata schema
glean_get_insights
Get insights
glean_get_skill_content
Get skill content
glean_index_documents
Index documents
glean_list_answers
List answers
glean_list_pins
List pins
glean_list_skills
List skills
glean_platform_chat
Platform chat
glean_recommend_documents
Recommend documents
glean_run_agent
Run agent
glean_search
Search
glean_set_beta_users
Set beta users
glean_sync_skill
Sync skill
glean_update_agent
Update agent
glean_update_document_permissions
Update document permissions
glean_upload_shortcuts
Upload shortcuts
glean_upsert_custom_metadata_schema
Upsert custom metadata schema

For more tools, view docs.

Build your Agent
Same auth pattern across LangChain, OpenAI, Anthropic, and Google ADK.
Python · LlamaIndex
import { ScalekitClient } from "@scalekit-sdk/node";
import { createReactAgent } from "@langchain/langgraph/prebuilt";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

// Glean tools scoped to this user
const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["glean"], toolNames: [
    "glean_search",
    "glean_chat",
    "glean_summarize_documents"] },
  pageSize: 100,
});

const agent = createReactAgent({ llm, tools });
await agent.invoke({ messages: [{ role: "user", content: "Find our latest PTO policy" }] });
import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const openai = new OpenAI();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["glean"] }, pageSize: 100,
});

const res = await openai.chat.completions.create({
  model: "gpt-5",
  messages: [{ role: "user", content: "Find our latest PTO policy" }],
  tools,
});

// Execute the tool call with the user's vaulted Glean access token
await sk.tools.executeTool(res.choices[0].message.tool_calls[0], "user_123");
import Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const anthropic = new Anthropic();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["glean"] }, pageSize: 100,
});

const msg = await anthropic.messages.create({
  model: "claude-sonnet-5",
  max_tokens: 1024,
  messages: [{ role: "user", content: "Find our latest PTO policy" }],
  tools,
});

// Tool call runs with the user's vaulted Glean access token
await sk.tools.executeTool(msg.content, "user_123");
import { Agent } from "@google/adk/agents";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["glean"] }, pageSize: 100,
});

const agent = new Agent({
  name: "workplace_agent",
  model: "gemini-2.5-pro",
  instruction: "Glean tools scoped to this user",
  tools,
});

await agent.run("Find our latest PTO policy");
Try these prompts
Copy any prompt into your agent. Each maps directly to a Glean tool. Click to copy, paste into your agent, done.
Search and answers
Copy the prompt
Copied
Find our latest PTO policy.
Copy the prompt
Copied
Summarize the Q3 planning docs with a focus on hiring.
Copy the prompt
Copied
Ask Glean Assistant what changed in the expense policy this year.
Agents and people
Copy the prompt
Copied
List the Glean agents I can access.
Copy the prompt
Copied
Run the onboarding agent for a new hire in Sales.
Copy the prompt
Copied
Look up the directory profile for jane@example.com.
Knowledge upkeep
Copy the prompt
Copied
Create a collection for the security review docs.
Copy the prompt
Copied
Create a go-link for the engineering handbook.
Copy the prompt
Copied
List documents I own that need verification.
SEE HOW AUTH WORKS
Each user connects their own Glean access token once; Scalekit sends it with every call. Tokens stay vaulted, every call is scope checked, and every action is logged.
1
Authorize
Your user connects
Glean
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
Glean
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
Glean
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
Glean
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
See the same per-user auth pattern across other search and knowledge connectors.
Support and Ops Teams
Meeting prep
Pulls agenda, participant context, and open action items before every meeting.
Engineering Teams
Slack triage
Polls Slack for new messages, classifies bugs and support requests with a LangGraph router, files GitHub issues or Zendesk tickets, and confirms in the thread.
Support and Ops Teams
Support triage agent
Fetches new Zendesk tickets, classifies them by type and urgency, searches the Notion knowledge base for an answer, and routes what it cannot resolve to Slack. Every call runs on the support agent's own delegated OAuth.
GTM and RevOps Teams
Competitive intelligence briefing agent
Scans Gong calls for competitor mentions, matches each one to its Notion battlecard, and DMs every affected rep a single Slack digest per cycle. Every call runs as the PMM who owns the briefing, never a shared bot.
Test other agents
See the same per-user auth pattern across other search and knowledge connectors.
OPS
Meeting prep agent
Assemble the agenda, HubSpot attendee history, and open action items from Gmail before every meeting on the calendar.
ENGINEERING
Slack triage agent
Classify new Slack messages as bugs or support requests, file the GitHub issue or Zendesk ticket, and reply in the thread.
SUPPORT
Support triage agent
Classify new Zendesk tickets, search the Notion knowledge base for an answer, and route what it cannot resolve to Slack.
GTM
Competitive intelligence briefing agent
Scan Gong calls for competitor mentions, match each one to its Notion battlecard, and DM every affected rep a single Slack digest.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
01.
Shared tokens break per-user analytics
A shared Glean access token looks fine in a demo. In production every search looks like one service account, and you cannot tell which user triggered it. Scalekit resolves the credential of the actual user who triggered the agent, never a shared bot.
// shared token
audit → bot_service_account

// scalekit
audit → user_abc ✓
02.
Authentication is not authorization
03.
Multi-tenancy is architectural
04.
Glean today. Ten connectors tomorrow.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions
Does the agent access Glean as the user or as a shared key?
As the user. Each user connects their own Glean access token once, and Scalekit sends it with every call. Audit logs attribute every action to that user, not a shared service account.
Where is the Glean access token stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. To rotate it, the user reconnects with a new access token. Revocation is a single dashboard action. Credentials never appear in prompts, logs, or LLM context.
Can I limit what the agent does in Glean?
Yes. Filter by tool name in listScopedTools to expose only what you want. Scalekit also enforces scope checks before every API call.
What happens when a user revokes Glean access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.
Which Glean tools should an agent use?
Glean has 137 tools: 62 read, 56 write, and 19 destructive. They cover search, document summaries, Glean Assistant chat, agents, collections, answers, announcements, pins, shortcuts, skills, triggers, and indexing for custom datasources. Most agents need only glean_search, glean_chat, and glean_summarize_documents; filter to those in listScopedTools.
Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""glean"": {
""url"": ""https://mcp.scalekit.com/glean"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.glean]
url = ""https://mcp.scalekit.com/glean""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""glean"": {
""url"": ""https://mcp.scalekit.com/glean"",
""type"": ""http""
}
}
}