Connect and control MCP servers

Review the built-in ERP tools, add an outside server with the wizard, control each tool's risk and approval, and test tools safely.

Required permission: ai.configure

Before you begin

  • MCP servers must be on in Applications > AI Assistant > Features and MCP must be on in Settings > General.
  • You need ai.configure. The MCP Servers menu is hidden from everyone else.
  • You need the server's HTTPS address and, if it requires one, a token or key. Use a test server and a test key first.

An MCP server supplies tools the assistant can use. The a2NSoft ERP server is built in and always present. Outside servers are optional.

Steps

Review the built-in tools

  1. Open AI Assistant > MCP Servers. The tiles show Connected servers, Disconnected, Tool errors, Average latency, Last success and Last failure.
  2. Open the a2NSoft ERP server and select the Tools tab. Each tool shows its domain, risk, approval policy, calls and errors. Read tools start on and need no confirmation; write tools need confirmation.
  3. Use the Enabled switch to turn a tool off. The assistant then says it is not allowed to use it.

Add an outside server

  1. Select Add server. The wizard has eight steps.
  2. Choose the Server type (Google Drive, Gmail, Microsoft 365, SharePoint, Bank API, Warehouse Scanner, External SQL or Custom API). The tile fills in a name, transport and URL prefix.
  3. In Connection, enter the Name (up to 80 characters), Transport (Streamable HTTP or HTTP), Endpoint URL (must start with http:// or https://) and a Description.
  4. In Authentication, choose None, Bearer token or API key header (sent as X-API-Key), and type the Secret.
  5. Select Save & test. If it connects you see the server name and version. Then Discover tools.
  6. Switch on only the read tools you need. Tools found on an outside server start off.
  7. Assign the agents that may use the server, then select Activate.

Set risk and approval

  1. On the Tools tab, set each tool's Risk: READ_ONLY, LOW_RISK_WRITE, MEDIUM_RISK_WRITE, HIGH_RISK_WRITE or CRITICAL. Set the Approval policy. DISABLED also switches the tool off.
  2. A tool that changes data can be made riskier, never READ_ONLY, and always asks for confirmation.

Test a tool

  1. Select Test tool, enter input as JSON such as {"query": "Test"}, and run it. Only read-only tools can be run here, with your own permissions.

Other tabs

  1. Use Overview, Resources, Prompts, Agents, Logs and Settings. In Settings, type a new secret to replace the old one; blank keeps the old.
  2. Connect / Disconnect, Test and Delete are in the server row.

What happens next

  • An activated server shows Connected, and its enabled read tools appear in chat as a block titled '<server> · <tool>'.
  • The activity log shows the server column for each call.
  • The secret is sealed. The screen only learns that a secret exists.

Good to know

  • 'The endpoint must be an http(s) URL.' 'A server needs a name.' 'Give the server's address.'
  • 'The sse transport is not supported yet; use Streamable HTTP.' WebSocket is not supported and stdio is not allowed.
  • A failed test shows an error such as HTTP status or AUTH_REQUIRED, and the Logs tab keeps it.
  • 'Only read-only tools can be run from here; a write goes through a chat and a confirmation.'
  • 'A tool that changes data cannot be classified as read-only.' 'A tool that changes data always asks for confirmation.'
  • Outside write tools are refused: '<tool> on <server> changes data and needs an approval flow that external tools do not have yet.'
  • The built-in server cannot be deleted: 'The a2NSoft ERP server can be restricted tool by tool, not deleted.' Deleting an outside server (confirm 'Delete this server and its tool registry?') removes it from every agent.
  • Important: the server calls whatever address you enter, including internal addresses. Only add servers you trust.
  • An agent with no servers ticked uses every enabled outside server. Tick servers on an agent to restrict it.
  • a2NSoft's own MCP endpoint is available for outside tools to read your ERP: it lists read tools and answers with the signed-in user's permissions. It does not check the tool switches or the never-send list, so treat it as a technical interface for administrators.
  • Two administrators editing one server: the last save wins.