Claude & MCP
Connect Claude to your account — on a leash
Paste a URL into Claude, Claude Code or any MCP client and work with your account in plain language. Ask what is outstanding, draft a reply, look up a customer, update a deal. Bounded, at every moment, by exactly what you could already do yourself.
- Works with Claude, Claude Code and any MCP client
- Never exceeds its creator's own authority
- Read-only until you say otherwise
- A redacted log of who read or changed what
Refused, not silently emptied. Account deletion, ownership transfer, role changes and credentials are off at every configuration — including for an owner.
It acts as you, and never more
An owner gets owner reach. A front-desk agent gets front-desk reach. A doctor gets clinic tools scoped to their own patients. A viewer is read-only at every configuration, no matter what they switch on. The MCP session runs as a real user, so every database policy behaves exactly the way it does when that person is clicking around the dashboard — the guarantee is not a check we remembered to write, it is the same mechanism the app already runs on.
- Five layers must all pass before a tool is even offered
- Four of them decide what the model may ask for
- The fifth — the database — decides what it may actually see
Read-only until you say otherwise
A brand-new connection has the read tools on and everything that writes off. From there every tool is individually switchable, so you can grant exactly the job you want done and nothing adjacent to it. Tools above your role are shown disabled with the reason given — a ceiling you might one day cross is worth seeing. Tools outside your job are not shown at all, because a whole side of the business that isn't your work is just noise.
Some things are never on the menu
Account deletion, ownership transfer, changing who is a member or what role they hold, and anything touching credentials — API keys, other MCP connections, AI provider keys, channel configuration. These are unavailable at every configuration, including to an owner. They are either irreversible, or they are changes to authority rather than to business data, and a model steered by text that someone else wrote into a conversation must not be able to reach them.
A log that answers 'who', not 'what they said'
Every call records which connection, which person, which tool, the outcome, and the role it ran as — plus a redacted summary of the arguments built from a per-tool whitelist. Message bodies, notes, phone numbers, emails and clinical values are never stored; a text argument is recorded only as its length. The log answers who read or changed what, and when. It deliberately cannot answer what it said.
Set up in about a minute
Create a named connection, choose its toolset, and paste the URL into your client. The URL is shown exactly once and only a short prefix is kept afterwards, so nobody — including us — can recover it later. Expiry is mandatory, ninety days by default, and regenerating kills the old URL the moment you confirm.
Questions
Frequently asked
Explore more
Works well with
Developer API
Account-scoped keys, from day one
Account-scoped API keys with granular scopes, per-key rate limits and a consistent response envelope — plus an honest account of what has shipped so far.
Learn moreAI copilot & assistant
Assistive today, autonomous when you're ready
Draft replies, summarise threads, and — when you're ready — let a configurable AI Assistant handle conversations with guardrails.
Learn moreSecurity & data isolation
Isolated by the database, not by a WHERE clause
Tenant isolation enforced by the database rather than by application code, encrypted secrets, verified webhooks — and the option to host it yourself.
Learn moreWant to see it running on your own data?
Book a demo and we'll connect Claude to a real account, with a real toolset, and show you what it can and cannot reach.