MCP is the protocol that lets an AI assistant reach a real business system instead of guessing. Getting the connection working is the easy part. Getting the permissions, the role design, and the guardrails right is the part that decides whether it is safe to keep.
Standing up an MCP connection to an ERP, a warehouse system, or a data source is often a day of work. The project is everything around it. What can this agent read. What can it never write. Which role does it run as. What happens when it is wrong. How would you know that it was wrong. Those questions do not have technical answers, they have operational ones, which is why they usually get skipped by whoever set up the connection.
Role and permission design scoped to the specific workflow rather than to the convenience of the person building it. Read-only architectures first, with write paths added deliberately and per workflow. Goal-based validation on every agent, meaning an explicit success definition, a way to check the output against it, and retry or escalation logic when it fails. Observable telemetry so you can audit what happened. And cost routing, so the expensive model is not doing work a cheap one handles fine.
You need it when the AI has to reach live transactional data, when more than one person depends on the output, or when the output touches anything auditable. You do not need it when a person is copying a file into a chat window once a week. That is a workflow question, not an integration question, and the honest answer is often to leave it alone.
NetSuite and Odoo primarily, plus the surrounding stack that mid-market operations actually run on: Shopify, 3PL and warehouse systems, integration platforms like Celigo, and the reporting layer. We are consultants rather than a platform vendor, so we have no reason to recommend a connection you do not need.
Model Context Protocol. It is an open standard that lets an AI assistant connect to external systems and data through a defined interface, so it can work with real records instead of whatever was pasted into a conversation.
It depends entirely on the role you give it. An agent running as an administrator is a risk. An agent running as a purpose-built role with read access to five record types and no write permissions is a very different proposition. The role design is the security model.
Often not. Many systems now publish their own. The work is usually in permissions, orchestration, and validation rather than in building a connector from scratch.
Over-permissioning at setup, no defined success criteria so nobody notices when output degrades, and no telemetry, so the first sign of a problem is someone downstream finding a bad number.
We start with the AI Action Plan at $5,000 to determine whether integration is even the right next step. Build work is scoped from that.
30 minutes. No commitment. We will tell you honestly whether we can help.
Book an ERP Strategy CallLast reviewed: August 2026
Book a 30-minute strategy call. No pitch deck. Just a conversation about what is not working and what we can do about it.
Book an ERP Strategy CallTFR Solutions, Los Angeles, CA · teddie@tfr.solutions · (310) 894-6031