Playbooks: how to apply it
Playbook: connect your AI assistant safely with MCP
MCP is an open standard that lets an AI assistant connect to your email, your CRM, your files and other software. That lets it do much more for you, and it also reaches everything the connection can reach. Five steps to connect it so you know what it is allowed to do.
Sound familiar?
- A colleague connected an AI assistant to the shared mailbox, using their own login.
- You find a useful connector online and do not know who made it.
- Nobody can say what the assistant did in your CRM yesterday.
Step 1. Write down what each connection may do
Split what an assistant can do into reading, preparing and executing. Reading is opening an email or a file. Preparing is making a draft that someone else sends. Executing is sending, paying, changing or deleting. Start every connection at reading, and only move up once you know what it does.
Step 2. Give every connection its own key
Never connect with your own admin account. Create a separate account or key per connection, with only the permissions from step 1. Where possible, sign in through a consent screen (OAuth), so no key sits in a configuration file. Then you can revoke one connection without touching the rest.
Step 3. Treat everything that comes in as data
An email, attachment or web page can contain text that makes the assistant do something you never asked for. This is called prompt injection, and OWASP puts it at the top of its list of risks for language models. So have every action that sends, pays or deletes something confirmed first, especially when the trigger came from outside.
Step 4. Only use connectors from a known maker
An MCP server is software that can reach your data. Choose connectors from the vendor itself or from a party you know, read which functions it offers, and pin it to a version. An update can add functions you never chose.
Step 5. Record what happens
Keep a record of every call: which function, with what input, when and for whom. For the first weeks, check each week that the assistant only did what you expected. Keep one list of all your connections, with how to revoke each one.
What it costs
MCP is an open standard and costs nothing. The time goes into the permissions per connection and keeping the list up to date. That time is smaller than cleaning up after an assistant that could do more than you thought.
How we do it ourselves
ConcurrentieRadar has its own MCP server. You sign in through a consent screen, reading and starting a scan are separate permissions, and addresses pointing to internal networks are refused. For our own AI employees, incoming email counts as data, and an email to a customer only goes out after approval.
Frequently asked questions
How is this different from a regular API integration?
An API integration does one fixed task that someone built. Through MCP the assistant chooses which function to call. That is why the permissions per connection matter more.
Does this work with ChatGPT or Claude?
Yes. Both can work with MCP connectors. The steps are the same.
Read on
In this series
Our approach
From advice to management, with one partner
The same rhythm for every project.
Advice
We start with a conversation, not with code. First clarity on what you need and what you do not.
Build
We build and integrate to measure, with technology that fits you. You own your data and your code.
Manage
We stay involved: monitoring, adjusting and growing with your business.
Do you know what your assistant is allowed to do?
Call us and we will go through your connections together.
Call 085 083 5775A 30-minute intake