MCP Server and Agent Tools
Let outside AI clients work on your portfolio through a tool catalog that separates read-only calls from writes and destructive actions.
These images are illustrations of the concept, not screenshots of the actual product.
Overview
The MCP concept opens the portfolio to AI clients that live outside Subscriber Bot. Instead of a general-purpose integration that can do anything, the design publishes a catalog of named tools — list relationships, fetch one by identifier, create a tracked relationship, list inbox messages, change an agent's posture, attach a policy, activate a draft workflow — each declaring what it does, what it needs and whether it only reads.
Connecting an assistant to financial and contractual records is exactly where a vague integration becomes dangerous. A tool that cancels a subscription and a tool that lists subscriptions should not look alike in a client's tool list, and whether a call requires confirmation should be visible before it is made rather than discovered afterwards. This console makes those distinctions part of the catalog itself.
The illustrated view is built around that idea. A header shows the server, its connection state, the transport in use and the endpoint it is pointed at, with the identity the session is acting as on the right. Three tiles count the domain tools, the platform modules behind them and — highlighted as an attention state — the tools classified as destructive. A search field and read-only, write and destructive filters narrow a long catalog quickly.
The catalog itself is a table with a column for the tool name, the area it belongs to, whether it reads or writes, whether confirmation is required, and a plain description of what it does. Destructive rows are tinted and marked with a warning icon, so cancelling a relationship, archiving a provider and removing a payment instrument stand apart from the reads around them. Selecting a row opens a detail panel with the tool's purpose, its required inputs and their types, and the result the last call returned — including error text, so a failed call is diagnosable from the same panel.
A warning strip along the foot of the page flags that confirmation is not being required for the destructive tools, which is the point of the whole design: the governance state is shown rather than assumed. The catalog mirrors the same posture and policy thinking that governs the built-in agents, extended to whatever client is connected.
What this concept shows
- A header showing the server name, its connection state, the transport in use and the identity the session acts as
- Tiles counting domain tools, the platform modules behind them, and the tools classified as destructive
- A search field plus read-only, write and destructive filters for narrowing a long catalog
- A tool table with columns for name, group, read or write annotation, confirmation and a description, spanning relationships, providers, payments, inbox, agents, workflows and health
- Destructive rows tinted and marked with a warning icon, separating cancellations, archives and removals from reads
- A per-tool detail panel listing required inputs with their types and the result of the last call, error text included
- A warning strip that surfaces when confirmation is not being enforced for destructive tools
- A side rail for the connection, tools, resources, reusable instruction templates and an activity log
How it works
- Open the console and check the header for the connection state, the transport and the endpoint in use.
- Read the tile counts to see how large the catalog is and how many of its tools are classified as destructive.
- Filter to read-only, write or destructive tools, or search by name to find a specific one.
- Scan the table for the annotation and confirmation columns to see what a tool does before allowing a client to call it.
- Select a tool to review its purpose, its required inputs and their types in the detail panel.
- Check the last result for that tool to confirm what happened, and review the activity log for the wider history.
Who it's for
- Developers connecting an AI client or assistant to a subscription portfolio
- Platform and integration engineers evaluating what a connected tool may do
- Security reviewers checking which calls are destructive and whether confirmation is enforced
- Power users automating portfolio work from an external tool
Illustrations
1 illustration of this concept. Select one to view it full size.
Tool Catalog with Annotations and Tool Detail
A dark console whose header names the server, shows a connected state, the transport in use and the endpoint it points at, with the acting identity on the right. A side rail lists the connection, tools, resources, reusable instruction templates and an activity log. Three tiles count domain tools, platform modules and, in a red attention state, destructive tools. A filter field and read-only, write and destructive toggles sit above a table whose columns cover the tool name, its group, a read-only or write annotation, whether confirmation is required, and a description. Rows are grouped by area such as relationships, providers, payments, inbox, agents, workflows and health, and three destructive rows are tinted and flagged with a warning icon. A detail panel shows the selected tool's purpose, its required inputs with types, and the last result in an error-tinted block. A strip at the foot warns that confirmation is not being enforced.
Topics
- MCP server
- Model Context Protocol tools
- agent tool catalog
- read-only versus write tools
- destructive tool confirmation
- AI client integration
- subscription API for agents
- tool annotations and inputs
- governed AI integration
- stdio transport connection
Related concepts

Governed AI Agents and Autonomy Controls
Specialized agents watch your portfolio and propose actions, while posture settings, policies and interlocks decide what they may do alone.
4 illustrations
Screen-Aware Assistant
An assistant docked beside the record you are already looking at, answering from that subscription's own plan, invoices and renewal history.
1 illustration
Workflow Automation
Turn a recurring event into a reliable routine: classify what arrives, match it to a subscription and branch into the right follow-up.
1 illustration
Subscription Relationships
Every subscription, membership, license and contract as one record with its plan, payment, entitlements, health and renewals.
3 illustrations