Assistants over your live data
Not a chatbot bolted onto your website. A governed connection between the assistant and the systems that actually run the business, so someone can ask a question in plain words and get the real number back. Every call is logged, and nothing changes until a person says so.
In plain words
The assistant does not learn your data. It asks your systems, live.
MCP is an open standard for connecting an assistant to a system. The server in the middle is the part we build and operate. It publishes a fixed list of named actions, and the assistant can do those things and nothing else.
That is the whole difference. There is no copy of your database sitting inside a model, no export that goes stale overnight, and no guessing. The answer comes from the record that exists right now, and you can see which call produced it.
A model trained on your data
Nothing is copied into a model. Training on your records is a different business with different risks, and it is not this one.
A chatbot for your customers
This is for your own staff, inside the assistant they already have open. No new application to roll out, no public-facing bot to police.
A named list of things it may do
“List overdue customers.” “Draft a payment reminder.” Each one is a tool we wrote, against your system, with your rules inside it.
Five of these are in production. Across four industries, today.
Together they publish more than 200 governed tools. The fifth, not in the grid below, is our public legal-data service, which reads case law and regulations for legal teams.
Fund compliance
Covenant health, deterioration scans, exposure and board packs over a live portfolio. Runs inside CapitalBridge at Cygnum Capital, across 7 funds and 191+ borrowers.
Legal practice
Matters, deadlines, hearings, time and billing for a European law firm, with statutory deadline maths computed rather than estimated.
Group business intelligence
Sales, stock, receivables and customer briefings over the live database of a European packaging group, multi-company, answering in the user's own language.
Planning models
Model introspection, variance autopsy and anomaly detection over Acterys planning models, multi-tenant, with a gated write-back path.
We did not arrive at this by reading about it. These have been running against real systems, with real users, long enough to have opinions about what breaks.
Read the full capability brief (PDF, 21 pages)
The safety model in depth, four end-to-end workflows from these deployments, and the tool inventories. No email required.
The interesting question is not what it can do. It is what it cannot.
Every objection a finance or compliance team raises about assistants is a governance question. So governance is the part we design first, not the part we add afterwards.
Named tools, never free-form access
The assistant does not get a database connection. It gets a list of actions we wrote, each one scoped, filtered and bounded by the same rules your application enforces.
Reads and writes are different things
Reading is the default. Writing is a separate, explicitly granted set of tools, so “let it answer questions” never quietly becomes “let it change records”.
Writes are drafted and held
A change is prepared, shown in full, and waits. A person approves it. Nothing enters your systems because a model was confident.
Every call is logged
Who asked, which tool ran, what it returned. When someone questions a number months later, the trail is there rather than reconstructed.
Permissions per tool, in the assistant itself
Each action can be set to allow, ask first, or block, and your administrators hold that switch. Scope shrinks as easily as it grows.
Start with one question your team asks every week. Widen it once it earns trust.
A first server is a small, useful thing that reaches production quickly. Every one we run today started that way and grew because people kept using it.
Pick the question
Not a strategy. One recurring question somebody currently answers by opening three systems and a spreadsheet.
Wrap the system
We build the read tools around it, against your live data, with your access rules carried through rather than re-invented.
Govern and hand over
Permissions set, logging on, your administrators holding the switches. Your team uses it in the assistant they already have.
Widen deliberately
More tools, then guarded writes, in the order your team actually asks for them. This is where the servers above grew to 60 and 90 tools.
What people ask before they say yes. Answered plainly.
What is an MCP server?
MCP is an open standard for connecting an AI assistant to a system. An MCP server is the piece in the middle that we build and operate. It publishes a fixed list of named actions, such as list overdue customers or draft a payment reminder, and the assistant can do those things and nothing else.
Is this a chatbot on our website?
No. This is for your own staff, in the assistant they already use. There is no new application to learn and no public-facing bot. The assistant reaches your live data through the server we build, and it answers from the real records rather than from a trained copy of them.
Can it change our data?
Only where you allow it, and never silently. Reads and writes are separate tools. A write is drafted and held until a person approves it, every call is logged with who asked and what came back, and each tool can be set to allow, ask first, or block.
Which assistants does it work with?
Claude, Microsoft Copilot and ChatGPT. MCP is a standard rather than a vendor feature, so the same server serves whichever assistant your organisation has settled on, and it keeps working if that choice changes.
Do you also do document extraction?
Yes, that is a separate offer. Document AI on Azure reads invoices, contracts and forms into structured data at 95%+ extraction accuracy, proven across thousands of real documents. It is often the step that produces the data an assistant then answers from.
Everyone is demonstrating assistants this year. Fewer are running them against live systems with the audit trail to show for it.
Compliance admin per quarter, across 7 funds and 191+ borrowers. Live in 4 weeks, and now carrying a 67-tool assistant layer on top.
The honest test is your own systems and one question you actually care about. In half an hour we can tell you whether an assistant will help with it, and whether the data behind it is in a fit state to be asked.
Sometimes the answer is that the reporting needs fixing first. We would rather say so than sell you a layer on top of a problem.
Related
CapitalBridge
Our own fund-compliance platform, and the system carrying the 67-tool assistant layer described above.
Case studies
Named clients and the outcomes we can publish, including the one above.
Document AI
Invoices, contracts and forms read into structured data on Azure, at 95%+ accuracy.
Capability brief (PDF)
21 pages: the safety model in depth, four end-to-end workflows, full tool inventories. No email required.
