MCP & AI TOOLS

The enterprise MCP server

One endpoint a whole company connects to, inside its own infrastructure, with keys it issues and a log it owns. What a team-grade MCP server needs that a laptop one does not.

Leadership Engineering EXPLAINER 4 min read
ChatGPTKEY · TEAM AClaudeKEY · TEAM BCursorKEY · TEAM CYOUR INFRASTRUCTUREONE ENDPOINTKEYS CHECKEDMCP serverTOOLS · KEYS · LOGORDERSPRODUCTSINDEXED COLLECTIONSLOGWHO ASKEDWHAT, WHENPRODUCTION DATABASE NEVER ON THE PATHChatGPTKEY AClaudeKEY BCursorKEY CYOUR INFRASTRUCTUREMCP serverTOOLS · KEYS · LOGORDERSPRODUCTSINDEXED COLLECTIONSLOGWHO ASKED WHAT, WHEN
One endpoint for the company. A key per team. A log you own.

From a laptop to a company

The first MCP servers were personal: a process on a developer's machine, started by the editor, reading whatever that developer could reach. That is fine for one engineer and wrong for an organization. The credentials are the developer's. The data path is often the production database. There is no record of what was asked, no way to switch a tool off for one team, and a second person wanting the same connection installs a second copy. An enterprise MCP server is the same protocol with the operational parts added: one endpoint, inside the company, with keys, a log and a deliberate tool list.

One endpoint, inside the boundary

The server runs in your infrastructure, next to the data it serves, and answers at one address. Every client - ChatGPT for the sales team, Claude for management, Cursor for the engineers - connects to that address. Deploy once, upgrade once, monitor once. And because the server sits beside an indexed copy of the collections rather than beside the database, every question any client asks is a read of the copy. The production database is never on the path, which is the single most important property for a security review to confirm.

Keys per team or tool

Access is an endpoint plus an access key, and the keys are issued from your deployment, not by the AI tool's vendor. One key per team or per tool keeps the blast radius small: the sales team's key can be rotated without touching engineering's, and a departing contractor's key can be revoked without a company-wide change. No key, no connection. The key is also what the log is written against, which turns "who asked what" from a mystery into a query. Access keys and revocation is the full model.

A log you own

An enterprise server records every tool call: the key, the tool, the arguments, the time. That log answers the questions that come after an AI rollout - which teams use it, for what, how often - and the questions that come from audit: was this collection queried by that tool on that day. A server without a log is a server whose use cannot be reviewed, and most organizations will not accept that for long.

A deliberate tool list

What the server publishes is what every client can do, so the list is a policy decision. For business data the right tools answer questions: list collections, describe fields, search with filters, facet, fetch a record. The wrong tools are the convenient ones - a free SQL tool, a write tool - because a tool published to the server is published to every key. An enterprise server is one where someone decided the list and can defend it. MCP server explained covers the tools in detail.

Side by side

CriterionLocal server · one laptopEnterprise server · one endpoint
Who runs itThe developer who started itYour infrastructure team, once
Who can connectThat machineEvery client given a key
CredentialsWhatever the laptop hasKeys issued per team or tool, revocable
Data pathOften the database directlyAn indexed copy; production never exposed
LogNone, usuallyEvery call, against the key that made it
UpgradesEach laptop separatelyOne deployment
BrandingA developer toolYour endpoint, under your name
Tools publishedWhatever was convenientA deliberate list: search, filter, aggregate, fetch

What crosses, and to whom

The tool call and its key come in; the requested results go back to the client, and from the client on to that client's own AI provider, under your agreement with that provider. The index, the keys and the database stay inside. The same honesty applies here as to the assistant: results do leave, to a party you chose, under keys you can revoke, and nothing leaves that was not requested. Data flow map places this flow beside the others.

Questions to ask before connecting a company

  1. Where does the server run, and does it read the production database or a copy?
  2. Who issues the keys, and how quickly can one be revoked?
  3. Is every call logged against its key, and can we read the log?
  4. Which tools are published, and can any of them write?
  5. What does a connected client receive, and under whose agreement with its AI provider?
  6. Does the endpoint carry our name, or the vendor's?

A vendor who answers all six in a table is offering an enterprise server. A vendor who answers "it supports MCP" is offering a laptop one with a public address.

See it on real data.

The demo instance runs dashboards, data grids and the AI Assistant on real business data. No sign-up.