Hosted connectors

A hosted connector is a backing source your organization points Atrium at. Atrium executes the calls itself and returns the result, so the tools show up in your team’s assistant with nothing to install and no credential to hand out.

How tools are named

Each server gets a tool prefix, derived from its name when you create it and stable afterwards even if you rename the server. Every tool the connector contributes is published as <prefix>_<action>, so two Postgres servers never collide:

warehouse_db_search_tables
warehouse_db_query
reporting_db_query
marketing_ga4_run_report
marketing_gsc_search_analytics

Available connectors

Postgres

Host, port, database, username, and SSL mode. Atrium stores the password encrypted and never displays it again.

search_tables
Find tables, views and materialized views by name across the schemas the role can reach, each tagged with its kind and its table comment.
describe_table
Column names, types, nullability, primary and foreign keys, plus any table and column comments the database carries. Works on views and materialized views too.
query
Run a read-only SQL query, with the row cap applied.

In curated mode the generic query tool is withheld entirely, and the server instead exposes one tool per named query you authored. Scope parameters on those tools are bound server-side from the caller's properties and never appear in the tool's input schema — so the model cannot widen its own access.

Google Analytics 4

A property ID (properties/123456789) and a service-account key, granted read access on the property. Atrium stores the service-account key encrypted and never displays it again.

run_report
Standard report over metrics and dimensions.
run_realtime_report
Realtime report for the last 30 minutes.
get_metadata
Metrics and dimensions available on the property.
get_property_details
Property name, timezone, currency, and industry.
get_account_summaries
Accounts and properties the service account can see.

Google Search Console

A site — either a domain property (sc-domain:example.com) or a URL-prefix property (https://example.com/) — and a service-account key granted on it. Atrium stores the service-account key encrypted and never displays it again.

search_analytics
Clicks, impressions, CTR, and position by dimension.
list_sites
Sites the service account has access to.
get_site
Permission level for one site.
list_sitemaps
Submitted sitemaps and their status.
get_sitemap
Detail for one submitted sitemap.
inspect_url
Live index status for a single URL.

URL inspection is a live call to Google and is noticeably slower than the other reads — expect it to take several seconds where the rest return in well under one.

Publishing a connector

  1. Create the server in Hosted servers and fill in the connection details for its kind.
  2. For a Google connector, follow the on-screen setup checklist. A missing grant, a wrong property ID, and a wrong property type all come back from Google as the same 403, so the dashboard tells you what to grant and where before you ever make the call.
  3. Test the draft. Atrium runs a real call with the credentials you supplied and reports what came back.
  4. Grant the roles that should see it, then publish. A draft server is never exposed over MCP.

Clients cache the tool list — reconnect after a change

Atrium resolves a caller’s tool list once per connection and does not push change notifications. When you publish a new connector, grant someone access, or change a connector’s visibility, already- connected clients keep their cached list. Users pick up the change by reconnecting — toggling the connector off and on, or restarting the session.

Limits

Results are capped at 1,000 rows by default, so a broad query returns a truncated answer rather than an unusable payload or a timeout. The cap is configurable per deployment.