MCP server that connects AI tools to your business data

Point an assistant at one address, sign in, and tick what it may touch. It reads what you can read, and nothing beyond it.

Ohne Kreditkarte · Keine Testphase · Alles exportierbar · Jederzeit kündbar

One address is the whole setup

Paste the server address into whatever your assistant asks for, and it opens a browser for you to sign in and choose what it may reach. There is no API key to create, no client ID to request and nothing to copy back.

  • One server address, nothing else to configure
  • Sign-in and consent happen in your browser, not in the assistant
  • Setup instructions in the app for eleven clients; any other MCP client takes the same address

It reads through your permissions, not around them

A connected assistant is bound to the permissions of the person who connected it, checked on every single call, and one organization's data is separated from another's by the database itself rather than by application code. It can never reach something you couldn't open yourself.

  • Capped at the permissions of whoever connected it
  • Row-level security in PostgreSQL, per organization
  • Salaries, staff records, roles, billing and your integrations are closed to any assistant

Reading is the default. Writing is a switch you flick.

Out of the box an assistant can read customers, invoices, quotes, leads, products, expenses and to-dos. Write access starts switched off on the authorization screen; turned on, it can create customers, products, expenses and leads — and that is the entire list.

  • Reads across seven record types
  • Writes off by default, and limited to creating four
  • Deleting a customer or voiding an invoice needs a human approval every time

Connected on your terms, disconnected the same way

A connected assistant is an installed integration like any other: it appears in Settings → Integrations, and uninstalling it stops every token immediately while the activity log keeps what it did. What the assistant does with data it has already read is between you and whoever makes it — so grant the least you need, and connect only assistants you trust.

  • Listed and revoked in Settings → Integrations
  • Revoking stops every token at once
  • The activity log keeps a record of what was done

KI-Tools (MCP) – häufige Fragen

Which AI tools can connect to ERPFlow?
Any client that speaks the Model Context Protocol. The app ships copy-paste setup for eleven of them — Claude, ChatGPT, Perplexity, Cursor and VS Code among them — and any other MCP client takes the same server address.
Can an AI assistant change my data?
Only if you allow it, and only within narrow limits. Write access starts switched off on the authorization screen. Switched on, an assistant can create customers, products, expenses and leads, and nothing else — deleting a customer or voiding an invoice needs a separate human approval each time.
Can a connected assistant see everything in my account?
No. It reads through the same permissions as the person who connected it and never more, and several areas are closed to any assistant regardless of role — salaries, staff records, roles, billing and your integrations among them.

Noch unentschlossen? Demo buchen

Kostenlos starten. Dann mitwachsen.

Führen Sie Ihr ganzes Unternehmen an einem Ort – und zahlen Sie dafür wie ein Gründer, nicht wie ein Konzern.

Ohne Kreditkarte · Keine Testphase · Alles exportierbar · Jederzeit kündbar