Dashboard

CRM assistant over MCP

An assistant that does real CRM work through tools reached over MCP, with approval on the calls that write.

The problem

An assistant that can only talk is half a tool. Users want it to actually do the CRM work — create a lead, log a call, send a follow-up — but hardcoding each integration is brittle and every new tool means new glue code.

You want the assistant to reach real tools over MCP, so the tools live behind a standard protocol instead of bespoke wiring, with approval on the ones that write. Add a tool by connecting a server, not by editing the agent.

Architecture

The agent talks to tools through one protocol. A user asks, the agent decides which tools it needs, it calls them over MCP where each integration is a server, the CRM actions run, and the agent reports what it did. MCP is the seam that lets you add a tool without touching the agent.

A user in, real CRM actions over MCP, a reply out
readswritesconfirmedA usera sales repThe agentpicks the toolsApprovalwrites onlyYour MCP serverthe only way inThe CRMvia ComposioThe replywhat it did
Hover or tap a piece to see what it does.

Put approval on the writes, not the reads. Looking a contact up is safe to do freely; creating a lead or sending an email is a call that should be confirmable, and the protocol boundary is a natural place to enforce it.

What it draws on

Everything here comes from this stage of the roadmap; the project is where those courses meet.

What done looks like

RequirementDone when
MCPThe CRM is reached only through your MCP server
PermissionsA rep never sees another rep's accounts
DraftsEmails are drafted, never sent, without approval
FailureAn expired token produces a clear message, not a crash

Where to start

Get the agent calling one read-only tool over MCP before anything writes. Prove the protocol path end to end, then add a write tool with an approval step. Adding the third tool should be a matter of connecting a server — if it means editing the agent, the seam is in the wrong place.

Composio and MCP servers hold their own credentials; the agent's model runs on a free Groq or Gemini key.
Back toAll frameworks

Every expert started right here.