AI Automation, RAG & MCP
6 min read
By UnlockLive IT engineering team
Diagram of an AI assistant connected to a CRM through an MCP server with per-user permissions and an approval step for updates

Your CRM holds the answers your sales team needs every morning. Which deals have gone quiet? Who has not been contacted since the demo? Which renewals close this month? Getting those answers usually means building a report, exporting a spreadsheet or asking the one person who knows the filters.

That friction costs more than time. Follow-ups slip, managers review pipelines from stale numbers, and reps update records late or not at all. The data is there. The problem is that asking it a plain question is still hard.

What this does

MCP (Model Context Protocol) is an open standard introduced by Anthropic. It lets AI assistants such as Claude, and other clients that support it, connect to tools and data through small programs called MCP servers. Support varies by AI client, so check each client's current documentation before you plan a rollout.

A CRM MCP server sits between the assistant and HubSpot, Salesforce, Pipedrive or a similar system. It exposes a short list of well-defined tools, such as "find stalled deals", "get account history" or "draft a follow-up". A rep can then ask:

  • "Which deals in my pipeline have had no activity in the last seven days?"
  • "Summarise everything we know about this account before my call."
  • "Draft a follow-up email for each deal stuck in the proposal stage."
  • "Move this deal to negotiation and log today's call." (only after approval)

The assistant answers from live CRM data, cites the records it used, and never touches anything the user could not already see.

A Monday morning example

Picture a sales manager starting the week. She asks the assistant which deals over a set size have had no activity for ten days. The server calls one tool and returns six deals, each with the owner, stage and last touch. She asks for a one-line summary of each. The assistant pulls notes and recent emails through a second tool.

Next she asks for follow-up drafts for the three oldest deals. The assistant writes them in her team's tone and saves them as drafts in the CRM. She edits one, approves all three, and the server logs the change. The review takes minutes instead of an hour of clicking through filtered views.

Nothing in that flow needed a new dashboard. It used the CRM the team already trusts, with the permissions they already have.

How it works, step by step

  1. Pick the questions. We list the ten or so questions your team asks most. These become the first tools.
  2. Design narrow tools. Each tool does one job with clear inputs. "List deals by stage and last activity date" is better than "run any CRM query".
  3. Connect per user. Each person signs in with their own CRM account, using OAuth where the client supports it. The server calls the CRM with that user's permissions.
  4. Ship read-only first. The first version only reads. Your team gets value immediately with no risk of bad writes.
  5. Add drafting. The assistant drafts follow-up emails and notes. A person reviews and sends them.
  6. Add approved updates. Narrow write tools, such as "update deal stage" or "log a call", show a preview. Nothing is saved until the user approves.
  7. Log and review. Every tool call is logged with the user, inputs and result. We review the logs with you in the first weeks.

Tools we use

  • MCP SDKs for TypeScript or Python, depending on your team's skills.
  • Python with FastAPI when the server also needs a small web API or admin screens.
  • Your CRM's official REST API and its OAuth flow, rather than scraping or shared admin keys.
  • n8n where a CRM action should trigger a wider workflow, for example a Slack alert when a deal moves stage.

APIs, rate limits and connector offerings change. We check the vendor's current documentation and integrations at the start of every project, and you should too.

What you need to get started

  • Admin access to your CRM, or someone who can create an API app and approve scopes.
  • A list of the questions and actions your team wants, ranked by value.
  • An agreed AI client, such as Claude, and confirmation that it supports the MCP features you need.
  • A decision on which fields are off-limits, for example personal phone numbers or contract values.
  • One or two sales users willing to test early versions and give blunt feedback.

Typical scope and timeline

As an estimate, a first read-only version with a handful of tools typically takes one to three weeks. The range depends on the CRM, how custom your data model is, and how authentication works in your setup. Drafting tools usually come in the same phase. Approved write actions are normally a second phase, once the team trusts the read-only answers.

Risks and how we handle them

Over-broad access

A server that uses one shared admin key lets every user see everything. We authenticate each user and pass their identity through, so CRM permissions still apply.

Wrong or unwanted writes

Language models can misread intent. Writes are limited to a few narrow tools, each with a preview and an explicit approval step. Bulk updates are not offered at all in the first version.

Prompt injection from CRM content

An email or note stored in the CRM could contain text that tries to instruct the assistant. We treat tool outputs as data, keep write tools behind approval, and test with planted instructions. Our MCP server security checklist covers this in more depth.

Rate limits and cost

CRM APIs have limits. We cache safe reads, cap result sizes and back off politely when the CRM asks us to.

When not to build this

Your CRM vendor or AI client may already offer an official connector. If it answers your questions with the permissions you need, try it first. A custom build also makes little sense if your CRM data is badly out of date. The assistant will answer confidently from bad records. Fix the data habits first. Finally, if you only need a weekly pipeline summary, a scheduled report may be simpler. See our guide to automated KPI reports in Slack and Telegram.

If your main pain is slow responses to new leads, rather than questions about existing deals, start with automated lead follow-up with n8n. For actions that need sign-off, read AI agents with human approval.

How UnlockLive can help

UnlockLive IT is a Toronto-headquartered software agency with its own engineering team. We build these integrations for companies in the US, Canada, the UK and Australia. Our MCP server development service covers scoping, the threat model, the build, deployment and ongoing maintenance. Is the CRM work part of a wider sales or operations workflow? Our AI Workflow Automation team connects the pieces with n8n and approval steps.

If you want a second opinion on scope or risk, book a free 30-minute call. Bring one or two questions your team asks every week, and we will tell you honestly whether an MCP server is the right tool.

Frequently asked questions

Can Claude connect to HubSpot, Salesforce or Pipedrive?

It can through an MCP server, either one the vendor provides or a custom one built for your account. Check your CRM vendor's current integrations and your AI client's documentation, because official connectors and client support change often.

Is it safe to let an AI assistant update CRM records?

It can be, if writes are limited and approved. A safe design starts read-only, then adds a small number of narrow update tools that show the user a preview and require explicit approval before anything is saved. Every change is logged with who approved it.

Does the AI see all of our CRM data?

It should not. A well-built MCP server authenticates each user and calls the CRM with that user's own permissions. The assistant only sees records the user could already open, and sensitive fields can be excluded entirely.

How long does it take to build a CRM MCP server?

A first read-only version typically takes one to three weeks, depending on the CRM, the number of tools and how authentication works in your setup. Adding approved write actions is usually a second phase.

Do we need a new CRM or a data warehouse first?

No. An MCP server works with the CRM you already use through its existing API. A warehouse can help for heavy historical reporting, but most day-to-day sales questions can be answered from the CRM directly.

What is an MCP server?

MCP, the Model Context Protocol, is an open standard for connecting AI assistants to tools and data. An MCP server is a small service that exposes a set of named tools, such as searching deals or reading a contact, which a compatible AI client can call. For a CRM, it sits between the assistant and the CRM's API and enforces each user's permissions.

How we can help

  • MCP Server Development ServicesCustom Model Context Protocol (MCP) servers that expose your APIs, databases, and internal tools to Claude, Cursor, ChatGPT, and any MCP-compatible AI.
  • AI Workflow AutomationAI automations on self-hosted n8n for lead follow-up, invoices, support triage, reports and documents, with Telegram, WhatsApp or Slack alerts and approvals.
  • AI Agent DevelopmentProduction AI agents with LangChain, OpenAI Agents SDK, and Claude. RAG, tool use, multi-agent orchestration, voice, and browser-using agents.

Talk to an engineer about your project

Tell us what you are building. We reply within one business day with a candid view on scope, approach and effort.

Book a free strategy call

Written by the UnlockLive IT engineering team. UnlockLive IT Limited works with clients through its Toronto headquarters and delivers engineering from its Dhaka delivery centre. About us

Related articles

AI Automation, RAG & MCPn8n AI Agents That Take Actions Safely: MCP Tools and Human ApprovalAI Automation, RAG & MCPAI Build vs Buy: An Honest Framework for Choosing Off-the-Shelf or CustomAI Automation, RAG & MCPStop Retyping Forms and PDFs: AI Document Extraction into Your ERP or CRM

Contact Us

Fill out the form below and our team will get back to you shortly to assist with your inquiry.