bRRAIn Certified Integration Engineer
Connect bRRAIn to CRMs, warehouses, SaaS tools, AI models and partner orgs through governed gateways that hold up in audit.
- Level
- Expert
- Learning time
- 41 hours
- Price
- $499
- Credential
- Valid 3 years
What changed in this edition.
- Rebuilt on the real product: Platform SDK v1.2.0 extensions, policy-aware ingestion, Data Pipe, Exchange MCP, the Tool Registry and the LLM Registry replace v1's fictional Handler adapter SPI and custom MCP firewall.
- The Universal Interconnection Principle is now taught as a method: bRRAIn-to-bRRAIn where both sides run bRRAIn, governed gateways for everything else; integrating with and exporting to other systems is normal and supported.
- New modules on identity and secrets (Login with bRRAIn, OAuth connections, Operator ENV), MCP clients, model integration with the Handler as default, and migration using the plan/apply/revert pattern.
- Every code sample compiles against the Platform SDK, and POPE is taught correctly as Persons, Organizations, Places, Events (POPE-Tagging Standard v1.1).
- 25 AI role-play labs and a written capstone scored against a published rubric replace the v1 sandbox and oral-interview claims; the exam is a LOFT form with six AI-conducted performance tasks.
What you will be able to do.
- You will be able to select and justify the governed integration path for any requirement and record the decision.
- You will be able to build and package Go extensions on the Platform SDK that commit content through policy-aware ingestion with role, policy and audit wiring.
- You will be able to connect and classify federated sources with Data Pipe and expose them, Exchange MCP servers and Tool Registry entries to AI assistants with least privilege.
- You will be able to integrate models through the LLM Registry with the Handler as default and commercial models as scoped, recorded opt-ins.
- You will be able to engineer identities, secrets and credential rotation with Operator ENV, OAuth connections, per-client tokens and Login with bRRAIn.
- You will be able to make integrations reliable with idempotent writes, classified retries, durable watermarks and observability, and migrate legacy content with a reconstructable audit trail.
- You will be able to run bRRAIn-to-bRRAIn engagements under the joint-session method and deliver integrations through the Build Methodology with recorded controller approvals.
Who it's for
- Senior integration engineers and solutions architects
- Systems integrators with enterprise middleware backgrounds
- Partner-firm integration practice leads
- Customer-side platform engineers taking ownership of bRRAIn integrations
Not covered here
- Application-level SDK fundamentals (prerequisite: SDK Developer)
- Multi-tenant platform architecture (see Platform Architect)
- Operations governance authority (see Operations Controller)
13 modules, 126 lessons.
About 41 hours of learning. Open a module to see every lesson.
-
Integration Architecture and Governed Gateways
The role, the eight zones as integration checkpoints, the governed gateways, path selection, surfaces and clients, the design record, and the Universal Interconnection Principle applied as a method.
- Module 1 pretest
- The Integration Engineer's map: role, zones and zero trust
- The governed gateways and what each one is for
- Choosing an integration path: a decision procedure
- Surfaces, clients and the external HTTP API
- Writing the integration design record
- The Universal Interconnection Principle in practice
- Lab: Choose the paths for a five-system rollout
- Lab: Answer a vendor's integration request
- Module retrieval check
-
Vault Data Modeling: Layout, POPE and Ontology
Record design for the vault, the ontology graph, POPE v1.1 tagging, versioning under Correction & Supersession, scope-aware layout, and store-versus-federate decisions.
- Module 2 pretest
- Record design for the vault: files, frontmatter and stable ids
- Building the ontology graph from tags and links
- POPE v1.1 for integrated records
- Schema drift, versioning and Correction & Supersession
- Scope-aware layout: projects, extension namespaces and read limits
- Store in the vault or federate in place?
- Lab: Model a CRM in the vault
- Lab: Review a batch of integrated records
- Module retrieval check
-
Building Extensions on the Platform SDK
The extension runtime, the SDK client and errors, the vault sub-client, policy-aware ingestion, governance calls, and the manifest contract and marketplace submission.
- Module 3 pretest
- How an extension runs: supervisor, internal API and namespaces
- Constructing the client, deadlines and APIError
- The vault sub-client in practice
- Policy-aware ingestion with Ingestion().Commit
- Role, policy, audit and notifier calls
- The manifest, the install contract and marketplace submission
- Lab: Code review of a ticket-sync extension
- Lab: Wire governance into a write path
- Module retrieval check
-
Governed Gateways and Cross-Organization Engagements
The Universal Interconnection Principle taught correctly, the design-time interconnection check, bRRAIn-to-bRRAIn engagements under the joint-session method, external auditor access, scope design and outbound data flows.
- Module 4 pretest
- The Universal Interconnection Principle, correctly
- The design-time interconnection check
- Running a bRRAIn-to-bRRAIn engagement with the joint-session method
- External auditors: the Robo Compliance auditor portal
- Designing scope: least data, least privilege
- Outbound data flows: what leaves, through which gateway
- Lab: Design a 60-day bRRAIn-to-bRRAIn engagement
- Lab: Defend the scope to a Security Controller
- Module retrieval check
-
Identity, Secrets and Non-Human Actors
Non-human identities, credential rotation, least privilege with scopes and custom roles, audit attribution, Login with bRRAIn for apps, and vendor secrets through Operator ENV and OAuth resolution.
- Module 5 pretest
- Non-human actors in bRRAIn
- Credential rotation without breaking the audit trail
- Least privilege with scopes, custom roles and per-project grants
- Audit attribution for services
- Login with bRRAIn for your app (OIDC)
- Vendor secrets: Operator ENV and call-time resolution
- Lab: Inventory and right-size integration identities
- Lab: Write a rotation runbook after a leaked token
- Module retrieval check
-
MCP Integration: Gateway, Exchange MCP and Tool Registry
The Z6 MCP Gateway and dynamic tool catalog, Exchange MCP servers and tiers, calling tools from code, MCP permissions, Tool Registry entries, and MCP clients.
- Module 6 pretest
- The MCP Gateway and the dynamic tool catalog
- Exchange MCP: 57 servers, tiers and credentials
- Calling MCP tools from an extension
- MCP permissions and coordination with the Access Controller
- Authoring Tool Registry entries
- MCP clients: Claude Desktop, VS Code, ChatGPT and the browser extension
- Lab: Roll out Exchange MCP servers for a department
- Lab: Design a Tool Registry entry for an internal API
- Module retrieval check
-
Reliability: Idempotency, Batching, Sync and Telemetry
Batching within ingestion limits, idempotency and safe retries, incremental sync with durable watermarks, telemetry, conflict handling and observability.
- Module 7 pretest
- Batching within ingestion limits
- Idempotency and safe retries
- Incremental sync and durable watermarks
- High-velocity and telemetry sources
- Conflicts, sources of truth and supersession
- Observability for integrations
- Lab: Design an incremental ticket sync
- Lab: Replay after a partial failure
- Module retrieval check
-
Data Pipe: Federated Data Sources
Index-then-federate and the hot cache, the 31 connectors, access tiers A0-A4, the datapipe MCP tools, pipelines and the Meta-Registry, and operating Data Pipe in production.
- Module 8 pretest
- How Data Pipe works: index, federate, cache
- Onboarding sources with the 31 connectors
- Access tiers A0-A4 in practice
- datapipe_list_sources and datapipe_query
- Pipelines, the Meta-Registry and scopes
- Operating Data Pipe: performance, cache and failure scenarios
- Lab: Onboard a warehouse and a SaaS source
- Lab: Classify twelve objects into access tiers
- Module retrieval check
-
Legacy Migration with an Audit Trail
Migration planning, document ingestion with Mega-parser, the audit trail, PII, legal hold, stale and duplicate content, the plan/apply/revert reference pattern, and cutover validation.
- Module 9 pretest
- Migration planning
- Documents: Mega-parser, ingestion rules and verification
- Keeping the audit trail through a migration
- PII, legal hold, stale and duplicate content
- The plan / apply / revert reference pattern
- Cutover validation and the go/no-go call
- Lab: Plan a document-system migration
- Lab: Run the go/no-go meeting
- Module retrieval check
-
Integration Catalog, OAuth Connections and Webhooks
The integration catalog, payload schemas, webhook ingress, OAuth connection management, Notifier outbound events, and choosing Agent Orchestrator workflows or extensions.
- Module 10 pretest
- The integration catalog: descriptors, events and actions
- Payload schemas and mapping events into records
- Webhook ingress done right
- Managing OAuth connections and triaging bearer failures
- Notifications and outbound alerts through the Notifier
- Agent Orchestrator workflow or custom extension?
- Lab: Design webhook ingress for a CRM
- Lab: Triage an OAuth failure
- Module retrieval check
-
Model Integration: LLM Registry and the Handler
The LLM Registry with the Handler default and commercial opt-in, model discovery and calls, idempotent registration, data handling for model calls, LLMOps governance and routing decisions.
- Module 11 pretest
- The LLM Registry and the Handler default
- Discovering and calling models from an extension
- Registering models idempotently
- Data handling for model calls
- Governing model use with LLMOps
- Model routing decisions
- Lab: Onboard a self-hosted model
- Lab: Review a commercial-model opt-in request
- Module retrieval check
-
Testing, Debugging, Documentation and Delivery Method
Test strategy with fake internal APIs and negative tests, debugging across layers, the integration dossier, the Build Methodology, controller coordination, and release and change.
- Module 12 pretest
- A test strategy for integrations
- Debugging across extension, pod and console
- The integration dossier
- The Build Methodology applied to integration work
- Coordinating with the controllers
- Releasing and changing integrations safely
- Lab: Debug a failing integration
- Lab: Defend the dossier to the Operations Controller
- Module retrieval check
-
Capstone: End-to-End Integration Design
The capstone brief, the design review checklist, a worked example, the capstone lab and an interleaved final review.
- Module 13 pretest
- The capstone: an end-to-end integration design package
- The integration design review checklist
- A worked capstone example (abridged)
- Capstone lab: End-to-end integration design package
- Interleaved retrieval check
Practice against someone who pushes back.
Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.
-
Lab 1 · Integration Architecture and Governed Gateways
Choose the paths for a five-system rollout
-
Lab 2 · Integration Architecture and Governed Gateways
Answer a vendor's integration request
-
Lab 3 · Vault Data Modeling: Layout, POPE and Ontology
Model a CRM in the vault
-
Lab 4 · Vault Data Modeling: Layout, POPE and Ontology
Review a batch of integrated records
-
Lab 5 · Building Extensions on the Platform SDK
Code review of a ticket-sync extension
-
Lab 6 · Building Extensions on the Platform SDK
Wire governance into a write path
-
Lab 7 · Governed Gateways and Cross-Organization Engagements
Design a 60-day bRRAIn-to-bRRAIn engagement
-
Lab 8 · Governed Gateways and Cross-Organization Engagements
Defend the scope to a Security Controller
-
Lab 9 · Identity, Secrets and Non-Human Actors
Inventory and right-size integration identities
-
Lab 10 · Identity, Secrets and Non-Human Actors
Write a rotation runbook after a leaked token
-
Lab 11 · MCP Integration: Gateway, Exchange MCP and Tool Registry
Roll out Exchange MCP servers for a department
-
Lab 12 · MCP Integration: Gateway, Exchange MCP and Tool Registry
Design a Tool Registry entry for an internal API
-
Lab 13 · Reliability: Idempotency, Batching, Sync and Telemetry
Design an incremental ticket sync
-
Lab 14 · Reliability: Idempotency, Batching, Sync and Telemetry
Replay after a partial failure
-
Lab 15 · Data Pipe: Federated Data Sources
Onboard a warehouse and a SaaS source
-
Lab 16 · Data Pipe: Federated Data Sources
Classify twelve objects into access tiers
-
Lab 17 · Legacy Migration with an Audit Trail
Plan a document-system migration
-
Lab 18 · Legacy Migration with an Audit Trail
Run the go/no-go meeting
-
Lab 19 · Integration Catalog, OAuth Connections and Webhooks
Design webhook ingress for a CRM
-
Lab 20 · Integration Catalog, OAuth Connections and Webhooks
Triage an OAuth failure
-
Lab 21 · Model Integration: LLM Registry and the Handler
Onboard a self-hosted model
-
Lab 22 · Model Integration: LLM Registry and the Handler
Review a commercial-model opt-in request
-
Lab 23 · Testing, Debugging, Documentation and Delivery Method
Debug a failing integration
-
Lab 24 · Testing, Debugging, Documentation and Delivery Method
Defend the dossier to the Operations Controller
-
Lab 25 · Capstone: End-to-End Integration Design
End-to-end integration design package
End-to-end integration design package
Artefact submitted in the capstone lab, AI-scored against the published rubric
Pass mark: 75%
Scored on
- Path selection and interconnection15%
- Data model and migration15%
- Extension and ingestion design15%
- AI tools and model integration15%
- Identity, secrets and least privilege15%
- Reliability and observability10%
- Delivery governance15%
One exam. A credential anyone can verify.
The exam
- Items per form
- 66
- Time allowed
- 180 min
- Pass mark
- 75%
- Performance tasks
- 6
- Attempts included
- 2
- Wait between attempts
- 7 days
- Online and timed, taken on learn.brrain.io.
- Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
- Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.
The credential
- A verifiable digital badge in your name.
- A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
- Valid for 3 years.
- Renewal: At 3 years by passing the then-current exam
Where this course sits.
Prerequisites
Stacks well with
Frequently asked.
Do I need to install anything for the labs?
No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.
How is the exam delivered?
Online and timed: 66 items in 180 minutes, on a form assembled for you from the course's item bank. 6 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 75%.
What if I don't pass first time?
You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.
How long is the credential valid?
3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.
I hold the v1 credential. Is it still valid?
Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.
Can my company enroll a team?
Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.
bRRAIn Certified Integration Engineer
Connect bRRAIn to CRMs, warehouses, SaaS tools, AI models and partner orgs through governed gateways that hold up in audit.