Stop 8 of 10 · Weekly
MCP to internal docs
A read-only connector to the team's reference library, an allow list of what it may reach, an explicit deny list of what it must never see, and a denial test set that proves the boundary holds.
The library nobody can find anything in
Fadi's team has eight years of good material: reference architectures for state agencies, an answer bank of compliance responses that survived assessment, quota references, migration patterns from twenty county projects. It sits across a documentation site and a shared drive, and finding the right one takes longer than rewriting it badly, so people rewrite it badly.
An MCP connector turns that library into something Claude reads while drafting. It also turns it into a surface, which is why this stop is mostly about what the connector cannot reach.
Scope at the grant, not in the prompt
The boundary lives in the access grant. An instruction that says do not use confidential material is a request to a system that cannot reliably tell what is confidential.
| Allowed | Denied |
|---|---|
| Published reference architectures | Every customer folder, without exception |
| The compliance answer bank | Deal documents, forecasts, competitive files |
| Service quota and limit references | The pricing space, published or not |
| The migration pattern library | Draft and personal spaces |
Read scopes only. No write scope is granted at the server, so a mistaken instruction cannot create, edit or delete a document. That stays true for at least a month of daily use, and longer if there is no clear reason to change it.
Using the documentation connector, find every published reference architecture and migration pattern we have for county government records platforms moving off on-premises databases. For each one: what it covers, which of our design decisions on the Calverton County account it supports or contradicts, and the document identifier so I can open it. If our library has nothing on a decision, say so rather than answering from general knowledge, and mark that as a gap in the library.
Using the connector, find the answers we have previously given to questions about data residency, key management and background screening for state and local customers. Draft the Rio Seco response for each, quoting the source answer and its document identifier, and flag any place where our previous answer no longer matches the architecture in this Project. Do not blend two answers into one without telling me you did it.
The flag is the value. Answer banks decay, and a previous answer that no longer matches the current design is the single most expensive thing in an RFP submission.
The test that proves the boundary
Ten queries that should return nothing, run against the connector, written down and re-run whenever the grant changes.
I am testing the scope of my documentation connector. Run each of these searches against it and report only what it retrieved, with document identifiers, or that it retrieved nothing. Search for: Calverton County contract; discount approval; unreleased pricing; forecast commit; any document containing an access key; any customer network diagram; any file in a personal or draft space; anything about a competitor deal; any document naming a named account manager and a rate; any student or records data extract. Do not summarise, do not decline, do not tell me what you would not quote. I need the raw retrieval result for each one, because a retrieval I did not expect is a scoping failure whatever you then chose to do with it.
Anything retrieved is a grant to fix, not a prompt to fix.