Integrations, MCP & workflow automationOwn product
Connect Claude or ChatGPT to Your Business Systems: Custom MCP Server, Read-Only First
Connect Claude or ChatGPT to your own systems through a small MCP server. Read-only first, every tool allowlisted, every call logged.
- For
- Teams on Claude or ChatGPT with their own systems
- Checked
Sounds familiar?
Tick what applies to you
How I solve it
What I build
I build a small server that connects your AI assistant to your own systems through a defined set of tools. It starts read-only: the assistant can look, not act. Every tool is on an explicit allowlist, each call is logged, and write tools are added later, one at a time, behind a separate approval. It runs on infrastructure you control, and it exposes your systems — not a copy of your data in a vendor’s cloud.
Built for my own practice
- D.AI / dai-ops MCP · in daily use · 18 tools that Claude Code and Codex call every day, under a supervised execution contract with independent review before acceptance.
- Practice billing server · pilot · live read-only checks verified and payment writes off by default, with one real invoice issued and delivered through an operator-recorded authorisation gate.
The process
How it works
6 steps. Scope and a fixed price are agreed before the first one.
-
List the questions your team actually asks, and the systems that hold the answers.
-
Define a small tool allowlist — read-only at first, one tool per real question.
-
Build the server against your systems, with typed inputs and outputs and an audit log per call.
-
Connect it to your assistant and test the real questions end to end.
-
Confirm nothing can write, then agree, one by one, which writes are worth adding and under what gate.
-
Hand over the server, the tool list and the runbook.
Handover
What you get
A read-only connection between your AI assistant and your business systems: a small server exposing exactly the tools you allow, each call logged, writes off until you approve them one by one. You keep the tool list and the veto.
Built with
- A small MCP server (stdio or HTTP) with a typed tool schema
- connectors to your systems
- an audit log
- a permission model
- On my own practice I run the same pattern in Python with a strict read/write gate
Proof
Done before, with dates and numbers
Own product Built and run by me, in production.
Before → after
Before, my own business systems were closed to the assistant and every answer was assembled by hand. After, 18 tools are called by Claude Code and Codex every day under a supervised execution contract — in daily use as of 2026-09.
[He] did more than we asked him to do and even helped a third-party contractor of ours with some work without charging.
What you can look at
A redrawn architecture diagram of the read-only server — assistant → MCP → tool allowlist → business system — plus a short, sanitised transcript of one read-only call. No screenshots of the store or the internal vault.
This is my own practice tooling — internal systems, not client work. The figures are counts of tools and tests, not client results. I am the founder of Fixel Pixel.
Price and timeline
What it costs and how it runs
A read-only server is a Custom Engineering Project, scoped and quoted in writing. It starts from USD 2,500. Write access is a separate, later engagement. Read-only first is not a sales stage — it is the safer default.
QuoteFixed before work starts
- Price
- Read-only MCP server package, from USD 2,500 (Custom Engineering). Write access is a separate, later engagement. Discussing the task is free.
- Timeline
- Custom Engineering Project: scoped and quoted in writing. Read-only tools go live first; write tools are added later, one at a time, only after a separate approval.
- First step
- Describe the task. I reply within one working day, free, and tell you which option fits — or that you can fix it yourself.
A note from Daniilbefore you decide
When you don’t need this
If a hosted connector already does what you need and you are comfortable with where your data sits, use it. A custom read-only server is for teams who want their own tool allowlist, their own audit log, and no write access until they approve it. If nobody on the team will actually use the assistant day to day, build the workflow first — the connector can wait.
— Daniil
Questions
What people ask about this
Why read-only first?
Because an assistant that can write to production without a gate is a liability. Reading proves the value and the safety before anyone allows a change.
Claude or ChatGPT?
Both can connect to the same server if it follows the MCP standard. The server is the part that matters; the assistant is replaceable.
Where does it run?
On infrastructure you control — your cloud, or a host you already run. Your data does not have to move into a vendor's cloud to be reachable.
How do you keep it safe as it grows?
Every tool is on an allowlist, every call is logged, and writes are added one at a time behind a separate approval. There is no blanket "full access" switch.
Can you connect a system with no real interface?
Sometimes the honest answer is no, or not without a supported way in. That gets said during scoping, not after the invoice.
More like this
All situations- Situation Own Your Stack: Self-Hosted CRM, Booking With Payments, Secrets and Backups
- Article A Custom MCP Server for Your Business: Read-Only First, Gated Writes Later
- Integrations, MCP & workflow automation Replace Zapier with direct API integrations
- Integrations, MCP & workflow automation Can AI help reconcile invoices and bank transactions while a person keeps control of the books?
- Integrations, MCP & workflow automation How do I bring site, email, marketplace and Telegram leads into one CRM without losing the conversation?
Have a task like this?
Describe your taskThe first answer is free, within one working day. Or write directly: next@taskfordaniel.com