Plur-e MCP · Security & governance
Permissions, audit and data handling for AI agents on your ERP
An agent is only as safe as the boundaries around it. These are ours.
Quick answer
Plur-e MCP servers authenticate each user with Microsoft Entra ID and call Business Central with Plur-e's application credentials, limited to the one environment and company the administrator configured; tools are read-only by default and write and post tools are enabled per MCP role (Read / Write / Post); every request and tool call is logged with user, inputs and outputs; prompts and results are processed by your AI provider's API under its commercial terms and are not used to train models; servers run in Plur-e's Azure or the customer's Azure tenant.
Identity and permissions
| Authentication | Microsoft Entra ID, per user (OAuth 2.0; the server publishes its protected-resource metadata so clients discover Entra ID). Business Central is called with Plur-e's application credentials; per-user delegated access is on the roadmap |
|---|---|
| Authorization | Read/write scope per tool and role in the Admin Center; every call is bounded to the environment and company configured by the administrator and by the permission set of the Business Central connection |
| Service accounts | Only for scheduled/background tools, with least-privilege permission sets |
Tool scopes and roles
| Default | Read-only tools |
|---|---|
| Write tools | Enabled per customer and role; annotated as non-read-only in the tool schema |
| Roles | Read / Write / Post per section or area; a role without Write or Post gets scope_denied instantly — there is no approval queue |
| Limits | Rate limits per user and tenant; maximum rows per response |
Audit and monitoring
| Logs | Request, tool name, inputs, outputs, user, timestamp, latency |
|---|---|
| Retention | Audit entries stay in the tenant's Plur-e database and are viewable in the Admin Center; retention and export options are available on request. |
| Alerts | Failed authentications, denied writes, unusual volumes |
Data handling
| AI provider | Your chosen AI provider's API. Data submitted through the API is not used to train models, under that provider's commercial terms |
|---|---|
| Residency | Business Central and Dataverse data stays in your Microsoft tenant; the MCP server runs in Azure (Plur-e or yours) |
| Subprocessors | Microsoft Azure, the AI provider you connect. Full subprocessor list available on request. |
| Deletion | Logs deleted on request. Beyond the audit log the server keeps only a 60-second in-memory tenant context; no Business Central data is stored |
FAQ
Frequently asked questions
Start with a two-hour discovery workshop
Bring the questions your team asks every day. We map them to tools, permissions and a pilot plan.