Skip to content

Initial Setup

Connecting an AI assistant takes a few minutes. You add the platform as a custom connector in your assistant, then approve the connection with your own platform login and two-factor authentication.

  • The MCP module enabled on your platform. If it is not, contact support.
  • MCP access on your account. Your data controller grants this per category of work, using the Access MCP user flags described in What you can grant. You only see the categories your account holds when approving a connection.
  • Two-factor authentication (2FA) set up on your account. If you have not enrolled yet, use Setup 2FA on the main menu first.
  • An MCP-capable assistant. Claude requires a plan that supports custom connectors; ChatGPT requires Developer mode and a plan that includes custom connectors. If the connection will reach personal customers, that plan also needs to be a commercial one: see Consumer accounts are not business accounts.

Open the AI Assistants (MCP) page from the Advanced menu in the platform. It shows the two things every assistant needs:

  • the connector URL for your platform
  • the OAuth Client ID

The page also lists your existing connections, and will tell you if your account is missing MCP access or 2FA.

  1. In claude.ai, open Settings -> Connectors and choose Add custom connector.
  2. Enter the connector URL shown on your AI Assistants (MCP) page.
  3. Open Advanced settings and enter the OAuth Client ID from the same page. Leave the secret blank.
  4. Add the connector, then choose Connect. A browser window will open on your platform: sign in as usual, enter your 2FA code, and choose Approve.
  5. In a conversation, enable the connector from the tools menu and ask a reporting question - for example, “Show invoice totals by month for this year”.
  1. In ChatGPT, open Settings -> Security and Login and enable Developer mode (custom connectors need a plan that includes them).
  2. Open Settings -> Plugins, then choose + at the top right to add a connector. Enter the connector URL shown on your AI Assistants (MCP) page as the MCP server URL.
  3. Select OAuth authentication, open the Advanced OAuth settings, and enter the Client ID from the same page. Leave the secret blank.
  4. Create the connector and connect: a browser window will open on your platform. Sign in as usual, enter your 2FA code, and choose Approve.
  5. In a conversation, enable the connector from the tools menu before asking your reporting question.

Any assistant that supports MCP connections with OAuth follows the same pattern: give it the connector URL and Client ID from your AI Assistants (MCP) page, and it will send you through the same platform sign-in and approval.

When your assistant connects for the first time, the platform shows an approval page confirming who the connection will act as, with a tickbox for each thing you can grant.

Permissions are grouped by the kind of work being done, rather than by which records get touched. This means you can let an assistant chase overdue accounts without also letting it cease live services.

Read access (offered pre-ticked):

GrantWhat it allows
Reporting - KPIsAggregate figures only, no individual records
General Records - ReadLook up and search individual records
Pre-Sales - ReadRead deals, proposals and their context
Credit Control - ReadRead cases and overdue-account context

Write and send access (every one unticked by default):

GrantWhat it allowsNeeds
General Records - Routine record keepingCreate and update everyday recordsGeneral Records read
Pre-Sales - Manage deals and proposalsManage deals, including sending a proposalPre-Sales read
Credit Control - Manage casesCases, promises, arrangements and case communicationsCredit Control read
Customer Interaction - SendSend bills, CDRs, correspondence and customer linksGeneral Records read
Pre-Sales OutreachCampaigns and automated sequencesPre-Sales read
Customer and Service LifecycleCreate, activate, suspend, reinstate and cease live servicesGeneral Records read
FinancialRaise charges and invoices, collect payments, refund and write off balancesGeneral Records read

Data-scope access (every one unticked by default):

GrantWhat it allowsNeeds
Personal CustomersInclude records for customers not explicitly classified as businesses-
Call Data - Aggregate summariesRead-only call totals: call counts, duration, data usage, retail and wholesale cost-
Call Data - Full per-call detailRead-only access to individual call records-

Two boundaries are worth knowing, because they are not where people assume:

  • Sending a proposal is Pre-Sales, not Customer Interaction. A connection set up for sales work can send proposals without being able to email bills.
  • Sending a bill is Customer Interaction, and it carries the collection behaviour configured for that bill. You do not need to grant Financial for a bill to be sent and collected in the normal way; Financial is for raising charges, refunds and write-offs.

Without the Personal Customers grant, a connection only sees individual records belonging to customers whose customer class is marked as a business. Records for personal customers, and for customers whose class does not say either way, are left out of record lookups, lists and searches. Aggregate KPI figures are unaffected: they still count everybody.

Consumer accounts are not business accounts

Section titled “Consumer accounts are not business accounts”

Paying for a subscription on the company card does not make it a commercial account. Individual subscriptions are consumer plans whoever settles the bill, and they are not suitable for customers’ personal data:

Not suitable (consumer plans)Suitable (commercial plans)
Claude Free, Pro, MaxClaude Team, Enterprise
ChatGPT Free, Go, Plus, ProChatGPT Business, Enterprise, Edu

The difference is the contract, not the price. A commercial plan is bought by your organisation, comes with a Data Processing Agreement naming your organisation as controller, keeps your conversations out of model training by default, and gives your administrators control over retention and access. An individual plan gives the person, not your organisation, the relationship with the provider, and the account leaves with them.

A commercial plan is the prerequisite, not the whole job: check that the Data Processing Agreement is actually in place. The two providers differ here.

  • OpenAI expect you to execute the DPA yourself. Signing up for ChatGPT Business does not put one in place: someone in your organisation has to complete the form on OpenAI’s Data Processing Addendum page, giving your legal entity and signatory details, before personal data goes anywhere near the account. A negotiated Enterprise Agreement may already include it, in which case check the signed contract rather than assuming either way.
  • Anthropic incorporate their DPA into the Commercial Terms of Service automatically, so accepting those terms with a Claude Team or Enterprise plan accepts the DPA with them. Nothing separate needs signing. See Anthropic’s note on viewing the DPA.

Confirm the current position with the provider and your own data controller rather than relying on this page: both providers revise their terms from time to time.

If you are not certain which plan an account is on, or whether a DPA has been executed, treat it as consumer and leave Personal Customers unticked. The business-only categories still work perfectly well without it, and your data controller can confirm the position before it is granted.

Call access is separate from ordinary record access, and both grants are read-only.

  • Aggregate summaries let the assistant total calls over a date range and group them by period, direction, call type, rating period, number type, dealer or site. Platform, dealer and site totals need nothing else. Summaries tied to a specific customer, number, service, feature, invoice or transaction also need General Records read, and the Personal Customers grant where that customer is a personal one.
  • Full per-call detail lets the assistant list and open individual call records. Calls belonging to personal customers are excluded unless Personal Customers is also granted.

Your own call permissions still apply on top: an account that cannot see call records in the platform cannot see them through an assistant either.

A connection can only do something if all three of these permit it:

  1. Your own user account holds the category
  2. The connection was granted the category at approval
  3. The platform’s MCP settings user permits the category, which acts as a site-wide kill switch

On top of that, your ordinary object permissions still apply. Granting Financial does not let an assistant touch records you could not touch yourself.

Enter the current code from your authenticator app and choose Approve. If you did not initiate the connection from your assistant, choose Deny.

You will receive a confirmation email whenever a connection is approved with your account. If you receive one you do not recognise, revoke the connection straight away and reset your password and 2FA.

  • Using AI assistants - example questions, what the assistant can see, and managing your connections