Back to Case Studies
Trading InfrastructureAI Agents on Claude

Giving Claude Audited, Read-Only Access to a Live Hosting Operation

An MCP server that lets Claude answer questions about customers, billing, support tickets and server health across a live hosting business, with no ability to change anything.

A managed VPS hosting provider for tradersDeployed Sept 20263 min read
Systems Checked per Customer Question
4, by hand→1 tool call
Write Access Granted to the AI
None, by credential
Calls Recorded in the Audit Log
Every call
Server Health Lookup
18 seconds→3 seconds

The Problem

A hosting business keeps its truth in several places. Billing and services live in one database, support tickets in another system, virtual machines on hypervisors in several data centres, and machine heartbeats in a monitoring database. Answering one customer question ("is my server up, and am I paid up?") meant a person opening four tools and joining the answer in their head.

An AI assistant could do that join in seconds. The risk is obvious: the same databases hold passwords, card references and API keys, and the hypervisors can stop or destroy a customer's machine. Nobody should hand that to a language model and hope the prompt holds.

What We Built

A Model Context Protocol (MCP) server that Claude connects to. It exposes six tools:

  • Find a customer from a search term
  • Get a customer with their services
  • Get billing status and invoices
  • Get tickets and recent support history
  • Get service health from the hypervisor and the heartbeat feed
  • Get an account snapshot that joins all of the above in one call

It serves two separate customer portals from the same tools.

Read-Only by Credential, Not by Prompt

The design decision that matters: the server cannot write, whatever it is asked to do.

  • Database access goes through views. The server's database user can only see a set of purpose-built views. Password, card and API-key columns are not in them. Custom fields are whitelisted one by one, because sensitive values sit in the same table as harmless ones.
  • Monitoring data is read in read-only transactions under a role that has SELECT on one table.
  • Hypervisor access uses an audit-only role. Any write returns a 403 from the hypervisor itself.
  • A full-power cloud API key was deliberately left out. Where the only available credential could do damage, that data source was not wired in, and the gap is documented instead.

A prompt can be argued with. A credential cannot.

Audit Log

Every tool call is written to an audit log with the caller, the tool and the arguments. You can see exactly what the AI looked at, and when.

What It Is Used For

  • Staff ask Claude a plain-English question about a customer and get one joined answer.
  • A support assistant calls the account snapshot tool to draft replies from live account state. Customer-facing drafts are reviewed by a person before they are sent.

What We Learned

  • Decide what the agent must never do before deciding what it can do. Starting from the credential made every later choice simpler.
  • Whitelist, do not blacklist. New sensitive fields appear over time. A whitelist fails safe.
  • Leave a gap rather than widen a permission. A documented blind spot is better than a key that can do more than you intended.
  • Index for the question the agent asks. One lookup went from 18 seconds to 3 by matching the query to the index.
ClaudeModel Context ProtocolPythonMariaDBPostgreSQLProxmox

Want results like these for your business?

Book a free 30-minute discovery call. No commitment, no sales pitch — just an honest conversation about what AI can do for you.

Book a Discovery Call