
The Model Context Protocol (MCP) is an open standard for connecting AI assistants and agents to the tools and data they need, such as a CRM, an ERP, a file store or a database. Anthropic introduced it in November 2024. You expose a system once as an MCP server, and any MCP-compatible AI application can discover what it offers and use it through the same interface.
For business teams, MCP matters because the hard part of useful AI is rarely the model. It's the integration: giving an AI system safe, permissioned access to the systems where your work actually happens. This guide explains how MCP works, what it changes and what to watch for on security.
What Problem Does MCP Solve?
MCP solves the "many-to-many" integration problem between AI applications and business systems. Without a standard, every AI tool needs its own connector to every system.
Picture five AI applications (a chat assistant, a coding tool, a support agent, a sales copilot, an internal agent) and ten systems (CRM, ERP, helpdesk, file storage, database, calendar and so on). Custom integrations mean up to fifty connectors, each built and maintained separately. With MCP, each system is wrapped once as a server, and each AI application implements the client side once. The integration effort grows with the number of systems plus the number of AI apps, not their product.
People often compare MCP to USB-C for AI: one standard plug instead of a drawer full of adapters. The comparison is useful as long as you remember that a standard plug doesn't make what you connect safe. That still takes engineering.
How Does MCP Work?
MCP uses a client-server architecture with three roles: hosts, clients and servers. Messages are exchanged as JSON-RPC 2.0.
- Host. The AI application the user interacts with, such as a desktop assistant, an IDE or your own agent platform.
- Client. A component inside the host that maintains a connection to one MCP server.
- Server. A program that exposes a system's capabilities in MCP format. It might wrap Salesforce, a PostgreSQL database, a document store or an internal API.
What can an MCP server offer?
Servers expose three main kinds of capability:
| Primitive | What it is | Business example |
|---|---|---|
| Tools | Actions the model can call, with a name, description and input schema | create_invoice, update_deal_stage, search_tickets |
| Resources | Data the application can read and pass to the model as context | A customer record, a policy document, a database schema |
| Prompts | Reusable prompt templates the server provides | "Summarize this account," "Draft a renewal email" |
The protocol also lets servers ask the host for help. For example, a server can request a model completion (sampling) or ask the user for missing input (elicitation), with the host staying in control of what is allowed.
How do clients and servers connect?
MCP supports two standard transports:
- stdio for local servers running on the same machine as the host, common for developer tools.
- Streamable HTTP for remote servers, which is how most business integrations are deployed. Remote servers can use the OAuth 2.1-based authorization flow defined in the specification.
When a client connects, it asks the server what tools, resources and prompts it offers. The descriptions are written for a language model to read, so the AI can decide when and how to use each tool without the developer hard-coding every case.
Why Does MCP Matter for Connecting Agents to CRMs and ERPs?
MCP turns your business systems into reusable building blocks for any AI agent or assistant you adopt, now or later. That has four practical benefits.
- Build once, reuse everywhere. An MCP server for your ERP can serve a finance copilot, a procurement agent and an executive assistant without three separate integrations.
- Less vendor lock-in. MCP is open and supported by several AI providers and tools. If you switch models or AI platforms, your integrations can come with you.
- Consistent controls. Permissions, logging and rate limits live in the server, in one place, instead of being reimplemented in each AI tool.
- Faster pilots. Many software vendors now publish official MCP servers for their products, and open-source servers exist for common databases and tools. A pilot can start from those and add custom servers only for internal systems.
A typical pattern for an enterprise agent looks like this: the agent runs on your agent platform (the host), connects to MCP servers for the CRM, ERP, helpdesk and document store, and calls their tools under the identity and permissions of the user it is acting for. Our enterprise solutions team builds and integrates the systems on that side of the connection, and our AI agent development team builds the agents that use them.
MCP vs other integration approaches
| Approach | What it is | Strength | Limitation |
|---|---|---|---|
| Direct API integration | Custom code calls each system's API | Full control, no extra layer | Rebuilt for every AI app and model |
| Function calling only | Tools defined inside one application | Simple for a single agent | Tools aren't shareable across apps |
| Vendor plugin ecosystems | Integrations for one AI product | Easy inside that product | Locked to that product |
| MCP | Open protocol for tools, data and prompts | Reusable across hosts and models | Another layer to secure and operate |
MCP doesn't replace your APIs. An MCP server is usually a thin, well-designed layer over the same REST or GraphQL APIs your other software already uses.
What Are the Security Considerations?
MCP makes it easier to connect AI to powerful systems, so security has to be designed in from the start. The protocol defines authorization patterns, but the safety of a deployment depends on how servers are built, chosen and governed.
Key risks and controls:
- Prompt injection through data. A ticket, email or web page returned by a tool can contain instructions aimed at the model. Treat tool output as untrusted data, keep high-impact actions behind human approval and limit what each tool can do.
- Malicious or tampered servers. Tool descriptions are read by the model, so a malicious server can try to steer it ("tool poisoning"), or a server can change behavior after you approved it. Use servers from trusted publishers, pin versions, review tool descriptions and maintain an allowlist.
- Over-broad access. A server with an admin token gives every user admin power through the AI. Use OAuth with narrow scopes, act on behalf of the actual user and enforce permissions in the server, not in the prompt.
- Token handling. Never pass a user's token straight through to downstream services or store secrets in tool descriptions or logs. Keep credentials in a secrets manager.
- Local servers. A stdio server runs with the permissions of the user who launched it. Only install local servers you trust, as you would any software.
- Visibility. Log every tool call with the user, arguments, result and approval. Route MCP traffic through a gateway if you need central policy, rate limiting and monitoring.
Our application security practice reviews AI integrations, including MCP servers, as part of secure development.
How Should a Business Start With MCP?
Start with one agent use case and the two or three systems it needs, rather than wrapping every system up front.
- Choose the use case. For example, a support agent that reads order data and drafts replies.
- List the actions it needs. Keep tools narrow:
get_orderis safer thanrun_sql. - Check for official servers. Use a vendor's MCP server if it meets your security bar; build custom servers for internal systems.
- Design permissions. Read-only first, then write actions with approvals and limits.
- Test with evals and red-teaming. Include injection attempts in your test set.
- Operate it. Monitor tool calls, cost and errors, and review logs regularly.
If terms like tools, guardrails or evals are new, our AI glossary defines them in plain English, and what is agentic AI explains how agents use these connections.
Connect Your Systems to AI, Safely
Aaga is an AI-native engineering team that builds agents and the integrations behind them, using our own platform for workflows, permissions and connectors so the basics are not rebuilt for every project. If you want an agent to work with your CRM, ERP or internal tools, book a free consultation and we'll scope a pilot around one workflow, with security designed in from the first release.

