{ "mailbox": "inbox", "limit": 1 }
1 message
{ "id": "18f3a…" }
signature found
Your last email is a quote request for a warehouse extension. From the signature:
Is this the contact you want to add?
{ "entity": "Company", "name": "%Nordet%" }
1 match
Toitures Nordet inc. is already in the CRM (Lévis). I will:
- add Julie Tremblay as a contact of Toitures Nordet inc.,
- log an activity: “Email received — quote request, warehouse extension”.
{ "entity": "Contact", "confirm": true }
contact #412
{ "entity": "Activity", "confirm": true }
activity #2087
Done. Julie Tremblay is now a contact of Toitures Nordet inc., with today’s activity attached.
An AI employee is an assistant that does not just chat — it does the work. It looks up a customer, drafts the quote, updates the order status, files the lead from last night’s form. The model behind it is the easy part; any of the big ones can reason well enough. The hard part is what it is allowed to touch, and how.
What an AI employee is made of
- A model — Claude, GPT — that understands the request and plans the steps.
- A job description: its instructions, what it does and what it must never do.
- A memory of how you work: the client who pays on the 15th, the quotes that need your approval.
- Tools: named actions it can take — “list overdue invoices”, “create a contact”, “move an appointment”. Without tools it can only talk.
The first three decide how smart it is. The fourth decides how much damage it can do.
The generic ways, and their problem
- Your login. It can do everything you can, including what it should not, and the logs say you did it.
- A robot clicking through your screens. Slow, breaks the day a screen changes, and impossible to limit to “invoices only”.
- An automation platform with an API key. Each connection is a key with broad rights, often stored at a third party, running chains of actions nobody reviews.
- Direct database access. Exact, and completely unguarded: one wrong query changes every row.
All four share the same flaw: the AI gets more access than its job needs, and afterwards nobody can tell exactly what it did.
Why MCP is the right tool
MCP — the Model Context Protocol — is the open standard AI assistants such as Claude use to connect to software. Your application offers a short menu of actions; the assistant can use what is on the menu and nothing else. Four properties make it the right choice for a business:
- Secure. The assistant signs in with a person’s own login and gets exactly that person’s rights, for reading or also for writing. A record you cannot see, it cannot see either.
- Audited. Refused attempts are logged, and the change history marks each edit as made by the AI, not by you — who, what, when.
- Reversible. Every change is recorded with its value before and after, so any edit the AI makes can be seen and put back. Nothing is created or deleted without your OK: it shows you the pending record and waits.
- Customised. The menu is yours. Beyond the generic list, read, create and update, you add tools for your actual jobs — “prepare a quote from this template”, “add this document to the knowledge base” — each with its rules written in code, not in a prompt.
What tools can look like
A few examples, each with the narrowest access that does the job:
- Mail, Google or Microsoft. Sort the inbox, summarise the threads that need you, draft the replies. It writes drafts; sending stays with you.
- Google Drive, OneDrive or SharePoint. Find the signed contract, summarise last week’s proposal. Read access to the folders it needs, not the whole drive.
- The office file server. Pull last year’s price list from the shared folder. Read-only, one share, no deleting.
- Logs. Read the web and application logs to tell you why the site was slow last night or who failed to log in. It reads; it cannot change a setting.
- Accounting. List unpaid invoices and draft the reminders. Payments, refunds and credit notes stay human.
- Orders and inventory. Check stock, update an order’s status, flag what needs reordering. Every change is kept with its before and after value.
- Website content. Draft a news post, update the opening hours for the holidays. Saved as a draft; you publish.
The pattern is the same every time: the narrowest access that does the job, drafts before actions, and a trace of what it did.
Side by side
| Generic tools | MCP | |
|---|---|---|
| Access | Everything the login or key allows | One person’s rights, read or write |
| Who did it | Looks like you | Marked as the AI |
| Undoing a change | Hope there is a backup | Before and after value of every change |
| Creating or deleting | Whatever the script says | Only after your explicit OK |
| When your screens change | A screen-clicking robot breaks | Unaffected — it calls actions, not screens |
| Where the credentials live | Often at a third party | In your application, behind its login |
GoatCheese: MCP built in
Every application I build with GoatCheese ships with its own MCP server, generated from the same description as the database, the back office and the API. There is no separate integration project: add it to Claude as a connector, sign in, approve — and the AI employee is at work.
- The same access rules as the back office and the API, down to “only your records” or “only your group’s”.
- Generic tools out of the box — describe, list, read, create, update, delete — with creating and deleting gated behind your confirmation.
- Custom tools next to them, in code, for the jobs that matter to your business.
- Logins throttled after repeated failures, API calls logged with credentials removed, and a before-and-after history on the tables you choose.
Start small
Start read-only: let the AI employee answer questions from your records for a few weeks. Then add one action that writes, with confirmation — updating a status, logging a call. Widen only what has earned trust. The history tells you exactly what it did along the way.
What this means for an SME
An AI employee is only as safe as its tools. Hand it a login and you have hired someone with the master key and no badge. Hand it MCP tools and you have written a job description that the software enforces.