The Model Context Protocol (MCP) is an open standard for connecting AI applications to tools and data. Instead of writing custom integration code for every model and every system, you build one MCP server per system, and any MCP-capable agent can use it, within the permissions you give it.
StandardOpen protocol
PartsHost, client, server
Servers offerTools, resources, prompts
Remote authOAuth
Reference architecture
How the pieces fit together
Scroll sideways to see the whole diagram →The agent never talks to your systems directly. It calls tools on MCP servers, and each server decides what the agent may do.
Part
What it does
1 Plan and reason
The agent uses the LLM to decide the next step, which tool to call, and whether the result is good enough.
2 Tool calls
Each MCP client connects to one server. Servers describe their tools (actions), resources (data to read) and prompts.
Server permissions
A server exposes only what is needed: the directory server can look up users but not change them.
3 Policy and audit
Risky tools require approval, and every call, result and approval is written to the audit log.
Designing good MCP servers
One server per system, small and specific. A ticketing server with five clear tools beats one giant server with fifty.
Narrow tools. "Reset password for user X" is safer than "run any directory command".
Least privilege. Each server uses its own service account with only the rights its tools need.
Clear descriptions. The model chooses tools by their descriptions. Vague descriptions cause wrong tool use.
Authenticate remote servers. Remote MCP servers over HTTP should use OAuth-based authorisation, as the specification describes.
Trust carefully. Only connect servers you built or have reviewed. A malicious server can feed the agent harmful instructions.
Tell us the process you would like to automate and the systems it touches. We will come back with a plain view of what an agent could safely do, what should stay with people, and how to start small.