What is an MCP server? How the Model Context Protocol connects AI to your systems

An MCP server is a program that lets an AI assistant, such as Claude or ChatGPT, read from and act in one of your company’s systems. It follows the Model Context Protocol (MCP), which Anthropic released in November 2024 as “a new standard for connecting AI assistants to the systems where data lives.” The server lists what the assistant may do, such as look up an order in the ERP or search the shared drive for a drawing, and the account it runs under decides which records the assistant can reach. This guide explains how MCP works, how to set permissions and approvals on an MCP server, whether to build or buy one, and what it means for a smaller manufacturer or distributor.

Inside a CNC turning centre, a steel shaft held between the chuck and the tailstock while a milling tool with gold inserts cuts it

What is the Model Context Protocol (MCP)?

A protocol is a set of rules that two programs follow to exchange messages. The MCP project defines the Model Context Protocol as “an open-source standard for connecting AI applications to external systems,” and compares it to a USB-C port for AI applications.

Anthropic introduced MCP on November 25, 2024, to fix a specific problem: “Every new data source requires its own custom implementation, making truly connected systems difficult to scale.” With MCP, a system needs one server, and each AI application that supports the protocol can connect to it. On December 9, 2025, Anthropic donated MCP to the Linux Foundation’s Agentic AI Foundation, which Anthropic, Block and OpenAI co-founded. By then, Anthropic said, ChatGPT, Cursor, Gemini, Microsoft Copilot and Visual Studio Code had adopted it. The specification is versioned by date, and its current version on September 28, 2026 was 2026-07-28.

Host, client and server

MCP’s architecture guide names three parts. The host is “The AI application that coordinates and manages one or multiple MCP clients,” such as Claude Desktop or Visual Studio Code. A client is the connection the host keeps with one server. The server is “A program that provides context to MCP clients,” meaning the information and actions a model can use.

A server for a business system often sits in front of that system’s API, the connection one program uses to call another. The model never connects to your ERP itself: the host carries each call to the server and brings back what it returns.

Tools, resources and prompts

A server can offer three kinds of things. Tools are actions the AI can call, such as a database query, and the specification calls them “model-controlled” because the model decides when to call one. Resources are data the AI can read for context, such as a file or a database record. Prompts are reusable instructions, such as a template for comparing two supplier quotes. Clients support different parts of the protocol: Microsoft says Copilot Studio supports tools and resources, and Anthropic says Claude implements a subset of the specification.

Local and remote MCP servers

A local server runs on the same computer as the AI application, and the architecture guide says it typically serves one client. A remote server runs elsewhere, is reached over the web through a transport called Streamable HTTP, and typically serves many. For remote servers, the guide says “MCP recommends using OAuth to obtain authentication tokens.” OAuth is the standard that lets a person approve an application’s access to an account without giving it a password. The application receives a token, a temporary key tied to that approval.

How an MCP server connects AI to your ERP, email and files

Take a buyer who asks an assistant which open purchase orders for a part are late. Following the flow in the architecture guide, the request runs in four steps:

  1. The host asks each connected server for its tools, and the ERP server lists tools such as “list purchase orders.”
  2. The model picks a tool and fills in the part number.
  3. The host sends the call to the ERP server, after asking the person to approve it if the tool changes data.
  4. The server calls the ERP with the permissions it holds and returns the rows, and the model writes the answer from them.

The same pattern works for a shared mailbox, a drive of drawings or a quality database. Each system gets its own server, and each server offers only the tools you choose.

An ERP example: Microsoft Dynamics 365 Business Central

Microsoft’s MCP server for Business Central online follows the pattern this guide recommends. “By default, the Business Central MCP server provides read-only access to all exposed Business Central API pages,” says its overview. An API page is a set of records, such as items or customers, that Business Central offers to other programs. To allow writes, an administrator grants separate permissions for each API page to create, modify, delete and run bound actions, such as posting a document. Microsoft adds that “All operations are performed with your user identity and permissions, ensuring audit trails show who performed each action.”

What to expose first, system by system

The table is our starting point for a plant or distributor, and your own review of each system decides the final list.

SystemRead tools to start withWrite tools to add later, one at a timeWho approves a write
ERPOrder status, stock on hand, open purchase orders and price listsCreate a draft quote or a draft purchase orderThe buyer or sales rep who owns the document, before it is posted
Shared mailboxSearch and read threads in one shared mailboxSave a draft replyThe person who sends it
Shared driveSearch drawings, specifications and procedures by part numberFile a document in a named folderThe owner of the folder
Quality or production databaseRead-only queries on a view, a saved query limited to the fields you chooseUsually noneNot applicable

MCP server security: permissions and approvals

The MCP specification says “Hosts must obtain explicit user consent before invoking any tool,” and also that “MCP itself cannot enforce these security principles at the protocol level.” Protection comes from how the server and the host are set up. For the account settings inside each AI tool, see secure AI at work.

Start read-only

Give the first version of a server read tools only. The MCP project’s security best practices recommend a “minimal initial scope set” containing “only low-risk discovery/read operations,” with more access requested when a privileged operation is first attempted. A scope is one named permission inside a token, such as permission to read orders.

Add write actions one at a time

Once the read tools give correct answers, add one write tool, such as creating a draft quote, and watch how people use it before you add the next. A narrow tool that creates a draft for review is easier to check than one that can edit any record. OpenAI’s guide to building MCP servers says to “Keep approval enabled for tools that can modify data or take other consequential actions.”

Give each person their own permissions

Each person should reach a system through the server with their own sign-in, so the AI opens only what that person can open. In Claude Team and Enterprise, once an Owner adds a connector, “users individually connect to and enable that connector,” which Anthropic says ensures “that Claude can only access tools and data that the individual user has access to.” The security best practices add that the authorization specification forbids token passthrough, where a server forwards a person’s token unchanged to another system, and state: “MCP servers MUST NOT accept any tokens that were not explicitly issued for the MCP server.” Avoid one shared login for write tools as well, because the ERP then records every change under one name.

Require approval before actions

The tools specification says “there SHOULD always be a human in the loop with the ability to deny tool invocations.” OpenAI’s API asks first: “By default, OpenAI will request your approval before any data is shared with a connector or remote MCP server.” For a business, the approval belongs to the person who owns the result, such as the buyer who signs a purchase order. Human in the loop explains how to design that step.

Watch for prompt injection and untrusted servers

Prompt injection is an attack in which someone hides instructions in content the model reads, such as a web page or an email, so that the model follows them. Claude Code’s documentation says: “Verify you trust each server before connecting it. Servers that fetch external content can expose you to prompt injection risk.” OpenAI warns that “A malicious server can exfiltrate sensitive data from anything that enters the model’s context,” meaning copy it out, and that “data sent to an MCP server is subject to their data retention and data residency policies.” Local servers need the same care, because they “may have direct access to the user’s system.” AI security covers the wider picture.

A setting to check

Anthropic tells Claude users to “only click ‘Allow always’ when using a server and tool that you trust to run unsupervised.” Leave approval on for any tool that sends, posts or deletes.

Which system to connect first

Tell Derik which systems your team works in every day. He will suggest which one to connect first and which tools to start with.

Start a conversation

MCP in Claude, ChatGPT and Copilot Studio

In Claude, an MCP server appears as a connector, and Anthropic’s developer documentation says Claude connects to one “from claude.ai, Claude Desktop, Claude mobile, Cowork, and Claude Code.” A user or an organization Owner adds a remote server as a custom connector by entering its URL, “with no review by Anthropic,” while servers listed in Anthropic’s directory are reviewed. In Claude Code, a developer adds servers from the command line. OpenAI recommends that you “do not connect to a custom MCP server unless you know and trust the underlying application.” The business plans of these assistants are compared in ChatGPT alternatives for business in Canada.

ProductHow it connects to MCP serversControls the vendor documents, checked September 28, 2026
Claude (claude.ai, Claude Desktop, Cowork, Claude Code)Remote servers as custom connectors on the Free, Pro, Max, Team and Enterprise plans, with one custom connector on Free (Anthropic). Claude Code also runs local serversTool approval requests with an “Allow always” choice. On Team and Enterprise, an Owner adds the connector and each user connects with their own account
OpenAI APIAn MCP tool in the Responses API calls remote servers, and an allowed_tools setting limits which of a server’s tools the model sees (OpenAI)Approval before data is shared with a server, on by default. A developer can turn it off for named tools or for a whole server
Microsoft Copilot StudioAgents connect to an existing server through a wizard, over the Streamable HTTP transport, and use its tools and resources (Microsoft)Authentication by API key, by OAuth 2.0 or none. The customer is responsible for the tools and resources it uses from an external server

Build or buy an MCP server

Use the server your software vendor publishes

Check first whether the vendor of your ERP, your CRM (the system that tracks customers and sales) or your document system publishes an MCP server. A vendor’s own server follows that product’s permissions, as Microsoft’s does for Business Central. OpenAI’s guide gives the same advice: “choose official servers hosted by the service providers themselves.”

The official MCP Registry, in preview, lists publicly accessible servers and “delegates security scanning” to package registries and marketplaces, so review a server’s code and permissions yourself before you connect it. The project’s own reference servers are “educational examples for developers building their own MCP servers,” and the project says they are not production-ready.

Build your own

Build a server when a system has no vendor server, when it is custom or old, or when you want tighter limits than the vendor’s server offers. The MCP project publishes official software development kits (SDKs), code libraries that handle the protocol, in ten languages, including Python, TypeScript, C# and Java. For an older ERP without a modern API, a server can read from a database view or a scheduled export, and legacy ERP automation covers agents that work through the ERP’s own screens. Keep tool results small: Claude caps one at about 150,000 characters on claude.ai and stops a tool call after 240 seconds, according to its connector documentation.

Questions to ask before you connect any MCP server

  1. Who runs the server, and where? Everything the server returns passes through it.
  2. Which tools does it offer? Ask for the list, and whether each tool reads or writes.
  3. Whose account does each call use? Ask whether each person signs in or the server uses one shared login.
  4. Which tools ask for approval? Every tool that sends, posts or deletes should wait for a named person.
  5. Where does our data go? The server’s operator and the model provider each keep data under their own rules, and private AI for business lists what to ask each one.
  6. Is every call logged? The specification tells clients to “Log tool usage for audit purposes.”

What MCP means for a smaller manufacturer or distributor

Most of what a plant or distributor knows sits in systems a chat window cannot see, such as the ERP, shared mailboxes and the drawings drive. An MCP server gives an assistant a controlled way into each one, so a customer service rep can ask for an order’s status in plain words.

MCP carries data between a system and a model, and where the model runs is a separate decision. An MCP server can sit on your own server in Canada while the assistant that calls it uses a hosted model that processes requests in another country. Sovereign AI and private AI for business cover where each step runs, local LLM covers running the model on your own hardware, and Claude API pricing shows what a hosted model costs per request.

MCP also differs from retrieval. Retrieval-augmented generation (RAG) searches a library of documents, such as procedures, and an MCP tool asks a live system for a current value, such as today’s stock of a part. What is RAG explains the first, and fine-tuning covers further training a model on your own examples.

A good first project connects one system with read tools only, for one team, and checks how often the answers match the ERP before adding a write action. How to build an AI agent lays out the steps. AI for manufacturing, industrial AI and AI for supply chain show where assistants help.

Questions people ask

What is an MCP server?
An MCP server is a program that gives an AI application access to one system, such as an ERP, a shared mailbox or a database, through the Model Context Protocol. It lists the tools the AI can call and the data it can read, and it acts with the permissions it has been given.
What is the Model Context Protocol?
The Model Context Protocol (MCP) is an open-source standard for connecting AI applications to external systems. Anthropic released it on November 25, 2024, and donated it to the Linux Foundation's Agentic AI Foundation on December 9, 2025. Claude, ChatGPT, Microsoft Copilot Studio and Visual Studio Code are among the applications that support it.
How do I add an MCP server to Claude?
On claude.ai and in Claude Desktop, add a remote server as a custom connector by entering its URL. Custom connectors are available on the Free, Pro, Max, Team and Enterprise plans, and Free users are limited to one. On Team and Enterprise plans, an Owner adds the connector and each user then connects to it.
Is an MCP server safe to use with company data?
It can be, when it is set up with care. Start with read-only tools, give each person their own sign-in, have a named person approve any action that changes data, and connect only servers you trust. OpenAI warns that a malicious server can exfiltrate sensitive data, and Anthropic warns that servers that fetch outside content can expose you to prompt injection.
What is the difference between an MCP server and an API?
An API is the connection a system offers to other programs, and each system's API has its own format. An MCP server often sits in front of an API and describes its actions in one standard format that any MCP-compatible AI application can discover and call. The system behind the API still applies its own rules and permissions.
Does ChatGPT support MCP?
OpenAI supports MCP. Its Responses API has an MCP tool that calls remote MCP servers, and by default OpenAI asks for approval before any data is shared with one. OpenAI's guide also covers connecting a custom MCP server to ChatGPT in developer mode.

How ThriveAI helps

ThriveAI is an AI engineering company in Ottawa. It builds private AI systems on the client’s own data for manufacturers and distributors in Ontario and Quebec, connected to the systems each company runs on, such as the ERP and shared mailboxes. Derik Lawlis, the founder, leads every project and stays close to the build.

The platform is designed to keep each client’s data on its own server in Canada. You choose the model that reads it: one on that server, or a hosted model under a written zero data retention agreement, under which the provider keeps no copy of a request or its answer. A hosted model may process requests outside Canada, so the contract names the model. Each connection starts read-only, and a named person at your company approves every action before anything is sent or saved. ThriveAI also runs hands-on AI training. Enterprise AI platform shows how the pieces fit together, and About ThriveAI covers the company.

Contact

Connect your AI assistant to one system first

Tell Derik which AI assistant your team uses and which system holds the answers it looks up most. He will tell you what an MCP server for that system should allow, and under which account.

Prefer to talk? Book a meeting.

Your message goes to Derik Lawlis, the founder.