Claude & MCP
Connect Claude to your account — on a leash
Paste a URL into Claude, Claude Code or any MCP client and work with your account in plain language. Ask what is outstanding, draft a reply, look up a customer, update a deal. Bounded, at every moment, by exactly what you could already do yourself.
- Works with Claude, Claude Code and any MCP client
- Never exceeds its creator's own authority
- Read-only until you say otherwise
- A redacted log of who read or changed what
Refused, not silently emptied. Account deletion, ownership transfer, role changes and credentials are off at every configuration — including for an owner.
It acts as you, and never more
An owner gets owner reach. A front-desk agent gets front-desk reach. A doctor gets clinic tools scoped to their own patients. A viewer is read-only at every configuration, no matter what they switch on. The MCP session runs as a real user, so every database policy behaves exactly the way it does when that person is clicking around the dashboard — the guarantee is not a check we remembered to write, it is the same mechanism the app already runs on.
- Five layers must all pass before a tool is even offered
- Four of them decide what the model may ask for
- The fifth — the database — decides what it may actually see
Read-only until you say otherwise
A brand-new connection has the read tools on and everything that writes off. From there every tool is individually switchable, so you can grant exactly the job you want done and nothing adjacent to it. Tools above your role are shown disabled with the reason given — a ceiling you might one day cross is worth seeing. Tools outside your job are not shown at all, because a whole side of the business that isn't your work is just noise.
Some things are never on the menu
Account deletion, ownership transfer, changing who is a member or what role they hold, and anything touching credentials — API keys, other MCP connections, AI provider keys, channel configuration. These are unavailable at every configuration, including to an owner. They are either irreversible, or they are changes to authority rather than to business data, and a model steered by text that someone else wrote into a conversation must not be able to reach them.
A log that answers 'who', not 'what they said'
Every call records which connection, which person, which tool, the outcome, and the role it ran as — plus a redacted summary of the arguments built from a per-tool whitelist. Message bodies, notes, phone numbers, emails and clinical values are never stored; a text argument is recorded only as its length. The log answers who read or changed what, and when. It deliberately cannot answer what it said.
Set up in about a minute
Create a named connection, choose its toolset, and paste the URL into your client. The URL is shown exactly once and only a short prefix is kept afterwards, so nobody — including us — can recover it later. Expiry is mandatory, ninety days by default, and regenerating kills the old URL the moment you confirm.
Questions
Frequently asked
Explore more
Works well with
Developer API
The whole account, over REST
Contacts, the inbox, messages, templates, broadcasts and the sales pipeline over a versioned REST API — with account-scoped keys, signed webhooks, an OpenAPI spec and reference docs.
Learn moreAI assistants
It drafts, it replies, it knows when to fetch a human
Draft replies and summarise threads, or hand whole conversations to an assistant that answers within limits you set — and steps aside the moment a person takes over.
Learn moreSecurity & data isolation
Isolated by the database, not by a WHERE clause
Tenant isolation enforced by the database rather than by application code, encrypted secrets, verified webhooks — and the option to host it yourself.
Learn moreWant to see it running on your own data?
Book a demo and we'll connect Claude to a real account, with a real toolset, and show you what it can and cannot reach.
We reply in under an hourOr message us on WhatsApp