AI, MCP & Agents

The model is not the product. The permissioned business context is.

Ask a question, make a decision and take an action — without giving the agent more access than the person who connected it.

One request, end to end

The permissioned action trace

01
User asks
Draft the renewal offer for Nordfeld Klinik.
02
Agent loads a skill
Document creation · versioned with the product
03
MCP selects a tool
Create document from template · write-capable
04
Permission scope is applied
Tenant · role · business unit · commercial visibility
05
Human confirms ambiguity
Two accounts match — candidates returned
06
The record changes
Draft renewal attached to the engagement
07
Audit evidence appears
Write attributed to the connecting user
Ask

Use the model you already trust.

The in-app assistant and approved MCP clients see the same permissioned tools and records. The model endpoint and provider are configurable per workspace.

Anthropic, OpenAI and Google providers
Local and OpenAI-compatible endpoints
Bring your own encrypted provider key
Decide

Procedure before improvisation.

Agents load maintained, versioned skills before non-trivial work. Unclear matches return candidates. Ambiguous writes stop and ask rather than guessing.

Document creation and editing
CRM research and capture
Meeting preparation and transcript filing
Profile maintenance and email drafting
Presales triage, which stops and asks before it commits
Your own sales rules, searched rather than assumed
Act

Actions on the real record.

The agent uses the same permission-aware services as the product UI, so it can research, draft and update without creating a parallel source of truth.

Resolve accounts and capture contacts
File inquiries, email and meeting transcripts
Create and revise governed documents
Update consultant profiles after review
Rewrite a draft in place, so one current version replaces a stack of them
Export a consultant profile as a PDF, anonymised or whitelabelled
Search your sales knowledge and return the rule that applies
Prove

Every action belongs to a person.

Each MCP token belongs to one user and inherits that user’s tenant, role, business-unit and commercial scope. Writes produce normal audit evidence.

Hash-only tokens shown once
Revocation and last-use history
Idempotent source capture
Human confirmation for critical writes

Governed by design

Per-user tokens

Every MCP connection has a human owner.

Inherited scope

The token never widens the connecting user’s access.

Human confirmation

Critical and ambiguous writes stop for review.

Normal audit evidence

Agent actions appear in the same history as UI actions.

Connect your own MCP client. Watch the audit log.

Connect Claude Desktop, Cursor or Copilot Studio to Genedar. In the walkthrough, we set up a user-scoped connection, let the agent complete a controlled task and show the full audit trail.