MCP & AI agents
The Agent Tools MCP server gives approved AI assistants a small set of narrow tools on top of the same governed APIs. The assistant never connects to a database directly.
Design rules we apply
- Act as the user. The MCP server exchanges the user's token for a downstream token, so the assistant sees only what that person may see.
- Read-only by default. Write actions produce drafts that a person approves.
- Cite everything. Tool results include record and page identifiers the assistant must cite.
- Minimize data. Mask sensitive fields and return summaries before full records.
- Log every call to the audit API and forward it to the SIEM.
Connecting a client
MCP client configuration
{
"mcpServers": {
"ironbrick-agent-tools": {
"type": "http",
"url": "https://<agency-gateway>/mcp",
"auth": "oauth2"
}
}
}Agency deployments register the MCP server with the agency IdP and allow-list which AI clients may connect. Contact us to set up a pilot.