What is an MCP server? How the Model Context Protocol connects AI to your systems
An MCP server is a program that lets an AI assistant, such as Claude or ChatGPT, read from and act in one of your company’s systems. It follows the Model Context Protocol (MCP), which Anthropic released in November 2024 as “a new standard for connecting AI assistants to the systems where data lives.” The server lists what the assistant may do, such as look up an order in the ERP or search the shared drive for a drawing, and the account it runs under decides which records the assistant can reach. This guide explains how MCP works, how to set permissions and approvals on an MCP server, whether to build or buy one, and what it means for a smaller manufacturer or distributor.

What is the Model Context Protocol (MCP)?
A protocol is a set of rules that two programs follow to exchange messages. The MCP project defines the Model Context Protocol as “an open-source standard for connecting AI applications to external systems,” and compares it to a USB-C port for AI applications.
Anthropic introduced MCP on November 25, 2024, to fix a specific problem: “Every new data source requires its own custom implementation, making truly connected systems difficult to scale.” With MCP, a system needs one server, and each AI application that supports the protocol can connect to it. On December 9, 2025, Anthropic donated MCP to the Linux Foundation’s Agentic AI Foundation, which Anthropic, Block and OpenAI co-founded. By then, Anthropic said, ChatGPT, Cursor, Gemini, Microsoft Copilot and Visual Studio Code had adopted it. The specification is versioned by date, and its current version on September 28, 2026 was 2026-07-28.
Host, client and server
MCP’s architecture guide names three parts. The host is “The AI application that coordinates and manages one or multiple MCP clients,” such as Claude Desktop or Visual Studio Code. A client is the connection the host keeps with one server. The server is “A program that provides context to MCP clients,” meaning the information and actions a model can use.
A server for a business system often sits in front of that system’s API, the connection one program uses to call another. The model never connects to your ERP itself: the host carries each call to the server and brings back what it returns.
Tools, resources and prompts
A server can offer three kinds of things. Tools are actions the AI can call, such as a database query, and the specification calls them “model-controlled” because the model decides when to call one. Resources are data the AI can read for context, such as a file or a database record. Prompts are reusable instructions, such as a template for comparing two supplier quotes. Clients support different parts of the protocol: Microsoft says Copilot Studio supports tools and resources, and Anthropic says Claude implements a subset of the specification.
Local and remote MCP servers
A local server runs on the same computer as the AI application, and the architecture guide says it typically serves one client. A remote server runs elsewhere, is reached over the web through a transport called Streamable HTTP, and typically serves many. For remote servers, the guide says “MCP recommends using OAuth to obtain authentication tokens.” OAuth is the standard that lets a person approve an application’s access to an account without giving it a password. The application receives a token, a temporary key tied to that approval.
How an MCP server connects AI to your ERP, email and files
Take a buyer who asks an assistant which open purchase orders for a part are late. Following the flow in the architecture guide, the request runs in four steps:
- The host asks each connected server for its tools, and the ERP server lists tools such as “list purchase orders.”
- The model picks a tool and fills in the part number.
- The host sends the call to the ERP server, after asking the person to approve it if the tool changes data.
- The server calls the ERP with the permissions it holds and returns the rows, and the model writes the answer from them.
The same pattern works for a shared mailbox, a drive of drawings or a quality database. Each system gets its own server, and each server offers only the tools you choose.
An ERP example: Microsoft Dynamics 365 Business Central
Microsoft’s MCP server for Business Central online follows the pattern this guide recommends. “By default, the Business Central MCP server provides read-only access to all exposed Business Central API pages,” says its overview. An API page is a set of records, such as items or customers, that Business Central offers to other programs. To allow writes, an administrator grants separate permissions for each API page to create, modify, delete and run bound actions, such as posting a document. Microsoft adds that “All operations are performed with your user identity and permissions, ensuring audit trails show who performed each action.”
What to expose first, system by system
The table is our starting point for a plant or distributor, and your own review of each system decides the final list.
| System | Read tools to start with | Write tools to add later, one at a time | Who approves a write |
|---|---|---|---|
| ERP | Order status, stock on hand, open purchase orders and price lists | Create a draft quote or a draft purchase order | The buyer or sales rep who owns the document, before it is posted |
| Shared mailbox | Search and read threads in one shared mailbox | Save a draft reply | The person who sends it |
| Shared drive | Search drawings, specifications and procedures by part number | File a document in a named folder | The owner of the folder |
| Quality or production database | Read-only queries on a view, a saved query limited to the fields you choose | Usually none | Not applicable |
MCP server security: permissions and approvals
The MCP specification says “Hosts must obtain explicit user consent before invoking any tool,” and also that “MCP itself cannot enforce these security principles at the protocol level.” Protection comes from how the server and the host are set up. For the account settings inside each AI tool, see secure AI at work.
Start read-only
Give the first version of a server read tools only. The MCP project’s security best practices recommend a “minimal initial scope set” containing “only low-risk discovery/read operations,” with more access requested when a privileged operation is first attempted. A scope is one named permission inside a token, such as permission to read orders.
Add write actions one at a time
Once the read tools give correct answers, add one write tool, such as creating a draft quote, and watch how people use it before you add the next. A narrow tool that creates a draft for review is easier to check than one that can edit any record. OpenAI’s guide to building MCP servers says to “Keep approval enabled for tools that can modify data or take other consequential actions.”
Give each person their own permissions
Each person should reach a system through the server with their own sign-in, so the AI opens only what that person can open. In Claude Team and Enterprise, once an Owner adds a connector, “users individually connect to and enable that connector,” which Anthropic says ensures “that Claude can only access tools and data that the individual user has access to.” The security best practices add that the authorization specification forbids token passthrough, where a server forwards a person’s token unchanged to another system, and state: “MCP servers MUST NOT accept any tokens that were not explicitly issued for the MCP server.” Avoid one shared login for write tools as well, because the ERP then records every change under one name.
Require approval before actions
The tools specification says “there SHOULD always be a human in the loop with the ability to deny tool invocations.” OpenAI’s API asks first: “By default, OpenAI will request your approval before any data is shared with a connector or remote MCP server.” For a business, the approval belongs to the person who owns the result, such as the buyer who signs a purchase order. Human in the loop explains how to design that step.
Watch for prompt injection and untrusted servers
Prompt injection is an attack in which someone hides instructions in content the model reads, such as a web page or an email, so that the model follows them. Claude Code’s documentation says: “Verify you trust each server before connecting it. Servers that fetch external content can expose you to prompt injection risk.” OpenAI warns that “A malicious server can exfiltrate sensitive data from anything that enters the model’s context,” meaning copy it out, and that “data sent to an MCP server is subject to their data retention and data residency policies.” Local servers need the same care, because they “may have direct access to the user’s system.” AI security covers the wider picture.
Anthropic tells Claude users to “only click ‘Allow always’ when using a server and tool that you trust to run unsupervised.” Leave approval on for any tool that sends, posts or deletes.
Which system to connect first
Tell Derik which systems your team works in every day. He will suggest which one to connect first and which tools to start with.
Start a conversationMCP in Claude, ChatGPT and Copilot Studio
In Claude, an MCP server appears as a connector, and Anthropic’s developer documentation says Claude connects to one “from claude.ai, Claude Desktop, Claude mobile, Cowork, and Claude Code.” A user or an organization Owner adds a remote server as a custom connector by entering its URL, “with no review by Anthropic,” while servers listed in Anthropic’s directory are reviewed. In Claude Code, a developer adds servers from the command line. OpenAI recommends that you “do not connect to a custom MCP server unless you know and trust the underlying application.” The business plans of these assistants are compared in ChatGPT alternatives for business in Canada.
| Product | How it connects to MCP servers | Controls the vendor documents, checked September 28, 2026 |
|---|---|---|
| Claude (claude.ai, Claude Desktop, Cowork, Claude Code) | Remote servers as custom connectors on the Free, Pro, Max, Team and Enterprise plans, with one custom connector on Free (Anthropic). Claude Code also runs local servers | Tool approval requests with an “Allow always” choice. On Team and Enterprise, an Owner adds the connector and each user connects with their own account |
| OpenAI API | An MCP tool in the Responses API calls remote servers, and an allowed_tools setting limits which of a server’s tools the model sees (OpenAI) | Approval before data is shared with a server, on by default. A developer can turn it off for named tools or for a whole server |
| Microsoft Copilot Studio | Agents connect to an existing server through a wizard, over the Streamable HTTP transport, and use its tools and resources (Microsoft) | Authentication by API key, by OAuth 2.0 or none. The customer is responsible for the tools and resources it uses from an external server |
Build or buy an MCP server
Use the server your software vendor publishes
Check first whether the vendor of your ERP, your CRM (the system that tracks customers and sales) or your document system publishes an MCP server. A vendor’s own server follows that product’s permissions, as Microsoft’s does for Business Central. OpenAI’s guide gives the same advice: “choose official servers hosted by the service providers themselves.”
The official MCP Registry, in preview, lists publicly accessible servers and “delegates security scanning” to package registries and marketplaces, so review a server’s code and permissions yourself before you connect it. The project’s own reference servers are “educational examples for developers building their own MCP servers,” and the project says they are not production-ready.
Build your own
Build a server when a system has no vendor server, when it is custom or old, or when you want tighter limits than the vendor’s server offers. The MCP project publishes official software development kits (SDKs), code libraries that handle the protocol, in ten languages, including Python, TypeScript, C# and Java. For an older ERP without a modern API, a server can read from a database view or a scheduled export, and legacy ERP automation covers agents that work through the ERP’s own screens. Keep tool results small: Claude caps one at about 150,000 characters on claude.ai and stops a tool call after 240 seconds, according to its connector documentation.
Questions to ask before you connect any MCP server
- Who runs the server, and where? Everything the server returns passes through it.
- Which tools does it offer? Ask for the list, and whether each tool reads or writes.
- Whose account does each call use? Ask whether each person signs in or the server uses one shared login.
- Which tools ask for approval? Every tool that sends, posts or deletes should wait for a named person.
- Where does our data go? The server’s operator and the model provider each keep data under their own rules, and private AI for business lists what to ask each one.
- Is every call logged? The specification tells clients to “Log tool usage for audit purposes.”
What MCP means for a smaller manufacturer or distributor
Most of what a plant or distributor knows sits in systems a chat window cannot see, such as the ERP, shared mailboxes and the drawings drive. An MCP server gives an assistant a controlled way into each one, so a customer service rep can ask for an order’s status in plain words.
MCP carries data between a system and a model, and where the model runs is a separate decision. An MCP server can sit on your own server in Canada while the assistant that calls it uses a hosted model that processes requests in another country. Sovereign AI and private AI for business cover where each step runs, local LLM covers running the model on your own hardware, and Claude API pricing shows what a hosted model costs per request.
MCP also differs from retrieval. Retrieval-augmented generation (RAG) searches a library of documents, such as procedures, and an MCP tool asks a live system for a current value, such as today’s stock of a part. What is RAG explains the first, and fine-tuning covers further training a model on your own examples.
A good first project connects one system with read tools only, for one team, and checks how often the answers match the ERP before adding a write action. How to build an AI agent lays out the steps. AI for manufacturing, industrial AI and AI for supply chain show where assistants help.
Questions people ask
What is an MCP server?
What is the Model Context Protocol?
How do I add an MCP server to Claude?
Is an MCP server safe to use with company data?
What is the difference between an MCP server and an API?
Does ChatGPT support MCP?
How ThriveAI helps
ThriveAI is an AI engineering company in Ottawa. It builds private AI systems on the client’s own data for manufacturers and distributors in Ontario and Quebec, connected to the systems each company runs on, such as the ERP and shared mailboxes. Derik Lawlis, the founder, leads every project and stays close to the build.
The platform is designed to keep each client’s data on its own server in Canada. You choose the model that reads it: one on that server, or a hosted model under a written zero data retention agreement, under which the provider keeps no copy of a request or its answer. A hosted model may process requests outside Canada, so the contract names the model. Each connection starts read-only, and a named person at your company approves every action before anything is sent or saved. ThriveAI also runs hands-on AI training. Enterprise AI platform shows how the pieces fit together, and About ThriveAI covers the company.