Your platform exposes an MCP endpoint, which lets an AI assistant work with your CRM, your project boards, your help desk and your knowledge base. This page covers how to set it up and how to keep it sensible.
What you need #
- An MCP-capable client. Claude, Claude Code, Cursor and Codex all work.
- A business plan with your AI supplier, not a free or consumer plan. This matters for the data processing agreement.
- Five minutes.
Step 1: create a user for the assistant #
Do not connect as yourself. Create a separate user in your platform and give it the narrowest role that still does what you want. The connection inherits that user’s permissions exactly, so the role is your control.
Our advice for the first weeks: a role that can read but not write. Most of the value is in reading.
Step 2: generate an application password #
In the profile of that user, generate an application password. Copy it once, because it is not shown again. This is a key you can revoke at any moment without changing anyone’s login password.
Step 3: copy the configuration #
The settings screen generates a ready-made configuration block for Claude Desktop, Claude Code, Cursor and Codex. Paste it into your client’s configuration and restart the client.
Step 4: check what it can see #
Ask it something read-only first. “How many contacts do we have, and how many were added in the last thirty days?” If it answers with numbers that match what you see in your own dashboard, the connection is right.
Keeping it sensible #
Approve anything irreversible. Let the assistant draft and propose. You approve what sends, charges or deletes. Not because it is careless, but because instructions are ambiguous and consequences are not.
Widen access slowly. When you have watched it get something right ten times, allow it to do that thing. Not before.
Watch for instructions inside content. Your assistant reads text other people wrote: tickets, form submissions, reviews. If someone puts instructions in that text, they land in the same context as yours. Read-only access removes most of this risk, and human approval removes most of the rest.
The GDPR side #
When personal data reaches your AI supplier, that supplier becomes a processor for you, not for us. So: a business plan with a data processing agreement, training on your data switched off, the supplier added to your processing register, and a mention in your own privacy statement.
We help with the technical side. The paperwork is yours, and it is not much.
Revoking access #
Delete the application password in the user’s profile. The connection stops immediately. Nothing else is affected.