Initial Setup
Connecting an AI assistant takes a few minutes. You add the platform as a custom connector in your assistant, then approve the connection with your own platform login and two-factor authentication.
What You Need
Section titled “What You Need”- The MCP module enabled on your platform. If it is not, contact support.
- MCP access on your account. Your data controller grants this per category of work, using the Access MCP user flags described in What you can grant. You only see the categories your account holds when approving a connection.
- Two-factor authentication (2FA) set up on your account. If you have not enrolled yet, use Setup 2FA on the main menu first.
- An MCP-capable assistant. Claude requires a plan that supports custom connectors; ChatGPT requires Developer mode and a plan that includes custom connectors. If the connection will reach personal customers, that plan also needs to be a commercial one: see Consumer accounts are not business accounts.
Find Your Connector Details
Section titled “Find Your Connector Details”Open the AI Assistants (MCP) page from the Advanced menu in the platform. It shows the two things every assistant needs:
- the connector URL for your platform
- the OAuth Client ID
The page also lists your existing connections, and will tell you if your account is missing MCP access or 2FA.
Connecting from Claude
Section titled “Connecting from Claude”- In claude.ai, open Settings -> Connectors and choose Add custom connector.
- Enter the connector URL shown on your AI Assistants (MCP) page.
- Open Advanced settings and enter the OAuth Client ID from the same page. Leave the secret blank.
- Add the connector, then choose Connect. A browser window will open on your platform: sign in as usual, enter your 2FA code, and choose Approve.
- In a conversation, enable the connector from the tools menu and ask a reporting question - for example, “Show invoice totals by month for this year”.
Connecting from ChatGPT
Section titled “Connecting from ChatGPT”- In ChatGPT, open Settings -> Security and Login and enable Developer mode (custom connectors need a plan that includes them).
- Open Settings -> Plugins, then choose + at the top right to add a connector. Enter the connector URL shown on your AI Assistants (MCP) page as the MCP server URL.
- Select OAuth authentication, open the Advanced OAuth settings, and enter the Client ID from the same page. Leave the secret blank.
- Create the connector and connect: a browser window will open on your platform. Sign in as usual, enter your 2FA code, and choose Approve.
- In a conversation, enable the connector from the tools menu before asking your reporting question.
Other Assistants
Section titled “Other Assistants”Any assistant that supports MCP connections with OAuth follows the same pattern: give it the connector URL and Client ID from your AI Assistants (MCP) page, and it will send you through the same platform sign-in and approval.
The Approval Screen
Section titled “The Approval Screen”When your assistant connects for the first time, the platform shows an approval page confirming who the connection will act as, with a tickbox for each thing you can grant.
What you can grant
Section titled “What you can grant”Permissions are grouped by the kind of work being done, rather than by which records get touched. This means you can let an assistant chase overdue accounts without also letting it cease live services.
Read access (offered pre-ticked):
| Grant | What it allows |
|---|---|
| Reporting - KPIs | Aggregate figures only, no individual records |
| General Records - Read | Look up and search individual records |
| Pre-Sales - Read | Read deals, proposals and their context |
| Credit Control - Read | Read cases and overdue-account context |
Write and send access (every one unticked by default):
| Grant | What it allows | Needs |
|---|---|---|
| General Records - Routine record keeping | Create and update everyday records | General Records read |
| Pre-Sales - Manage deals and proposals | Manage deals, including sending a proposal | Pre-Sales read |
| Credit Control - Manage cases | Cases, promises, arrangements and case communications | Credit Control read |
| Customer Interaction - Send | Send bills, CDRs, correspondence and customer links | General Records read |
| Pre-Sales Outreach | Campaigns and automated sequences | Pre-Sales read |
| Customer and Service Lifecycle | Create, activate, suspend, reinstate and cease live services | General Records read |
| Financial | Raise charges and invoices, collect payments, refund and write off balances | General Records read |
Data-scope access (every one unticked by default):
| Grant | What it allows | Needs |
|---|---|---|
| Personal Customers | Include records for customers not explicitly classified as businesses | - |
| Call Data - Aggregate summaries | Read-only call totals: call counts, duration, data usage, retail and wholesale cost | - |
| Call Data - Full per-call detail | Read-only access to individual call records | - |
Two boundaries are worth knowing, because they are not where people assume:
- Sending a proposal is Pre-Sales, not Customer Interaction. A connection set up for sales work can send proposals without being able to email bills.
- Sending a bill is Customer Interaction, and it carries the collection behaviour configured for that bill. You do not need to grant Financial for a bill to be sent and collected in the normal way; Financial is for raising charges, refunds and write-offs.
Personal customers
Section titled “Personal customers”Without the Personal Customers grant, a connection only sees individual records belonging to customers whose customer class is marked as a business. Records for personal customers, and for customers whose class does not say either way, are left out of record lookups, lists and searches. Aggregate KPI figures are unaffected: they still count everybody.
Consumer accounts are not business accounts
Section titled “Consumer accounts are not business accounts”Paying for a subscription on the company card does not make it a commercial account. Individual subscriptions are consumer plans whoever settles the bill, and they are not suitable for customers’ personal data:
| Not suitable (consumer plans) | Suitable (commercial plans) |
|---|---|
| Claude Free, Pro, Max | Claude Team, Enterprise |
| ChatGPT Free, Go, Plus, Pro | ChatGPT Business, Enterprise, Edu |
The difference is the contract, not the price. A commercial plan is bought by your organisation, comes with a Data Processing Agreement naming your organisation as controller, keeps your conversations out of model training by default, and gives your administrators control over retention and access. An individual plan gives the person, not your organisation, the relationship with the provider, and the account leaves with them.
A commercial plan is the prerequisite, not the whole job: check that the Data Processing Agreement is actually in place. The two providers differ here.
- OpenAI expect you to execute the DPA yourself. Signing up for ChatGPT Business does not put one in place: someone in your organisation has to complete the form on OpenAI’s Data Processing Addendum page, giving your legal entity and signatory details, before personal data goes anywhere near the account. A negotiated Enterprise Agreement may already include it, in which case check the signed contract rather than assuming either way.
- Anthropic incorporate their DPA into the Commercial Terms of Service automatically, so accepting those terms with a Claude Team or Enterprise plan accepts the DPA with them. Nothing separate needs signing. See Anthropic’s note on viewing the DPA.
Confirm the current position with the provider and your own data controller rather than relying on this page: both providers revise their terms from time to time.
If you are not certain which plan an account is on, or whether a DPA has been executed, treat it as consumer and leave Personal Customers unticked. The business-only categories still work perfectly well without it, and your data controller can confirm the position before it is granted.
Call data
Section titled “Call data”Call access is separate from ordinary record access, and both grants are read-only.
- Aggregate summaries let the assistant total calls over a date range and group them by period, direction, call type, rating period, number type, dealer or site. Platform, dealer and site totals need nothing else. Summaries tied to a specific customer, number, service, feature, invoice or transaction also need General Records read, and the Personal Customers grant where that customer is a personal one.
- Full per-call detail lets the assistant list and open individual call records. Calls belonging to personal customers are excluded unless Personal Customers is also granted.
Your own call permissions still apply on top: an account that cannot see call records in the platform cannot see them through an assistant either.
How the grants combine
Section titled “How the grants combine”A connection can only do something if all three of these permit it:
- Your own user account holds the category
- The connection was granted the category at approval
- The platform’s MCP settings user permits the category, which acts as a site-wide kill switch
On top of that, your ordinary object permissions still apply. Granting Financial does not let an assistant touch records you could not touch yourself.
Enter the current code from your authenticator app and choose Approve. If you did not initiate the connection from your assistant, choose Deny.
You will receive a confirmation email whenever a connection is approved with your account. If you receive one you do not recognise, revoke the connection straight away and reset your password and 2FA.
What’s Next
Section titled “What’s Next”- Using AI assistants - example questions, what the assistant can see, and managing your connections