Plur-e MCP · Security & governance
Permissions, audit and data handling for AI agents on your ERP
An agent is only as safe as the boundaries around it. These are ours.
Quick answer
Plur-e MCP servers authenticate each user with Microsoft Entra ID and call Business Central and Dataverse with that user's token, so existing permissions apply; tools are read-only by default and write tools are enabled per role with optional human approval; every request and tool call is logged with user, inputs and outputs; prompts and results are processed by the Claude API under Anthropic's commercial terms and are not used to train models; servers run in Plur-e's Azure or the customer's Azure tenant.
Identity and permissions
| Authentication | Microsoft Entra ID, per user (OAuth 2.0, on-behalf-of flow). VALIDAR exact flow |
|---|---|
| Authorization | Business Central permission sets and Dataverse security roles apply to every call |
| Service accounts | Only for scheduled/background tools, with least-privilege permission sets |
Tool scopes and approvals
| Default | Read-only tools |
|---|---|
| Write tools | Enabled per customer and role; annotated as non-read-only in the tool schema |
| Approvals | Optional human approval before posting documents; approver and payload logged |
| Limits | Rate limits per user and tenant; maximum rows per response |
Audit and monitoring
| Logs | Request, tool name, inputs, outputs, user, timestamp, latency |
|---|---|
| Retention | VALIDAR: default retention period and export options |
| Alerts | Failed authentications, denied writes, unusual volumes |
Data handling
| Model provider | Claude API (Anthropic). Data submitted through the API is not used to train models under Anthropic's commercial terms |
|---|---|
| Residency | Business Central and Dataverse data stays in your Microsoft tenant; the MCP server runs in Azure (Plur-e or yours) |
| Subprocessors | Microsoft Azure, Anthropic. VALIDAR complete list for the DPA |
| Deletion | Logs deleted on request; no customer data stored beyond logs and cache. VALIDAR cache policy |
FAQ
Frequently asked questions
Start with a two-hour discovery workshop
Bring the questions your team asks every day. We map them to tools, permissions and a pilot plan.