Tailscale
for LuumenAI

Read your tailnet in full, then change device approval, routes, and tags with review.

Connect Tailscale and your agent can see the whole tailnet: every device with its addresses, tags, and authorization state, the subnet routes each node advertises, DNS and tailnet-wide settings, users, and configuration audit events for a given window. Changes to device approval, enabled routes, and ACL tags are previewed and go through approval first.

The Tailscale toolbox

10 tools: 7 read, 3 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadGet DeviceGet the full current record for one manageable Tailscale device by ID.
  • ReadGet DNS ConfigurationReturn the selected tailnet's combined MagicDNS, nameserver, search-path, and split-DNS configuration.
  • ReadGet Tailnet SettingsReturn current tailnet-wide approval, update, key-duration, HTTPS, routing, logging, and posture settings.
  • ReadList Configuration Audit LogsReturn configuration audit events for an explicit RFC3339 time window in the selected tailnet, optionally filtered by actor, target, or event name.
  • ReadList Device RoutesReturn the subnet routes advertised and currently enabled for a Tailscale device.
  • ReadList Tailnet DevicesReturn all devices in the selected tailnet, including identifiers, names, addresses, tags, authorization state, and connectivity metadata.
  • ReadList UsersReturn users in the selected tailnet, optionally filtered by membership type or role.
  • WriteSet Device AuthorizationApprove or revoke approval for one device when device approval is enabled on the tailnet. Approval by default
  • WriteSet Device RoutesReplace the enabled subnet routes for one device with an explicit list of routes. Approval by default
  • WriteSet Device TagsReplace all ACL tags assigned to one Tailscale device. Approval by default

One prompt, start to finish

What a governed Tailscale run looks like inside Luumen.

Questions

How does LuumenAI connect to Tailscale?

Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Tailscale on its own?

Read actions answer immediately. Anything that writes — set device authorization, set device routes, set device tags — is shown as a plan and requires approval by default. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to Tailscale — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Tailscale to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.