Claude & MCP

Connect Claude to your account — on a leash

Paste a URL into Claude, Claude Code or any MCP client and work with your account in plain language. Ask what is outstanding, draft a reply, look up a customer, update a deal. Bounded, at every moment, by exactly what you could already do yourself.

  • Works with Claude, Claude Code and any MCP client
  • Never exceeds its creator's own authority
  • Read-only until you say otherwise
  • A redacted log of who read or changed what
Claude — connected to RaabtaHQ
Front desk — Ayeshaacting as agent
Who's waiting on a reply, and can you chase the oldest one?
list_conversationsread · allowed
Six are waiting. The oldest is Hina R., 2 days — she asked about Saturday availability. I've sent her the slots.
delete_accountnever available

Refused, not silently emptied. Account deletion, ownership transfer, role changes and credentials are off at every configuration — including for an owner.

Activity log
list_conversationsstatus:open, limit:20ok
send_messageconversation_id:uuid, text[97]ok
delete_accountdenied

text[97] is the whole record of that message — its length, never its contents.

It acts as you, and never more

An owner gets owner reach. A front-desk agent gets front-desk reach. A doctor gets clinic tools scoped to their own patients. A viewer is read-only at every configuration, no matter what they switch on. The MCP session runs as a real user, so every database policy behaves exactly the way it does when that person is clicking around the dashboard — the guarantee is not a check we remembered to write, it is the same mechanism the app already runs on.

  • Five layers must all pass before a tool is even offered
  • Four of them decide what the model may ask for
  • The fifth — the database — decides what it may actually see

Read-only until you say otherwise

A brand-new connection has the read tools on and everything that writes off. From there every tool is individually switchable, so you can grant exactly the job you want done and nothing adjacent to it. Tools above your role are shown disabled with the reason given — a ceiling you might one day cross is worth seeing. Tools outside your job are not shown at all, because a whole side of the business that isn't your work is just noise.

Some things are never on the menu

Account deletion, ownership transfer, changing who is a member or what role they hold, and anything touching credentials — API keys, other MCP connections, AI provider keys, channel configuration. These are unavailable at every configuration, including to an owner. They are either irreversible, or they are changes to authority rather than to business data, and a model steered by text that someone else wrote into a conversation must not be able to reach them.

A log that answers 'who', not 'what they said'

Every call records which connection, which person, which tool, the outcome, and the role it ran as — plus a redacted summary of the arguments built from a per-tool whitelist. Message bodies, notes, phone numbers, emails and clinical values are never stored; a text argument is recorded only as its length. The log answers who read or changed what, and when. It deliberately cannot answer what it said.

Set up in about a minute

Create a named connection, choose its toolset, and paste the URL into your client. The URL is shown exactly once and only a short prefix is kept afterwards, so nobody — including us — can recover it later. Expiry is mandatory, ninety days by default, and regenerating kills the old URL the moment you confirm.

Questions

Frequently asked

Explore more

Works well with

Want to see it running on your own data?

Book a demo and we'll connect Claude to a real account, with a real toolset, and show you what it can and cannot reach.