Applied AI engineering
AI agents and MCP servers
Two kinds of work. Internal agents that read and act across your databases, APIs, chat and CRM, with scoped permissions, an audit trail and confirmation for anything irreversible. And making your SaaS agent-ready: a Model Context Protocol (MCP) server for your product, so your customers' AI assistants can use it safely.
- Timeline
- Agreed per project after a scoping call
- Price
- Fixed-scope quote after a scoping call
- Engagement
- Fixed-scope project
Is it a fit?
For
- Operations, support and finance teams with repetitive multi-step work across several tools
- SaaS companies whose customers ask how to use the product from ChatGPT, Claude or Copilot
- Teams that tried an agent framework and couldn't make it safe enough to deploy
Not for
- Fully autonomous agents with unrestricted access to production systems
- Workflows with no clear definition of a correct result
What you get
- An agent or MCP server with the tools it needs, and nothing more
- Scoped credentials, permission checks and human confirmation for risky actions
- An audit log of every tool call and its inputs
- An evaluation set of realistic tasks, including attempts to misuse the agent
- Documentation for your team, and for your customers if the server is public
How it runs
- 01
Map the work
Which tasks, which tools, which data, and which actions need a person's approval.
- 02
Design the tools
Narrow, well-described tools with the least access that does the job.
- 03
Build and test
The agent or MCP server, tested against realistic tasks and deliberate attempts to misuse it.
- 04
Roll out
To a small group first, with logs reviewed, then wider.
Typical stack: Model Context Protocol · Anthropic API · OpenAI API · TypeScript · Python · PostgreSQL · OAuth 2.0
Questions
What is MCP?
The Model Context Protocol is an open standard for connecting AI assistants to tools and data. An MCP server describes what your system can do; assistants that support MCP can then use it, within the permissions you set.
Is our data safe with an agent?
Agents get only the tools and data a job needs, through credentials scoped to that job. Sensitive actions need a person to confirm, and every call is logged. Where data can't leave your infrastructure, the model can run inside it.
Can agents take actions, or only answer questions?
Both. Reading is low-risk. Writing, sending and deleting go through explicit confirmation, or run automatically only in narrow, well-tested cases.
Sources
More in applied ai engineering
- AI features in your product: LLM features that work on your real data, measured before they ship.
- LLM evals, guardrails and cost control: Know whether your AI feature is getting better or worse, and what it costs.
Tell me about your project.
A short brief is enough to start. I’ll reply with questions, a suggested first step and when I could begin.