Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
MuleSoft Agent Fabric vs Workday Agent System of Record
MuleSoft Agent Fabric
Control plane for agents, MCP servers, and APIs across platforms
Workday Agent System of Record
Workday system of record to find, add, register, configure, monitor, and manage AI agents
Short answer
MuleSoft Agent Fabric is a control plane for agents, MCP servers, and APIs across platforms; Workday Agent System of Record (ASOR) is set up per Workday tenant to register and manage agents.Source 1, Source 2, Source 3 Agent Fabric enforces policy at a gateway in managed agents’ request path; ASOR gives each agent a unique Workday identity under Workday security.Source 4, Source 5, Source 6
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
MuleSoft Agent Fabric
- Agents across organizations: Not publicly documented
Workday Agent System of Record
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
MuleSoft Agent Fabric
MuleSoft documents Agent Fabric as an AI control plane for agents, MCP servers, and APIs across platforms.Source 1 Scanners and manual registration fill its registry, Omni Gateway enforces policy in managed agents’ request path, and agent brokers orchestrate A2A-compliant agents.Source 4, Source 10, Source 11
Workday Agent System of Record
Workday Agent System of Record (ASOR) is a functional area you enable in a Workday tenant to find, register, configure, monitor, and manage AI agents.Source 2, Source 3 Its Agent Management Hub manages Workday-built, partner-built, and self-built agents, each with a unique Workday identity.Source 3, Source 5
The differences that matter
How agents get into the registry
MuleSoft Agent FabricScanners register the agents, APIs, and MCP servers they find on supported platforms; other agents can be registered by uploading an agent card.Source 4, Source 11
Workday Agent System of RecordExternal agents are currently registered only through the ASOR API; the registration call is based on the A2A Agent Card and records each agent’s platform.Source 7, Source 17
MuleSoft lists scanner limits of one run a day and 10,000 services.Source 18 Workday says some agents, including those for HiredScore and Evisort, are not part of ASOR.Source 3
Who decides what an agent can reach
MuleSoft Agent FabricOmni Gateway, in managed agents’ request path, can require authentication and authorization and limit which tools and APIs an agent can call.Source 4
Workday Agent System of RecordWorkday security policies and groups set each agent’s access; acting for a user, an agent gets only what both may do.Source 5, Source 6
MuleSoft says policy at the communication layer lets third-party agents be governed without being modified.Source 15 Workday’s Agent Interaction Policy sets which users may use an agent’s delegate-mode skills.Source 19
Where each one runs
MuleSoft Agent FabricAgent Fabric runs on MuleSoft-hosted regional control planes; Omni Gateway can be self-managed, including in a data center or on EKS, GKE, or AKS.Source 1, Source 20, Source 21
Workday Agent System of RecordASOR is set up in each Workday tenant, with no current way to migrate its configuration; external agents’ definitions record where they are hosted.Source 2, Source 17
A self-hosted Agent Fabric control plane is not publicly documented, and neither is a self-hosted ASOR.
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| MuleSoft Agent Fabric | Workday Agent System of Record | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Control plane for agents, MCP servers, and APIs across platforms.Source 1 MuleSoft says it discovers, governs, orchestrates, and observes agents.Source 13 | Set up in each Workday tenant to find, register, configure, monitor, and manage AI agents built by Workday, partners, or the customer.Source 2, Source 3 |
| Maturity | MuleSoft says it is generally available, with new capabilities each month.Source 15 Its first release note is dated 3 October 2025.Source 10 | Announced in February 2025; generally available since February 2026.Source 16, Source 28 Agent Gateway was announced in June 2025.Source 29 |
| Control | ||
| Agent registry and discovery | One inventory of agents, MCP servers, and APIs, whatever platform built them.Source 4 Scanners fill it; agents can also be added by uploading an agent card.Source 4, Source 11 | The Agent Management Hub lists Workday-built, partner-built, and self-built agents with status.Source 3 Some, such as HiredScore and Evisort agents, aren’t in ASOR.Source 3 |
| Identity and access control | Omni Gateway can require authentication and authorization and limit which tools and APIs an agent can call.Source 4 User roles come from Anypoint access management.Source 1 | Each agent has a unique Workday identity, governed by security policies and groups.Source 5, Source 6 Acting for a user, an agent gets only what both may do.Source 5 |
| Ownership, policy, and revocation | Governance strategies set rules for in-scope agents, APIs, and MCP servers and can block or flag noncompliance.Source 4 MuleSoft says scanners pull ownership metadata.Source 15 | Admins set each agent’s skills and who can use it, and activate or deactivate it.Source 3, Source 30 Each agent’s profile shows who built it.Source 7 |
| Audit log and observability | Omni Gateway can keep a traffic audit trail.Source 4 Platform audit logs are kept a year by default; Integration Advanced or Titanium adds export to third-party tools.Source 8 | An audit trail report covers agent transactions; delegated actions record the agent and the user.Source 5, Source 9 Per-agent analytics reports cover Workday-built agents only.Source 3 |
| Connection | ||
| How agents connect | Omni Gateway sits in the request path of each managed agent, API, or MCP server.Source 4 An egress gateway carries agent networks’ calls to agents outside the network.Source 22 | Third-party agents must route Workday API traffic through Agent Gateway, a single regional endpoint.Source 12 Outbound-only use is not publicly documented. |
| Agents across organizations | Agent networks can use agents from another agent network or elsewhere in your company.Source 31 Partner-held access controls: not publicly documented. | ASOR manages partner-built agents; a definition can carry an ID locating one in the partner’s system.Source 3, Source 17 Partner-held access controls: not publicly documented. |
| Protocol support | Omni Gateway supports MCP and A2A.Source 32 A2A powers orchestration in agent networks, and MCP Bridge turns an API into an MCP server without custom code.Source 4, Source 33 | API registration is based on the A2A Agent Card.Source 17 Outside assistants can call the Self-Service Agent over A2A, and tool search can filter by SOAP, REST, or MCP.Source 34, Source 35 |
| Frameworks, models, and clouds supported | MuleSoft calls it vendor agnostic and says its scanners cover Amazon, Google, Microsoft, Databricks, and more.Source 13, Source 15 Brokers orchestrate only A2A-compliant agents.Source 4 | Registration records each agent’s platform, or OTHER.Source 17 Workday names Google Gemini Enterprise as an outside assistant able to call its Self-Service Agent.Source 34 |
| Operations | ||
| Deployment options and data residency | Agent Fabric runs on MuleSoft-hosted regional control planes.Source 20 Omni Gateway can be self-managed.Source 1, Source 21 Self-hosting its control plane isn’t publicly documented. | Set up in each Workday tenant.Source 2 Agent Gateway endpoints: US, EU, UK, Canada, Australia, Singapore, India, Japan.Source 12 Self-hosting: not publicly documented. |
| Compliance attestations | MuleSoft says Anypoint Platform meets ISO 27001, SOC 2, PCI DSS, HIPAA, and GDPR.Source 26 An attestation naming Agent Fabric is not publicly documented. | Workday says its SOC 2 report covers Workday Enterprise Products.Source 27 Its ISO 42001 certificate covers named products including Workday Platform; ASOR isn’t named.Source 27 |
| Support and SLA | MuleSoft’s Cloud Offerings SLA commits to 99.95% monthly for covered services, on subscriptions started by 1 May 2025.Source 36 Anypoint plans include Premier Success.Source 37 | Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.Source 38 An ASOR uptime SLA is not publicly documented. |
| Time and effort to get running | With product access, an admin turns Agent Fabric on.Source 1 Agent networks need a Managed Omni Gateway; scanners need a connected cloud provider for each source.Source 1 | Enable the ASOR functional area and set its security policies.Source 2 Registering an external agent includes finding the IDs of the Workday APIs it will use.Source 7 |
| Pricing model and public prices | MuleSoft packages start at $2,000 a month, billed annually, with usage in Mule Credits.Source 14 MuleSoft lists the Agent Fabric package with no price: contact sales.Source 14 | No additional specific SKU for ASOR.Source 3 Workday-built agents in production need a Flex Credits policy opt-in.Source 3 A credit’s price is not publicly documented. |
| Building | ||
| Agent building tools | Agent networks are defined in YAML, brokers in Agent Script.Source 4, Source 31 MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.Source 15 | You provide an external agent’s definition through an API.Source 3 Workday announced the low-code Flowise Agent Builder for Workday’s separate Workday Build in 2025.Source 39 |
| Model access | Brokers support OpenAI, Azure OpenAI, Bedrock OpenAI, and Gemini models.Source 31 Model Proxy is one access layer for several providers, with spend caps.Source 4, Source 40 | Workday’s AI agents use large language models.Source 3 Which models ASOR supports or includes is not publicly documented. |
| Integrations and ecosystem | The catalog has curated MCP servers from the Official MCP Registry and Informatica.Source 4 Policies can apply to Apigee, Kong Gateway, and Azure API Management APIs.Source 41 | In February 2026, Workday said more than 65 partners were connecting agents to ASOR.Source 16 Workday says partner agents reached its Marketplace in June 2025.Source 29 |
Which to choose
Choose MuleSoft Agent Fabric if
- Your agents run on several platforms, and you want scanners that MuleSoft says cover Amazon, Google, Microsoft, and more.Source 4, Source 13
- You want policy enforced in the request path of managed agents, MCP servers, and APIs, at a gateway you can self-manage.Source 1, Source 4
- You want brokers to orchestrate A2A-compliant agents, and a reversible quarantine for rogue agents after an admin reviews them.Source 4, Source 10, Source 23
- You already run MuleSoft’s Anypoint Platform: Agent Fabric uses Anypoint Platform access management and is turned on there.Source 1
Choose Workday Agent System of Record if
- Your agents mostly work in Workday, and each should have a unique Workday identity under your existing security policies and groups.Source 3, Source 5, Source 6
- You want an agent acting for a user limited to what both may do, with audit entries naming both.Source 5
- You want Workday-built, partner-built, and self-built agents listed with their status in one Agent Management Hub.Source 3
- You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR.Source 2, Source 3
Questions buyers ask
Does either one build or host agents?
Agent Fabric’s brokers run on CloudHub 2.0 or Runtime Fabric; MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.Source 4, Source 15 ASOR takes an external agent’s definition through an API; Workday announced a low-code agent builder for Workday’s separate Workday Build.Source 3, Source 39
How is each one priced?
MuleSoft packages start at $2,000 a month, billed annually.Source 14 MuleSoft lists the Agent Fabric package with no price: contact sales.Source 14 ASOR needs no additional specific SKU; Workday-built agents in production need a Flex Credits policy opt-in.Source 3 Credit prices are not publicly documented.
Do they support MCP and A2A?
Agent Fabric’s Omni Gateway supports MCP and A2A, and A2A powers orchestration in its agent networks.Source 32, Source 33 Workday bases external agent registration on the A2A Agent Card and lists MCP as a tool type; outside assistants can call its Self-Service Agent over A2A.Source 17, Source 34, Source 35
Can either one connect agents across companies?
Agent networks can use agents from elsewhere in your company, and an egress gateway enforces policy on their outbound calls.Source 22, Source 31 ASOR manages partner-built agents, which Workday calls second-party agents.Source 3 For both, access controls held by the partner company are not publicly documented.
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
46 public sources, each with the date we checked it. Every one opens in a new tab.
Source 2: Set Up Agent System of Record (Workday Administrator Guide) Back:abcdefghi
Source 3: About Workday Agents (Workday Administrator Guide) Back:abcdefghijklmnopqrstuvwxyz272829
Source 4: Agent Fabric Overview Back:abcdefghijklmnopqrstuvwxyz2728293031
Source 5: Concept: Agent Security (Workday Administrator Guide) Back:abcdefghijklm
Source 6: Setup Considerations: Agent Security (Workday Administrator Guide) Back:abcdef
Source 7: Register External Agents (Workday Administrator Guide) Back:abcdef
Source 9: FAQ: Agent Security (Workday Administrator Guide) Back:abc
Source 12: Concept: Workday Agent Gateway (Workday Administrator Guide) Back:abcde
Source 13: MuleSoft Agent Fabric | Agent Governance and Orchestration Back:abcd
Source 14: MuleSoft Pricing | Plans From $2,000 a Month Back:abcdef
Source 15: See Every Agent. Govern Every Agent. Control AI Costs. (mulesoft.com home page) Back:abcdefg
Source 16: The Workday Agent System of Record Is Now Generally Available Back:abc
Source 17: ASOR API Documentation v1.2 (Workday/asor on GitHub) Back:abcdef
Source 18: Discovering and Cataloging External Services with Scanners Back to text
Source 19: Concept: Agent Interaction Policy (Workday Administrator Guide) Back to text
Source 22: Deploying Agent Network Ingress and Egress Managed Omni Gateways Back:abc
Source 24: OAuth 2.0 OBO Credential Injection Policy Back to text
Source 25: Concept: External Agent ASU Considerations (Workday Administrator Guide) Back to text
Source 28: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Back to text
Source 29: Workday Announces New AI Agent Partner Network and Agent Gateway Back:ab
Source 30: Workday Agent System of Record | Workday US Back to text
Source 31: Building Agent Networks for Agent Fabric Back:abcd
Source 32: Securing Agent Interactions with Omni Gateway Back:ab
Source 34: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Back:abc
Source 35: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Back:ab
Source 36: MuleSoft Cloud Offerings Service Level Agreement (SLA) for subscriptions with an Order Start Date on or before May 1, 2025 Back to text
Source 37: MuleSoft Subscription Plans - effective for Customer purchases made from Salesforce on or after June 27, 2025 Back to text
Source 39: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Back:ab
Source 41: Enhanced MuleSoft Experience Overview Back to text