Model Context Protocol

Custom MCP Server: When Your Business Needs One and How to Build It Safely
Custom MCP Server: When Your Business Needs One and How to Build It Safely 150 150 Nadeem Shaikh

A custom MCP server is a small, controlled service that lets AI assistants and agents read from and act on your own systems, such as your ERP, CRM, database or document store, through one standard connection instead of a new integration for every AI tool. If your team already uses AI assistants and keeps copying data into them by hand, an MCP server is usually the next thing worth building.

MCP stands for Model Context Protocol. It is an open standard that tools like Claude, ChatGPT and Cursor use to connect to outside data and actions. This week shows how fast it is becoming the default: Atlassian rebuilt its MCP server for Jira, Confluence, Loom and Bitbucket and says it now handles more than 15 million tool calls a day, Google moved its MCP Toolbox Java SDK to a stable 1.0, and several data platforms announced MCP access to enterprise data. The big vendors are wiring their products for AI agents. The question for most businesses is how to do the same for the systems that are unique to them.

What an MCP server actually does

An MCP server sits between an AI assistant and one of your systems. It publishes a short list of tools, for example “look up an order”, “list open invoices for a customer” or “create a support ticket”, and describes each one in plain language so the AI knows when to use it.

When someone asks the assistant a question, the assistant picks a tool, the MCP server checks whether that user is allowed to run it, calls your system, and returns only the data the user is allowed to see. Your system never hands its database password to the AI. The MCP server holds that access and decides what goes through.

When off-the-shelf MCP servers are enough

If the data lives in a popular SaaS product, check for an official MCP server first. Atlassian, GitHub, Slack, many CRMs and most major clouds now publish one. Using it is faster and cheaper than building your own, and the vendor keeps it updated.

You need a custom MCP server when:

  • The data lives in a system you built or heavily customized, such as an in-house ERP, a legacy SQL database or a line-of-business app.
  • You want the AI to follow your business rules, for example “never quote below list price” or “only show a customer’s own orders”.
  • You need one tool that pulls from several systems at once, like order status that combines your ERP, shipping provider and support history.
  • Security or compliance means data must stay inside your own cloud or network.

How to build a custom MCP server that is safe to put in production

1. Start with three to five tools, not your whole database

Pick the questions your team asks most often and build a tool for each. Narrow tools with clear names work better than one tool that runs any query. The AI chooses more accurately, and you can see exactly what it is allowed to do.

2. Make reads and writes separate

Read-only tools are low risk and a good first release. Tools that change data, such as creating orders, updating records or sending anything to a customer, should come later and usually ask a person to confirm before they run.

3. Pass the user’s identity through

The MCP server should act as the person asking, not as an all-powerful service account. That way a sales rep sees their accounts, a manager sees their team, and your existing permissions still apply.

4. Log every call

Record who asked, which tool ran, what went in and what came back. When an answer looks wrong, the log tells you whether the data, the tool or the AI was the problem.

5. Keep responses small

Return the fields the AI needs, not whole records. Smaller responses are cheaper to run, faster, and less likely to leak data nobody asked for.

6. Test with real questions before rollout

Write down 20 or 30 questions your team actually asks and check that the assistant picks the right tool and gets the right answer. Run that list again every time you add or change a tool.

MCP server vs. RAG: which one do you need?

They solve different problems and often work together. RAG (retrieval-augmented generation) helps an AI answer questions from documents such as manuals, contracts and policies by finding the right passages first. An MCP server gives the AI live access to systems and actions, such as today’s order status, current stock or creating a ticket.

A simple rule: if the answer is in a document, start with RAG. If the answer is in a system, or the AI needs to do something, you need an MCP server. Many useful assistants use both, with RAG as one of the tools the MCP server exposes.

What to have ready before you start

  • A list of the systems you want the AI to reach, and who owns each one.
  • The top questions or tasks your team would hand to an assistant.
  • How users sign in today (Microsoft, Google or your own login), so permissions can carry through.
  • Which AI tools your team already uses, so the server is tested against them.
  • Where it should run: your AWS or Azure account, or on-premises.

Get help building your MCP server

GrtLabs builds custom AI integrations, agentic AI workflows and AI assistants that connect to the systems your business already runs. If you want your team’s AI tools to work with your own data safely, talk to us about your systems and we’ll help you pick the first tools worth building.