Blog / Field guides

What is MCP (Model Context Protocol)? A guide for business teams

MCP is an open standard that lets AI tools connect to your CRM, database or shared drive in one consistent way. Here is how it works and what to check.

Xagent team · 7 October 2026 · 6 min read

What is MCP? MCP (Model Context Protocol) is an open standard that lets AI applications connect to outside systems in one consistent way. A company puts a system, such as a CRM or database, behind an MCP server. Any AI tool that supports MCP can then find and use that system’s tools and data, within the permissions the server allows.

The MCP project describes it as a USB-C port for AI applications.

How does MCP work?

MCP works through three roles. A host is the AI application a person uses. The host creates one client for each server it connects to. Each server is a program that usually exposes one system, such as a ticketing tool or a warehouse database.

The MCP specification lists three things a server can offer. Its latest version is 2026-07-28, as of October 2026.

  • Resources, which are context and data the AI can read, such as a customer record or a policy document.
  • Prompts, which are templated messages and workflows.
  • Tools, which are functions the AI model can run, such as “create a ticket” or “look up an order”.

Messages use a format called JSON-RPC 2.0. A business team does not need to know more than that.

Servers also come in two forms. The architecture documentation says a local server usually serves a single client. A remote server usually serves many clients. That makes a remote server the natural fit for a shared company system.

What is an MCP server? Some examples

An MCP server is a small service that sits in front of one system and tells AI tools what they can do with it. It lists the available tools and data, and it runs the requests that come in.

Anthropic released MCP on 25 November 2024, with pre-built servers for systems including Google Drive, Slack, GitHub and Postgres. As of October 2026, the project’s servers list shows all four as archived, and Slack’s is now maintained by another company. The kinds of server still make good examples:

  • A shared drive server lets an AI tool find and read documents your team already stores there.
  • A database server lets an AI tool run queries against a warehouse or orders database.
  • A server you build yourself can expose an internal system, such as a ticketing queue or a CRM, with only the actions you choose.

For many teams the most useful case is the last one, because internal systems rarely have a ready-made server.

MCP vs API: what is the difference?

An API is how one piece of software talks to another. MCP is a shared way for AI tools to discover and use those APIs. In practice, an MCP server usually wraps an existing API, so the two work together.

Direct API integrationMCP
SetupOne custom connection for each pair of AI tool and systemOne server for each system; a remote server can be shared by every AI tool that supports MCP
DiscoveryA developer reads the documentation and writes the callsOnce the server is built or installed, the AI tool asks it what it offers
Best whenOne app talks to one system and rarely changesSeveral AI tools need the same systems
UpkeepEach connection is maintained separatelyOne server to maintain, kept current with the MCP version your AI tools support
SecuritySet by your code and the API’s own controlsThe protocol defines authorisation, but your servers and AI tools must enforce it

A direct integration is the better choice when you have one application and one system. It is simpler, and you control every detail. Anthropic’s launch post pointed to the problem MCP addresses: every new data source needed its own custom implementation. That cost grows with every new system, and again with every new AI tool.

Why does MCP matter for business teams?

MCP matters because many teams now use more than one AI tool, and each one needs access to the same systems. Without a shared standard, your IT group builds and maintains a separate connection for every combination.

With MCP, a support lead’s AI assistant and a sales lead’s AI assistant can use the same ticketing and CRM servers. IT can set what each system allows at the server, in one place. Each AI tool still needs its own approval settings.

The standard has also moved beyond one vendor. The Linux Foundation announced the Agentic AI Foundation on 9 December 2025, with MCP among its founding contributions. Other vendors support it as well. As of October 2026, OpenAI’s documentation describes giving models new capabilities through remote MCP servers, and Microsoft Copilot Studio supports MCP tools and resources. Copilot Studio does not list prompts as supported.

What are the risks, and what should IT check?

MCP does not enforce security by itself. The specification states that it cannot enforce its own security principles, such as user consent and access control, at the protocol level. Your servers and your AI applications have to do that.

Here is what the person approving a tool should check:

  • Who built the server. The MCP project’s security best practices describe local server compromise, where an attacker hides a malicious payload inside the server itself. Run only servers you trust.
  • What the server can do. The same guidance recommends starting with a minimal scope, limited to low-risk discovery and read operations. It then recommends asking for more access only when a privileged action is first needed.
  • Who is responsible. Microsoft’s Copilot Studio documentation covers this, as of October 2026. If you connect an external MCP server, you are responsible for the tools and resources you access from Copilot Studio.
  • Whether a person confirms actions. The specification’s security principles say hosts must get explicit user consent before invoking any tool. The protocol cannot enforce this itself. Check whether your AI application asks before it acts, and who can switch that off.

How to start with MCP

Start with one system and read-only access. The risk stays low, and you find out early whether the setup is worth extending.

  1. Pick one system that several people already ask AI tools about, such as a ticketing queue or a shared drive.
  2. Check whether the vendor already offers a server for it. If a server comes from someone else, check who maintains it before you use it.
  3. Give the server read-only access first, with the narrowest scope that does the job.
  4. Connect one AI tool that supports MCP and test it on real questions from your team.
  5. Review what the AI tool did, then decide whether to add write actions or a second system.

If you want a hands-on example, our guide to connecting your systems through MCP walks through the steps in Xagent.

Xagent is an enterprise agent platform by Xinference. It has native connectors for Google (Gmail, Calendar, Drive, Maps), Microsoft (Outlook, Teams, OneDrive), Meta (Facebook, Instagram) and LinkedIn. Other systems, including internal ones, connect through MCP servers. Every tool call and result is visible while a task runs. To see how that would look with your own systems, book a demo.

Questions

Does OpenAI support MCP?

Yes, on the developer side. As of October 2026, OpenAI’s API documentation describes connecting models to remote MCP servers. Tool calls can run automatically or wait for the developer’s approval.

How does MCP compare with RAG?

RAG retrieves information to inform text generation. According to Google Cloud, it is not typically used to run actions in external systems, whereas MCP standardises how AI tools connect to those systems. In practice, an agent can use RAG to look things up and MCP to act.

Is MCP just an API?

No. An API is how software exposes a system, and MCP is a standard way for AI tools to find and use that exposure. An MCP server often wraps an existing API.

Who owns MCP?

Anthropic released MCP in November 2024. In December 2025 it became one of the founding contributions to the Agentic AI Foundation, formed under the Linux Foundation. The foundation now gives MCP a vendor-neutral home.

Is MCP still relevant?

Yes. The latest specification is dated 2026-07-28. As of October 2026, OpenAI and Microsoft both document MCP support in their own developer tools.

Try Xagent. See all use cases, or book a demo on your own workflow.

Stop repeating the same work.

Book a demo on your own workflow. We will hand the busywork to agents while you watch.

Book a demo

Discover more from Xagent

Subscribe now to keep reading and get access to the full archive.

Continue reading