Native MCP support, built in

Your AI assistant, connected to your actual business.

Ask Claude “who owes me money?” and get the real answer, pulled from your own invoices, on your own server. Not a copy-paste. Not a screenshot. Not a chatbot trained on your PDFs.

It speaks MCP, the Model Context Protocol: the open standard the whole AI world is standardizing on to connect assistants to real software. Not a bolt-on. Not a proprietary API. The real thing, shipped in the box.

Native MCP support · Self-hosted · Read-only by default · Off until you switch it on

Every AI tool wants your data. This one doesn't have to leave home.

The usual way to get AI near your business data is to upload it somewhere: a vendor's cloud, a vector database, a “secure enclave” you are asked to take on faith. Your books end up as a copy on someone else's disk, and every question you ask is a query against a snapshot that is already stale.

SelfHostedERP takes the other route. Your data never moves. Your AI assistant is handed a door into the running system, the same records, the same permissions, live, and asks questions through it.

The technology is MCP, the Model Context Protocol: the open standard for connecting AI assistants to real systems. It ships built in. There is nothing to buy, nothing to bolt on, and no third party in the middle.

How it works.

Every request runs through the same permission check your workspace already uses. Every time. Logged.

Your AI app
Claude
Cursor
The permission check
Who is this key for?
What may they see?
Your records
invoices · leads
tasks · reports

every request · every time · logged

  1. 1
    Create a key
    Inside your workspace, and tick which rooms it may reach.
  2. 2
    Paste it into your AI app
    One command for Claude Code, a small block for Claude Desktop or Cursor.
  3. 3
    Ask questions in plain English
    The AI picks the right tool, reads the live records, and answers.
  4. 4
    Changes wait for you
    Anything it wants to write goes to a review queue, not a done deal.

The AI borrows your badge. It never gets its own.

The easy way to build this is to give the AI an all-powerful service account. That is how people get burned, so we do not do it. A key is bound to a real person's membership in the workspace, and every permission check the system already runs for that person runs, unchanged, for the AI acting as them.

It can never see more than you can

Ticking rooms when you create a key only ever narrows what it reaches. A key cannot grant access its owner does not already have.

Read-only by default

Writing is a separate, deliberate decision, and even then changes queue for a human to approve before anything is saved.

Every request is logged

Including the refused ones, and the reason why. "What has the AI been doing?" is a question with an actual answer.

Revoking is instant

Delete the key, or remove that person from the workspace, and it stops working immediately. No restart, no propagation delay.

It never leaves your server

The endpoint is part of your install, behind your certificate, on your infrastructure. We cannot see it. Neither can anyone else.

Off until you switch it on

AI connections ship off. One setting turns them on, and no key means no entry.

What you can actually ask.

Money
  • Who owes me money and hasn’t paid in 60 days?
  • How did last month compare to the one before?
  • Show me the profit and loss for Q3.
Sales
  • Which deals have gone quiet?
  • Tell me everything about Acme Corp.
  • What should have closed by now but hasn’t?
The whole business
  • What needs my attention today?
  • What did we ship last week?
  • What’s on fire right now?

Your assistant also gets a set of ready-made routines it can run on request, month-end close review, pipeline hygiene sweep, “what's on fire,” so the useful questions are there before you think to ask them.

What it can reach.

Tools across all four rooms, every one of them permission-checked individually. Because the ERP is build-your-own, the tools follow your data: define a new record type and your AI assistant can read it, no plugin, no code, no waiting on us.

ERP System

Invoices, bills, expenses, aging reports, accounting, plus customers, leads, deals, and pipeline, and every custom record type you have built.

SEO & AI Briefs

Keyword rankings, AI-citation briefs, content clusters, and content-gap findings.

Marketing & Ads

Campaign items, Palette ad creative, and AI ad copy.

Communications

Meetings, team chat channels, and the shared calendar.

Which AI apps work.

  • Claude CodeOne command
  • Claude DesktopPaste one block
  • CursorPaste one block
  • Anything speaking MCP over HTTPAddress and key
  • ChatGPTNot yet, see below

On ChatGPT, plainly: its custom connectors accept an OAuth sign-in or no authentication at all, so they cannot carry an access key the way Claude and Cursor do. Supporting it means this software also becoming an OAuth provider, which is on the roadmap and is not built yet. We would rather say that than tell you to expose your business data with no lock on the door.

Setup takes about five minutes.

No technical background needed for the parts you do.

  1. 1
    Switch it on
    One setting in your install’s environment file, then restart.
  2. 2
    Create a key
    Settings, then AI Connections, then New connection. Tick the rooms, press create, copy the key.
  3. 3
    Paste it into your AI app
    The page hands you the exact command, already filled in, plus a Test it now button that confirms the key works before you go anywhere else.

There is a guided version inside the app that checks each step as you go and ticks it off.

AI connections, answered.

  • What is MCP?

    The Model Context Protocol, an open standard for connecting AI assistants to real systems and data. An MCP server offers a set of tools; an AI app connects and uses them. It is built into SelfHostedERP, so there is nothing extra to install or license.

  • Does my business data get sent to an AI company?

    Only what you ask about, in the moment you ask. Answers travel to whichever AI app you chose, exactly as they would if you had typed the numbers in yourself. What does not happen is any bulk upload, sync, or copy of your database to us or anyone else. Nothing is indexed, nothing is stored elsewhere, and the data stays on your server.

  • Can the AI delete my records or change my books?

    Not unless you decide it can. Connections are read-only by default. Grant one write access and it still cannot act alone: every change is written to a review queue with a plain-English summary, and a human presses Approve or Reject.

  • What if someone steals a key?

    It can only do what its owner could do, in the rooms you ticked, and every use is logged. Revoke it on the connections page and it dies instantly. Keys also expire, 90 days by default.

  • Which AI assistants can connect to SelfHostedERP?

    Claude Code, Claude Desktop, Cursor, and any client that speaks MCP over HTTP. ChatGPT is not yet supported because its custom connectors require OAuth rather than an access key.

  • Does connecting an AI assistant cost extra?

    No. MCP support is part of the software. Because it is self-hosted there is no per-seat AI charge and no metered API calls to us.

Your business software already knows the answer. Now you can just ask it.

Tell us about
your team.

A specialist reviews every inquiry within one business day. No sales pressure, no auto-drip, no demo bot.

Protected by Cloudflare Turnstile. We never share your details.