Allies Group · internal service

AG MCP

The Allies Group agent capability surface.

AG MCP is an internal Model Context Protocol server. It lets approved AI assistants answer questions about Allies Group's own business systems. Every tool call is authenticated and attributed to the person asking, with the permission controls appropriate to the system being used.

What it connects to

Who can use it

Members of the Allies Group Microsoft 365 tenant, signing in with their own work account. There is no anonymous tool access. Business Central, personal Microsoft Graph operations and Azure DevOps use the signed-in user's delegated rights. Ordinary analytical-warehouse reads use a restricted service identity behind AG MCP's access controls. Known raw _gold and _bronze GL relations require Finance; specifically configured super-users can use an explicit delegated SQL path. Any raw relation keeps the whole statement restricted. The CAC marketing view is the shipped narrow curated exception; the general row-secured GL view remains planned. System Teams posts require an active SQL-backed AG MCP administrator and an exact configured destination, execute as AGBot, and attempt to audit the person who triggered them. Empty or malformed channel configuration denies every post.

How it authenticates

AG MCP is its own OAuth 2.1 authorization server, delegating sign-in to Microsoft Entra ID. It supports discovery per RFC 9728 and RFC 8414, dynamic client registration, and PKCE. Interactive sign-in happens at Microsoft, so AG MCP does not receive the user's password.

Status

Claude, ChatGPT and Microsoft 365 Copilot are live supported clients. Copilot discovery remains subject to the tenant's licensed-user and agent-access policies. Service health is published at /health.