AI · Agents · Integrations

What is MCP (Model Context Protocol) and why it matters for your company's processes

Until recently, an AI assistant at work was a chat window: you pasted the text in, it handed a summary back. For it to read your ERP or write to your CRM, someone had to program that connection, model by model and system by system. MCP is the standard that turned that into a plug.

This guide explains what it is without jargon, why every vendor is announcing an MCP server, what really changes for a mid-sized company, what it does not solve at all, and how to start without handing over the keys to the building.

A glowing glass sphere connected by a single plug to a central ring, from which four identical cables run to a ledger, a contact card, a stack of documents and a database, each passing through an amber gate; below, old grey cables dissolve into dust
AR
Owner of Dokuflex
Updated: 4 October 2026

For general managers, operations, IT and digital leads in small and mid-sized companies. An explanatory guide with primary sources linked. Analyst figures are their authors' forecasts, not Dokuflex data.

Direct answer

MCP (Model Context Protocol) is an open standard, published by Anthropic in November 2024 and contributed in December 2025 to the Linux Foundation's Agentic AI Foundation, that defines how an AI agent connects to tools and data: one connector instead of a custom integration for every model-and-system pair. There are already more than 10,000 MCP servers published, and Forrester expects 30% of enterprise software vendors to launch their own in 2026.

What MCP is, without the jargon

MCP is an agreement on how two programs talk to each other: an AI application (your vendor's chat, an agent, an assistant inside your process platform) and a system that has something to offer (your ERP, your CRM, your document manager, a database). The system publishes, in a standard format, three things: the tools that can be invoked ("find customer", "create order", "read the file"), the resources that can be consulted and the instructions it recommends. The AI application connects, discovers that list and uses it. The publishing program is called an MCP server; the consuming one, an MCP client.

The comparison everyone reaches for is USB-C: before it existed, every device had its own cable; now one connector serves almost everything. Before MCP, connecting a language model to a system was a hand-built integration that had to be repeated for each model and each system. With MCP, the ERP vendor builds a server once and any compatible application can use it.

It is also worth saying what MCP is not, because the confusion is common:

  • It is not an AI model. It is the way of connecting models to things. It works with models from Anthropic, OpenAI, Google and others.
  • It is not an agent. The agent is the program that decides what to do; MCP is the socket it does it through.
  • It is not a security or governance layer. It defines how tools are discovered and called; who may call what, with which permissions and under what supervision is up to you. We will come back to this, because it is what matters most.

Why everyone is talking about MCP now: the timeline

MCP went from announcement to de facto standard in little more than a year, and it did so because the big competitors chose not to fight over the connector. The sequence, with sources:

Date What happened Why it matters
25 Nov 2024Anthropic publishes MCP as an open standard, with specification and SDKsThe connector is born; being open, anyone can implement it
2025The main model providers and developer tools add MCP client supportIt stops being "one vendor's protocol"
26 Aug 2025Gartner predicts 40% of enterprise applications will feature AI agents by end of 2026, up from under 5% in 2025If every application has an agent, a standard is needed for them to talk to the rest
5 Nov 2025Forrester predicts 30% of enterprise application vendors will launch their own MCP servers in 2026, and half of ERP vendors will launch autonomous governance modulesYour ERP, CRM and payroll will ship with the socket built in
9 Dec 2025The Linux Foundation forms the Agentic AI Foundation; Anthropic contributes MCP, Block contributes goose and OpenAI contributes AGENTS.md. Platinum members: AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft and OpenAI. More than 10,000 MCP servers publishedNeutral governance: nobody can close the standard or take it away
2026Wave of MCP server announcements from enterprise software vendors and the first dedicated security guidesThe question is no longer "whether", but "with which permissions"

One nuance from the same source is worth keeping: Gartner also expects over 40% of agentic AI projects to be cancelled by the end of 2027 because of costs, unclear value or inadequate risk controls. MCP makes connecting easier; it does not make deciding what for any easier.

What really changes for a mid-sized company

The change is that the agent stops talking and starts doing. Until now, using AI at work meant copying something into the chat and pasting the answer where it belonged; that is what from prompts to processes is about. With a standard connector, the agent looks up the data where it lives and writes the result where it belongs. Some examples by department:

Department Before (isolated chat) With the agent connected to the systems
FinancePaste an invoice and ask for the data to be extractedThe agent reads the invoice, finds the purchase order in the ERP, compares amounts and proposes the journal entry for someone to approve
SalesAsk for a customer summary by copying emailsThe agent queries the CRM, the latest tickets and the signed contracts, and prepares the meeting
HRAnswer the same leave question by handThe agent reads the collective agreement and the person's file, answers, and opens the request in the approval flow
OperationsSearch three systems to find where an order isThe agent checks all three and returns the status with the source of each figure
ITOne custom integration per AI use caseOne server per system, reused by every agent, with a single place to control permissions

Notice that every row hides a dangerous verb: write. Reading the ERP is one thing; creating a journal entry, changing a bank account or approving a request is another. The usefulness of MCP lies in both; almost all the risk lies in the second.

MCP versus API, iPaaS and RPA

MCP does not replace anything you already have; it builds on it. The difference lies in who decides when the connection is used:

Technology What it connects Who decides to use it Behaviour
APIA program with a systemThe developer, when writing the codeDeterministic: always the same
iPaaS / integrationsSystems with each other (ERP with CRM, payroll with HR)A rule: "when X happens, do Y"Deterministic and programmed
RPAA robot with the screen of a system that has no APIA script of clicksDeterministic and fragile when screens change
MCPA language model with tools from several systemsThe model, case by case, from the contextProbabilistic: it decides with judgement, which is why it needs governance

In a healthy company they coexist: integrations for what must always happen the same way, and connected agents for what has to be resolved with judgement. We made the same point when comparing RPA and BPM: the mistake is using the probabilistic tool where a rule was needed.

What MCP does not solve: security and governance

An agent with access to your systems is, in practice, a privileged user that works very fast and never gets tired. The protocol brings no permissions, no supervision and no logging: that is on you. The incidents documented in 2025, compiled by Checkmarx in May 2026, repeat the same pattern:

Asana, April 2025

A vulnerability in its AI feature could have exposed one organisation's information to users of others. The feature was taken offline for two weeks. Lesson: in a shared service, isolation between tenants is part of the server's design, not an extra.

GitHub MCP server, May 2025

Malicious instructions hidden in a public issue made the agent include data from private repositories in a pull request. This is prompt injection: the agent reads text from outside and obeys it as if it were your order.

postmark-mcp package, September 2025

An MCP server distributed as an npm package carried a backdoor that added a hidden copy to every email sent, addressed to the attacker. This is supply chain: installing an MCP server is installing software with access to your data.

Add tool poisoning: a malicious server describes its tools with hidden instructions that the model follows without the user seeing them. The Cloud Security Alliance's best practices guide and the recommendations in the specification itself agree on the minimum controls:

  1. Least privilege per agent and per user. The agent inherits the permissions of the person using it, not a shared administrator credential.
  2. Separate read from write. Tools that change things are enabled one by one, with justification.
  3. Human validation before actions with effect. Creating a payment, changing a bank account or approving a request goes through a person.
  4. OAuth authentication with per-client consent, with no shared or passed-through tokens between services.
  5. A log of every call: who, which tool, with what data, when and with what result.
  6. Treat external content as untrusted. An email, a document or an issue the agent reads may contain orders; the agent does not obey them.
  7. Inventory of servers and versions, with verified origin, as with any other software.
  8. Data in the European Union and a processing agreement for every server that handles personal data.

And one obligation that already exists: the EU Artificial Intelligence Act has required since February 2025 that anyone deploying AI systems ensures their staff's AI literacy (Article 4), and the reasonable practice is to keep an inventory of the AI systems in use. An agent connected to your ERP through MCP is certainly one of them. For a deeper look at the risks, see AI agent security in business processes.

How to start in 90 days without handing over the keys

The typical mistake is to start with the technology: install the ERP's MCP server, give it an administrator credential and see what happens. The right order is the reverse.

  1. Weeks 1-2: inventory. List the systems an agent might need (ERP, CRM, document manager, payroll, email) and, for each, whether the vendor offers an MCP server, which tools it exposes and which ones write.
  2. Weeks 3-4: one process, not one department. Pick a process with lots of lookups and little writing: preparing sales meetings, answering HR questions, locating orders. Define what the agent may read and what it must never do.
  3. Weeks 5-8: the agent inside the process. The agent does not float loose in a chat; it lives as one step of a flow with an input, an output, a confidence threshold and human validation. If the process is already modelled, this step is short.
  4. Weeks 9-12: measure and decide. Cycle time before and after, errors, human interventions per hundred runs, and a fixed date to decide whether to extend it to a write tool, with validation, or stop.

And the seven questions worth asking any software vendor, including your long-standing one:

  • Do you have an MCP server, or a date for one, and which tools does it expose?
  • Are permissions evaluated per user, or with a single credential for the whole agent?
  • Do you distinguish read tools from write tools, and can they be enabled separately?
  • Is every call logged, and can the log be exported?
  • Does it support human validation before executing actions with effect?
  • Where is data processed, and under which data processing agreement?
  • How does it authenticate: OAuth with per-client consent, or a shared token?

If an answer is "we don't know yet", that is not a bad vendor; it is an honest vendor in October 2026. The worrying one answers "yes to everything" without showing it.

How Dokuflex handles it

In Dokuflex, a low-code BPM platform with AI, the agent never floats loose: it is one step of a process. That settles half of the control list above out of the box, because the process already has an input, an output, a confidence threshold, human validation and a log, and governed agents inherit the permissions of the user on whose behalf they act.

To connect to your systems, the agent uses the same pieces as the rest of the platform:

  • More than 200 native connectors to ERP, CRM, payroll and storage (SAP, Sage, A3, Holded, Salesforce, HubSpot, Microsoft 365) and documented REST and GraphQL APIs for anything bespoke. Details on the integrations page.
  • Credentials in an encrypted vault with AES-256 and periodic rotation, never shown in logs or on screen: the agent does not see passwords, it sees permissions.
  • Language models and RAG inside the platform, with data in the European Union, as explained in LLM and RAG under the GDPR.
  • An audit trail of every step, human or AI, with who, what, when and with which data, which is exactly what the MCP security guides ask for and what you will need for the AI Act inventory.

For us, MCP is one more way of plugging a model into the tools of a process, welcome because it saves custom integrations. What governs what the agent may do does not change with the connector: it is still the process.

Frequently asked questions

What does MCP stand for?+

MCP stands for Model Context Protocol. It is an open standard that defines how an AI application (the client) discovers and uses the tools, data and instructions offered by a system (the server). The idea is that a language model connects to an ERP, a CRM or a document management system through a single standard connector instead of a custom integration for every model-and-system pair.

Is MCP owned by Anthropic?+

Anthropic created it and published it as an open standard on 25 November 2024, but since 9 December 2025 it has been governed by the Agentic AI Foundation, a directed fund of the Linux Foundation co-founded by Anthropic, Block and OpenAI, with Amazon Web Services, Google, Microsoft, Cloudflare and Bloomberg among its platinum members. It is the same neutral governance model behind projects such as Kubernetes or Node.js, and it is what allows competing vendors to adopt it.

Do I need MCP to use AI in my processes?+

No. MCP solves one specific problem: letting an AI agent read and act on your systems without someone programming each connection. If what you need is for AI to classify documents, extract data from invoices or draft replies inside a workflow, that is already done today with a model built into the process platform, with or without MCP. MCP matters when you want the agent to query or modify several different systems and you want to avoid a custom integration for each one.

Is it safe to connect an AI agent to my ERP through MCP?+

It is as safe as the permissions you grant and the controls you put around it. The protocol includes no governance: a misconfigured MCP server exposes whatever it exposes, and the incidents documented in 2025 (private data leaked through the GitHub MCP server, cross-tenant exposure in an Asana AI feature, a malicious npm package that forwarded emails to an attacker) share the same pattern: the agent had access to more than it needed and nobody reviewed what it did. The practical rule is to treat every agent with data access as a privileged user: least privilege, write actions with human validation, and a log of everything.

Does MCP replace integrations or an iPaaS?+

No, it builds on them. An iPaaS connects systems to each other deterministically: when a deal closes in the CRM, an order is created in the ERP, always the same way. MCP connects a language model to tools, and the model decides case by case which tool to use. Underneath, the MCP server usually calls the same APIs your iPaaS already uses. In a company they coexist: integrations for what must always happen the same way, and MCP for what an agent has to resolve with judgement inside a process that governs it.

What is an MCP server?+

It is the program that, on the side of a specific system (your ERP, your document manager, a database), publishes in a standard format which tools it offers (for example, find customer or create order), which resources can be read and which instructions it recommends. Any compatible AI application can connect to it, discover those capabilities and use them. According to the Linux Foundation, there were more than 10,000 published MCP servers in December 2025.

What should I ask my software vendor about MCP?+

Seven things: whether it offers or plans an MCP server and which tools it exposes; whether permissions are evaluated per user or with a single credential for the whole agent; whether it distinguishes read tools from write tools; whether it logs every call with who, what and when; whether it supports human validation before executing actions with effect; where data is processed and under which contract; and how it handles authentication, which should be OAuth with per-client consent rather than shared tokens.

Sources

Next step

An agent connected to your ERP, inside a process that governs it

Bring a process with lots of lookups and little writing. In 30 minutes we will set it up with an agent that reads your systems, show you the log of every call and decide together whether it is worth continuing. No commitment.