Capabilities
APIs over legacy systems
What it is
We design and build integration layers — REST or event-driven facades — in front of legacy ERP, CRM, mainframe transactions and vendor packages with poor APIs. The layer translates modern requests into operations the legacy system supports, enforces business rules and returns consistent errors agents can handle.
This is infrastructure, not a chat feature. Assistants, agents and copilots depend on it for read and write access without one-off hacks per project.
Typical deliverables
- API specification with versioning and deprecation policy.
- Adapters to legacy protocols — message queues, stored procedures, CICS, RFC.
- Auth integration with your identity provider and service accounts.
- Rate limiting and circuit breakers protecting fragile backends.
- Synthetic monitoring and golden-path tests.
- Documentation and sandbox environments for agent teams.
When it pays back
Payback is immediate when multiple AI or digital initiatives duplicate the same fragile integration. One API team serves many consumers. Risk drops when writes pass through validation instead of ad hoc scripts.
It also shortens delivery timelines — agent projects stall when ERP access is unknown. A scoped API for read customer balance and create service ticket clears the path for service agents and assistants alike.
Prioritise this when
- Legacy vendor APIs are missing, deprecated or per-screen.
- Integration knowledge lives in one retiring developer's head.
- AI pilots use nightly CSV exports.
- Audit asks how automated writes reach the ledger.
How Incubics engineers it
Discovery: two weeks mapping systems and operations with your enterprise architects. Week twelve: production API covering a bounded operation set with tests and monitoring — not the entire ERP.
Perceive — weeks 1–2
We document current integration paths, data contracts and failure history. We prioritise endpoints by downstream demand — which agents need what first. Output: API design, non-functional requirements, security review pack, phased roadmap.
Engineer — weeks 3–10
We implement adapters, schema validation, idempotency keys for writes and observability. Contract tests run in CI. Load tests respect legacy throughput limits agreed with ops.
Deliver — by week 12
Production endpoints with auth, logging, rate limits and runbook for legacy outages — degraded modes defined, not silent corruption. Consumer teams onboard with sandbox keys.
Run — ongoing
We monitor error budgets, coordinate with legacy change windows and version APIs when backend fields shift. New consumers reuse the layer instead of new tunnels.
Failure modes
- Leaking raw legacy error codes to agents — loops and confusion.
- No idempotency — retries double-post.
- Over-scoping v1 — never ships.
- Bypassing the API for one urgent project — drift returns.
- Undocumented batch jobs fighting online writes.
Legacy teams sometimes fear API layers add latency. Measured p95 against direct calls, with caching where safe, usually settles the debate with data.
What you get
- OpenAPI or AsyncAPI specifications checked into your repos.
- Implementation deployed to your cloud or on-prem standards.
- Auth, throttling and audit logging on every endpoint.
- Test suites including legacy simulators where available.
- Monitoring dashboards and on-call runbooks.
- Migration guide for retiring point integrations.
- Optional managed run for the integration layer.
What we refuse to ship
We refuse production write paths without idempotency and reconciliation. We refuse screen-scraping wrappers labeled APIs. We refuse endpoints without owners named in the runbook.
Is this the same as full ERP replacement?
No. This makes the current system usable for modern consumers while replacement proceeds on its own timeline if at all.
Who maintains the API when legacy patches ship?
Run covers contract tests that fail when behaviour changes. Ownership is explicit — platform team, SI, or Incubics managed run.
Can agents call the API directly?
Yes, through the tool gateway with scoped credentials. Humans and services share the same contract.
What about message-based legacy systems?
Event-driven facades are often safer than synchronous REST for mainframe workloads. Design follows ops constraints.
How does this relate to cloud modernisation?
API layers are often a modernisation wave themselves. See Application & Cloud Modernisation for broader re-platforming; this capability focuses on the interface AI needs now.
Next step
Start with two weeks.
A fixed-fee discovery gives you a ranked use-case portfolio, a target architecture, a cost model and a build proposal you can take to your board. If we don't find a case worth building, we tell you.