This website uses cookies

Read our Privacy policy and Terms of use for more information.

MCP (the Model Context Protocol) is what lets Claude read your Gmail, pull a QuickBooks report, or check your calendar without you copying and pasting any of it into a chat window. Three separate newsletters covered a piece of this the same week: Adobe wired its creative suite into Slack, a solo creator built a read-only MCP server over his own content archive, and a wearable started piping conversations straight into Claude. The pattern underneath all three: your AI assistant is turning into a real front end for the tools you already run, and the practical starting point for a small business is one read-only connection, not a dozen at once.

The Five Desks: Where to Start

Anthropic's own Claude for Small Business package (shipped inside Claude Cowork, May 13, 2026) organizes a business into five functional areas instead of a pile of individual app connections:

  • Connect: social feeds and content, e.g. Metricool or Canva

  • Leads: your inbox and CRM, e.g. Gmail and HubSpot

  • Money: accounting and invoicing, e.g. QuickBooks or PayPal

  • Admin: scheduling and agreements, e.g. Google Calendar and DocuSign

  • Knowledge: documents and SOPs, e.g. Google Drive or a local markdown folder

The advice across every case study covering this is the same: pick one desk, not all five. Most people's first instinct is to wire up every app they use on day one. The developer docs explicitly warn against it. Start with the desk that has the least downside if something goes wrong, usually Knowledge, and get comfortable before expanding.

The Golden Rule: Look Free, Change Never

The desk you're most likely to hesitate on is Money. Connecting QuickBooks or Stripe raises an obvious question: what stops an AI from hallucinating and zeroing out an invoice, or double-paying a vendor?

The answer is in how a read-only MCP connection is actually built. A read-only MCP connection grants a restricted API token that only carries GET requests, not mouse-and-keyboard access to the software. Claude can pull your profit-and-loss statement into its context window to answer a question, but it has no software command available that pushes a change back to your ledger. That's the rule: look free, change never. It's a one-way mirror: the AI observes and queries, but it can't reach through the glass.

From Read-Only to Read, Draft, Approve

Read-only analysis is the first rung. The next one is letting Claude take action (drafting a client email based on what it found, for instance) without letting it act unsupervised. The workflow that makes this safe is read, draft, approve: Claude reads an incoming booking inquiry, checks your calendar via API, and drafts a tailored response, but it doesn't send it. The draft queues and waits for you.

Think of it like a prepared tax return: the software pulls your numbers, fills out the forms, and runs the math, but it can't submit anything to the government until a human reviews it and clicks the final "sign and file" button. That's the friction that matters, and it's been moved from the creation phase, where it used to slow you down, to the approval phase, where it should live.

The One Setting to Never Touch: "Always Allow"

Every one of these safety flows depends on a single habit: never click "Always Allow" when a connected tool asks for write permissions. Clicking it once removes your own approval step permanently. It's the equivalent of letting the AI submit that tax return on its own from then on. Bypassing manual review on a write-capable connection is where small businesses get into trouble, not the connection itself.

The Bigger Picture

None of this requires buying a dozen new AI apps. It requires connecting the handful of tools you already use, one desk at a time, and shifting your own role from doing the data entry to directing and approving the work. If there's a repetitive, copy-paste-heavy task eating up your mornings right now, that's the one worth connecting first. The difference between doing it manually and reviewing a thirty-second approval click is the entire point of MCP for a small operator.

FAQ

What is MCP in plain terms?
MCP (Model Context Protocol) is a standard that lets an AI assistant like Claude connect directly to business tools (email, accounting software, calendars, CRMs) instead of you manually pasting information into a chat every time you need help with it.

Is it safe to connect QuickBooks or Stripe to Claude?
Yes, if the connection is read-only. A read-only MCP connection only grants GET-request access, meaning Claude can see your data to answer questions but has no technical ability to write, edit, or delete anything in the underlying system.

How many tools should I connect at once?
One. Every case study and developer guide covering this converges on the same advice: pick a single "desk" (Connect, Leads, Money, Admin, or Knowledge), connect one tool read-only, and only add a second desk once the first is clearly saving you time.

What's the single most important safety rule?
Never click "Always Allow" when a connected tool requests write permissions. Keep every write-capable action (sending an email, updating a record, issuing a payment) behind a manual approval click, every time.

Companion episode:

Want more breakdowns like this? Head to joebuildsai.com for daily AI agent and automation coverage built for solo operators and small teams.

Reply

Avatar

or to participate