How to connect Claude to your CRM with MCP

AI assistants are good at reading, summarising and drafting. With MCP they can also work with your business data — find leads, create tasks, check shipments. That is useful only if the system on the other side keeps control over what the agent may change. This guide explains how MCP works, how to connect Claude safely to any CRM that supports it, and how the connection works in OrgLines.

What MCP is in one paragraph

The Model Context Protocol is an open standard that describes how an AI assistant discovers and uses the tools of another program. The program runs an MCP server that publishes a list of actions — “find leads”, “create a task”, “show today's shipments” — with a description of each. The assistant (the MCP client) reads that list and calls the actions when your request needs them. You keep talking in plain language; the assistant turns it into tool calls and shows you the results.

Why control matters more than the number of tools

A language model can misunderstand a request, pick the wrong record or act on text it found inside an email. Reading data is low-risk; changing, deleting or sending is not. Before you connect an agent to any business system, check three things: who decides whether a change needs your approval, what the agent can see, and how you revoke access. The safest answer to the first question is “the server, not the agent” — an instruction in a prompt can be ignored, a server-side rule cannot.

What you can ask

  • “Which leads from this week have no reply yet? Create follow-up tasks.”
  • “Summarise yesterday's mail from clients and flag anything urgent.”
  • “Show today's trips and which freight orders still have no carrier.”
  • “Which subscriptions renew next month?”
  • “Plan my week from open tasks and calendar events.”

A worked example: from question to confirmed change

  1. You ask: “Which leads from this week are still waiting?” The agent calls a read tool, for example stale leads, and lists them. No approval is needed for reading.
  2. You say: “Create a follow-up task for each, due tomorrow.” The agent prepares the tasks. The server returns a proposal instead of writing immediately.
  3. You check the proposal and confirm. Only then are the tasks created.
  4. If you had asked to delete leads or send emails, confirmation would be required in every case.

How OrgLines keeps control

OrgLines sorts every action into classes: read, create, change, destructive, external and financial. Most writes requested through MCP return a proposal first, and the change is made only after you confirm it; destructive, external and financial actions always need confirmation, and the agent cannot skip it. The agent sees only the modules and data your plan and role allow. Whatever it remembers is stored as ordinary records you can review, edit and delete.

The tools cover notes, tasks, calendar, reminders, CRM and leads, mail, expenses, subscriptions, documents, knowledge base, ERP, logistics and HR. When a client connects, a consent screen shows which access it requests; the client acts on your behalf in that workspace only, and you can revoke access at any time in the settings.

Requests an agent can execute well

  • Name the object and the filter: “open leads from the Meta campaign, older than three days, without an owner”.
  • Ask for a list first, then for the change: “show them” before “create tasks for them”.
  • Say what the result should look like: a short table, three bullet points, a draft reply.
  • Give dates and people explicitly instead of “soon” or “the usual person”.
  • Ask the agent to remember recurring preferences, such as your working hours or report format, and check later what it stored.

MCP or the built-in assistant?

OrgLines also has its own AI assistant with memory and a knowledge base, working inside the app. It has a safe mode that only views data, and modes where actions run after confirmation or automatically. MCP is the better choice when your team already works in Claude every day and wants business data in the same chat; the built-in assistant suits people who prefer to stay in OrgLines.

Connecting Claude to OrgLines

  1. Create an OrgLines workspace or sign in.
  2. Open the MCP section in the settings and copy the server address.
  3. Add it as a connector in Claude (or another client that supports remote MCP servers).
  4. Sign in with your OrgLines account and review the requested access on the consent screen.
  5. Start with read-only questions, then let the agent prepare changes for your confirmation.

Common mistakes

  • Connecting an agent with an administrator account when a narrower role would do.
  • Confirming proposals without reading them.
  • Asking for one huge change instead of a few small, checkable steps.
  • Vague requests: “clean up the CRM” instead of “show leads without an owner older than 14 days”.
  • Forgetting clients you no longer use; revoke their access.

Checklist

  • Confirmations are enforced by the server, not only by the prompt.
  • The agent's account has only the role it needs.
  • You know where to revoke access.
  • You can see and delete what the agent remembers.
  • The first week is read-only questions, then small changes.

Try it free in OrgLines

FAQ

Frequently asked questions

What is MCP?

The Model Context Protocol is an open standard that lets AI assistants such as Claude use external tools and data sources in a controlled way.

Which AI clients work with OrgLines?

Claude and any other client that supports remote MCP servers.

Can the agent delete data or send emails on its own?

No. Destructive, external and financial actions always require your confirmation, and the server enforces it.

Does the agent see all my data?

Only the modules and data your plan and role allow, and only in the workspace you authorised.

Is the agent's memory hidden from me?

No. Everything it remembers is stored as ordinary records in your workspace. You can read, correct or delete each of them, or ask the agent to forget something.

How do I disconnect an AI client?

Revoke its access in the OrgLines settings. It can no longer act in the workspace after that.