Academyby Dasow

Stop 8 of 10 · Weekly

MCP to internal docs

A read-only connector to the team's reference library, an allow list of what it may reach, an explicit deny list of what it must never see, and a denial test set that proves the boundary holds.

Watch first · 0:55

The library nobody can find anything in

Fadi's team has eight years of good material: reference architectures for state agencies, an answer bank of compliance responses that survived assessment, quota references, migration patterns from twenty county projects. It sits across a documentation site and a shared drive, and finding the right one takes longer than rewriting it badly, so people rewrite it badly.

An MCP connector turns that library into something Claude reads while drafting. It also turns it into a surface, which is why this stop is mostly about what the connector cannot reach.

Scope at the grant, not in the prompt

The boundary lives in the access grant. An instruction that says do not use confidential material is a request to a system that cannot reliably tell what is confidential.

Allowed Denied
Published reference architectures Every customer folder, without exception
The compliance answer bank Deal documents, forecasts, competitive files
Service quota and limit references The pricing space, published or not
The migration pattern library Draft and personal spaces

Read scopes only. No write scope is granted at the server, so a mistaken instruction cannot create, edit or delete a document. That stays true for at least a month of daily use, and longer if there is no clear reason to change it.

Use the connector while drafting
Using the documentation connector, find every published reference architecture and migration pattern we have for county government records platforms moving off on-premises databases.

For each one: what it covers, which of our design decisions on the Calverton County account it supports or contradicts, and the document identifier so I can open it. If our library has nothing on a decision, say so rather than answering from general knowledge, and mark that as a gap in the library.
Draft an RFP answer from the answer bank
Using the connector, find the answers we have previously given to questions about data residency, key management and background screening for state and local customers.

Draft the Rio Seco response for each, quoting the source answer and its document identifier, and flag any place where our previous answer no longer matches the architecture in this Project. Do not blend two answers into one without telling me you did it.

The flag is the value. Answer banks decay, and a previous answer that no longer matches the current design is the single most expensive thing in an RFP submission.

The test that proves the boundary

Ten queries that should return nothing, run against the connector, written down and re-run whenever the grant changes.

Run the denial test set
I am testing the scope of my documentation connector. Run each of these searches against it and report only what it retrieved, with document identifiers, or that it retrieved nothing.

Search for: Calverton County contract; discount approval; unreleased pricing; forecast commit; any document containing an access key; any customer network diagram; any file in a personal or draft space; anything about a competitor deal; any document naming a named account manager and a rate; any student or records data extract.

Do not summarise, do not decline, do not tell me what you would not quote. I need the raw retrieval result for each one, because a retrieval I did not expect is a scoping failure whatever you then chose to do with it.

Anything retrieved is a grant to fix, not a prompt to fix.

Quick check

Try it

Report a bug or share feedback