Building MCP into a SaaS: Why Human Judgment Still Governs AI Tool Design
A developer building PontoBarato, a small SaaS for Brazilian businesses to manage employee work hours, integrated a Model Context Protocol (MCP) interface to let owners manage tasks via natural language through tools like ChatGPT or Claude. While AI assistance sped up implementation, the developer found that critical decisions around trust boundaries, permissions, and scope could not be delegated to the model. A key security rule was established: company scope must always derive from the authenticated session, never from identifiers supplied or generated by the AI. Rather than exposing a broad database access tool, the developer designed narrow, role-specific tools mapped to recognizable business actions such as creating employees, assigning shifts, and checking hour balances. The experience highlighted that conversational interfaces introduce ambiguity that structured forms avoid, making human-defined boundaries essential before expanding an AI tool's capabilities.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in