Agents

What agent access is in Scipio ERP 4.0: an MCP endpoint per application, a token as a user login, default deny.

Scipio 4.0 exposes every application webapp to an AI agent through the Model Context Protocol (MCP), over Streamable HTTP. Each application has its own endpoint, for example /ordermgr/mcp for orders or /accounting/mcp for accounting; /admin/mcp is the hub that reaches every application from one connection.

The token is a user login#

An MCP access token is not a separate credential type. Every token points at one userLoginId. An agent that connects with a token acts as that user, with exactly that user’s permissions. No permission comes from the token itself. Scipio ships a seed user, scp-agent, in the read-only SCIPIO_AGENT security group, for a first connection.

Default deny#

A call passes only when every gate in the policy engine allows it: server access (MCP_ACCESS, the webapp’s base _VIEW permission), tool access, a service deny list, gateway permission for a direct service call, read-only classification for a read-only token, the service’s own declared permissions, and a component-level base permission for any service the earlier gates did not already decide. The first failing gate denies the call.

One audit row per call#

Every tool call writes one McpAuditLog row, whether it was allowed or denied. Webtools > Agent Access > Audit lists them, with a DENIED filter for blocked attempts.

  • Quickstart : create a token and connect a client in five steps.
  • Security : the permission model, the policy engine, tokens, and the operations checklist.
  • Extending agent access : add a tool, a server profile, a provider, or a skill.

Ask the people who wrote it.

Support, development and training from the team that builds Scipio ERP.