Learning
MCP integration:
control beats reach.
The Model Context Protocol (MCP) connects language models to business systems. The technology is quick to build. Whether it holds up in a company depends on something else.
What it is about
A language model knows nothing about your orders, customers and contracts. Through MCP it gets tools to look things up in ERP, CRM, mailbox or registers. That is the step from general world knowledge to answers from your own data.
In the Lab we built several such integrations: for Microsoft 365, for public registers and for annual accounts. The pattern repeated itself every time.
Learnings
What we learned
Control before reach
What matters is not how many tools a server offers but how precisely it defines who may use which tool for which data.
Detect before the model reads
Personal and sensitive content has to be detected before it reaches a model. Afterwards nothing can be taken back.
Deliver the provenance
An answer from connected data must say where it comes from and which data is missing. Otherwise it cannot be checked.
What it means for the architecture
MCP servers belong in the business architecture, not just in development. Every integration needs a business owner, a permission model and a log.
Open protocols keep the choice of model open. Whoever integrates today should be able to switch models tomorrow without rebuilding the integration.
Related in the Lab
Field reports and articles
Microsoft 365 and AI
The value lies in control, not in access.
Trademarks in an agent workflow
Anonymous and consented access, cleanly separated.
Building your own MCP server
Blog: tailoring it so it holds up in operation.
From the Lab into consulting
Does this fit your project?
SIMO GmbH puts into practice what holds up in the Lab: Business Data Strategy & Architecture for AI. The initial call takes 45 minutes and is free of charge.