Reuben AI guides
MCP and AI tool access for private capital
Private capital vendors are starting to publish MCP servers so that general assistants can query and update firm data from a chat window. The protocol is straightforward. The governance question underneath it, which is what an outside assistant is permitted to do with fund records, is the part that deserves the attention.
Short answer
What does MCP access to a CRM or fund platform actually grant, and what should a firm settle first?
MCP, the Model Context Protocol, is an open standard that lets an AI assistant call tools exposed by another system. If a vendor publishes an MCP server, an assistant can read from and, where permitted, write to that vendor's data. The protocol itself carries no opinion about permissions, so the questions that matter are which records are exposed, which actions are allowed, who authorised the connection, and whether every action is recorded.
What MCP is, in plain English
The Model Context Protocol is an open specification for how an AI assistant discovers and calls tools that live in another system. A vendor publishes an MCP server describing the actions it supports. An assistant connects to that server, sees the available actions, and can call them on the user's behalf.
In practice this is what allows someone to ask an assistant to pull up a company record, add a note or update a status without opening the underlying application. The specification is public and vendor neutral.
MCP replaces a category of bespoke plugin work. It does not, by itself, decide anything about who may do what.
Where the private capital category is on MCP
Adoption in private capital software is early but visible. Affinity has publicly announced an MCP server allowing assistants to prepare for meetings, add notes and update deal status from a chat interface (see affinity.co for their own description). Other vendors are exposing data to assistants through plugins and connectors that solve a similar problem in a different way.
The pattern is the same in each case: a window into one system, in natural language. The reach of that window is the reach of the system behind it.
For a firm running a CRM, a portfolio tool, a fund administrator's system and a document store, connecting an assistant to one of them still leaves the assistant unable to answer questions that span the workflow.
The governance questions to settle before connecting anything
The risk profile of an assistant that can read a contact list is not the risk profile of an assistant that can change a valuation or issue a capital call. Firms should be explicit about which side of that line each connection sits on.
- Scope: exactly which records and fields the connection exposes.
- Direction: read only, or read and write.
- Authorisation: the named person who approved the connection.
- Expiry and revocation: how the connection is ended, and by whom.
- Record: whether every action taken through it is logged in a way an auditor can follow.
- Residency: where the request and any returned data are processed.
Mandate tokens: the answer to what an assistant may do
Reuben AI's approach to agent permissions is the mandate token. Rather than an agent inheriting a user's full rights, it is issued a bounded mandate: a defined scope over defined records, for a stated purpose, granted by a named person, with an expiry and an immutable record of every action taken under it.
That model is protocol independent. It applies to an agent working inside the platform and to any external assistant reaching in. The point is that the permission decision sits with the firm and is reviewable later, rather than being implied by whoever happened to authenticate the connection.
If you are evaluating any assistant integration, in any product, this is the layer to interrogate. The protocol is the easy part.
What a well governed assistant connection looks like
A firm should be able to answer, without engineering help, which assistants are connected, what each is allowed to do, who approved it, and what it has done. If any of those answers requires a support ticket, the connection is not governed.
The same standard applies to output. An assistant-produced figure that lands in a board pack or an LP letter needs a path back to the records it drew on and the version of those records at the time.
Common questions
- What is MCP?
- The Model Context Protocol is an open standard that lets an AI assistant discover and call tools exposed by another system. A vendor publishes an MCP server, an assistant connects to it, and the assistant can then read from or write to that system on a user's behalf.
- Do private capital CRMs support MCP?
- Some do. Affinity has publicly announced MCP support that lets assistants prepare for meetings, add notes and update deal status. Adoption across the wider category is uneven, and other vendors expose data to assistants through plugins or connectors instead.
- Is MCP access to fund data safe?
- The protocol is neither safe nor unsafe on its own. Safety comes from what the connection is permitted to do, who authorised it, whether it expires, and whether every action is recorded. Read-only access to non-sensitive records is a very different decision from write access to fund records.
- What is the difference between an MCP connection and a native agent?
- An MCP connection lets an external assistant reach into one system through a defined set of actions. A native agent runs inside the platform, on the full data model, under a permission scheme the platform controls. The first is a window into one system, the second operates across the lifecycle.
- How does a mandate token relate to MCP?
- A mandate token is the permission object. It states which records an agent may touch, for what purpose, granted by whom, until when. It applies whether the agent is native to the platform or an outside assistant connecting over a protocol such as MCP.
Keep reading
See how this works in practice
Everything on this page is free to read, print and share. If you want to try the workflow itself, a guided trial workspace takes a few minutes to set up and no card is required.
Cite this guide
Free to quote and link. Please cite the permalink and the review date.
Katriona Lee. "MCP and AI tool access for private capital." Reuben AI, 2026. Last reviewed 2026-07-29. https://www.goreuben.com/mcp-and-ai-tool-access-for-private-capital
- Publisher
- Reuben AI
- Author
- Katriona Lee
- Last reviewed
- 2026-07-29