The Problem
A hosting business keeps its truth in several places. Billing and services live in one database, support tickets in another system, virtual machines on hypervisors in several data centres, and machine heartbeats in a monitoring database. Answering one customer question ("is my server up, and am I paid up?") meant a person opening four tools and joining the answer in their head.
An AI assistant could do that join in seconds. The risk is obvious: the same databases hold passwords, card references and API keys, and the hypervisors can stop or destroy a customer's machine. Nobody should hand that to a language model and hope the prompt holds.
What We Built
A Model Context Protocol (MCP) server that Claude connects to. It exposes six tools:
- Find a customer from a search term
- Get a customer with their services
- Get billing status and invoices
- Get tickets and recent support history
- Get service health from the hypervisor and the heartbeat feed
- Get an account snapshot that joins all of the above in one call
It serves two separate customer portals from the same tools.
Read-Only by Credential, Not by Prompt
The design decision that matters: the server cannot write, whatever it is asked to do.
- Database access goes through views. The server's database user can only see a set of purpose-built views. Password, card and API-key columns are not in them. Custom fields are whitelisted one by one, because sensitive values sit in the same table as harmless ones.
- Monitoring data is read in read-only transactions under a role that has SELECT on one table.
- Hypervisor access uses an audit-only role. Any write returns a 403 from the hypervisor itself.
- A full-power cloud API key was deliberately left out. Where the only available credential could do damage, that data source was not wired in, and the gap is documented instead.
A prompt can be argued with. A credential cannot.
Audit Log
Every tool call is written to an audit log with the caller, the tool and the arguments. You can see exactly what the AI looked at, and when.
What It Is Used For
- Staff ask Claude a plain-English question about a customer and get one joined answer.
- A support assistant calls the account snapshot tool to draft replies from live account state. Customer-facing drafts are reviewed by a person before they are sent.
What We Learned
- Decide what the agent must never do before deciding what it can do. Starting from the credential made every later choice simpler.
- Whitelist, do not blacklist. New sensitive fields appear over time. A whitelist fails safe.
- Leave a gap rather than widen a permission. A documented blind spot is better than a key that can do more than you intended.
- Index for the question the agent asks. One lookup went from 18 seconds to 3 by matching the query to the index.