MCP for ERP Consultants: What a Client Engagement Includes

ERP consultants offer MCP services by configuring secure, read-only ERP access for AI. An engagement includes scoping, setup, validation, and training, and is distinct from data licensing.

As an ERP consultant, your clients look to you for expertise on connecting business systems and maximizing the value of their data. The rise of powerful AI assistants has created a new challenge and opportunity: clients want to use AI with their live ERP data but are rightly concerned about security, accuracy, and control. An MCP (Model Context Protocol) service engagement allows you to provide a structured, secure solution for this demand.

An engagement focuses on configuring controlled, auditable access for AI models to query client ERP data. This enables new reporting and analysis capabilities but requires your expertise in setting up permissions, defining usable tools, and training users. It is a technical and advisory service, fundamentally distinct from data licensing, which involves selling access to data to external parties.

The business problem: Clients want to use AI with their ERP data

Enterprise clients see the potential of using AI assistants like Claude to get instant answers from their business data. However, connecting an AI directly to a production ERP system like NetSuite or Microsoft Dynamics 365 presents significant risks:

  • Security: Unrestricted access could expose sensitive financial, customer, or employee data.
  • Data Integrity: Accidental or malicious write-back commands could corrupt financial records, inventory counts, or CRM data.
  • Hallucinations: Without proper grounding in the company's specific data structures, AI models can invent plausible but incorrect answers.
  • Complexity: Standard APIs are designed for developers, not for the semantic understanding required by AI agents.

Clients need a trusted advisor to bridge this gap. As an ERP consultant, you are perfectly positioned to solve this problem by implementing a secure access layer using MCP. This protocol allows an AI to use pre-approved "tools" that correspond to specific, safe, and verifiable actions within the ERP, such as running a saved report or looking up an inventory SKU.

Illustrative example: A NetSuite MCP setup for a mid-market distributor

Client: A $75M CPG distributor using NetSuite for financials, inventory, and order management.

Business Need: The CFO and sales operations manager want to ask natural language questions about inventory, open sales orders, and accounts receivable without having to run multiple custom reports or wait for the finance team to provide data.

Consultant's Engagement Workflow:

  1. Scope & Discovery: You meet with the client to identify the highest-value initial questions. They prioritize three areas: inventory levels by location, open A/R aging, and unshipped sales orders by customer.
  2. Server & Role Setup: You configure access to a hosted NetSuite MCP server. This involves creating a new, dedicated integration role in the client's NetSuite instance. The role is given read-only permissions limited to the specific records required (e.g., inventory items, customer invoices, sales orders) and access to run a few pre-existing saved searches.
  3. Tool Configuration: You define the specific "tools" the AI can use. These are not general API calls but named, understandable functions:
    • `get_inventory_on_hand(sku, warehouse_location)`: Runs a saved search for a specific item and location.
    • `get_accounts_receivable_aging(customer_id)`: Executes a SuiteQL query to pull the aging buckets for a given customer.
    • `list_open_sales_orders(customer_id)`: Fetches unshipped orders, excluding draft or canceled statuses.
  4. Testing & Validation: You and the client's finance team test the system. The CFO asks, "How many units of SKU 45-B31 do we have in the Dallas warehouse?" The AI uses the `get_inventory_on_hand` tool, gets the result, and presents it with the source (the NetSuite saved search it ran). You verify this number against a live report in the NetSuite UI to confirm accuracy.
  5. User Training & Handoff: You train the CFO and sales ops manager on how to phrase questions, understand the AI's limitations (it can only do what the tools permit), and how to check the source evidence for each answer. You also document the process for them to request new tools in the future as their needs evolve.

This structured engagement provides immediate value to the client while maintaining strict security and data governance. It positions you as a forward-thinking advisor who can safely deliver AI capabilities.

MCP service engagement checklist for ERP consultants

Use this checklist to structure your MCP implementation projects for clients.

  • Phase 1: Discovery & Scoping
  • [ ] Identify key stakeholders and intended AI users (e.g., CFO, controller, sales ops).
  • [ ] Define 3-5 initial business questions the client wants to answer with AI.
  • [ ] Document the target ERP system, version, and available API/integration modules.
  • [ ] Review the client's existing ERP roles, permissions, and data governance policies.
  • [ ] Confirm client authorization to proceed with a limited, read-only integration.
  • Phase 2: Technical Setup & Configuration
  • [ ] Provision or connect to a hosted MCP server for the client's ERP (e.g., NetSuite, Dynamics 365 ERP).
  • [ ] Create a dedicated, read-only service role within the ERP system.
  • [ ] Configure secure authentication (e.g., OAuth 2.0) between the MCP server and the ERP.
  • [ ] Define and implement the initial set of MCP tools based on the scoped business questions.
  • [ ] Configure comprehensive audit logging for all AI queries and tool usage.
  • Phase 3: Validation & User Acceptance Testing (UAT)
  • [ ] Develop a test plan with specific natural language queries and expected outcomes.
  • [ ] Execute test queries and manually reconcile AI-generated answers against native ERP reports.
  • [ ] Involve the business stakeholder to run their own test queries.
  • [ ] Document any discrepancies, tool limitations, or data quality issues discovered.
  • [ ] Secure written sign-off on UAT results from the project stakeholder.
  • Phase 4: Handoff & Training
  • [ ] Conduct a training session for the business users on effective prompting and interpreting results.
  • [ ] Provide clear documentation on the available tools, their parameters, and their scope.
  • [ ] Establish a go-forward process for users to request new tools or reporting capabilities.
  • [ ] Schedule a post-launch follow-up to review usage and identify future opportunities.

Prerequisites and limitations

It is critical to set clear expectations with your client about what an MCP engagement can and cannot do.

Prerequisites:

  • System Access: The client's ERP must have a stable, accessible API (e.g., NetSuite SuiteCloud, Dynamics 365 web services). Some older or highly customized on-premise systems may not be suitable.
  • Client Authorization: You must have explicit, written permission from an authorized decision-maker at the client company to connect to their systems.
  • Designated Contacts: The client must provide a business owner for validating data and a technical contact for facilitating system access.

Limitations:

  • Access vs. Ownership: An MCP engagement provides controlled access for internal AI use. It does NOT grant you, the consultant, or any third party ownership of the data or the right to license, sell, or redistribute it. This must be made explicitly clear in your statement of work. Data licensing rights are a completely separate matter requiring executive authorization.
  • Read-Only Focus: For initial projects, always scope for read-only access. Write-back capabilities introduce significant risk and should only be considered in later phases with rigorous controls and approvals.
  • Data Quality Dependency: The AI's answers are only as good as the underlying ERP data. MCP is not a data cleansing, ETL, or master data management tool. Your engagement may identify data quality issues, which can become a follow-on project.
  • No Resale of Licensed Research: If an MCP server connects to licensed data sources like PitchBook or AlphaSense, that data is still governed by the client's license. It cannot be redistributed or resold.

Questions to ask the client and the MCP vendor

As the consultant, you'll need to gather information from both your client and the MCP technology provider.

For the Client:

  1. Who is the designated individual authorized to approve access to specific data sets (e.g., financial summaries vs. detailed payroll)?
  2. What are the first 3-5 high-value questions you want to ask that are currently time-consuming or difficult to answer?
  3. Do you have an existing data governance or information security policy that we need to incorporate into the project plan?
  4. Who will be the business owner responsible for validating the accuracy of the AI's outputs during testing?

For the MCP Server Vendor:

  1. Is your MCP server hosted or does it need to be deployed in the client's environment? What are the security and data residency implications?
  2. Can you provide documentation on your security controls, such as your SOC 2 or ISO 27001 compliance?
  3. What specific authentication methods (e.g., OAuth 2.0, token-based) do you support for connecting to our client's ERP?
  4. What is the process for defining, testing, and deploying a new custom tool for the AI agent?

Next step with SourceX

As you help clients connect their systems using MCP, you are in a unique position to identify companies with valuable, well-structured operational datasets. While your MCP engagement is focused on the client's internal use of AI, some of these companies may be eligible to license their anonymized historical data to external AI labs and data buyers.

This is a separate, permissioned process that SourceX manages. We build, contract, and manage the supply and transaction layer for enterprise AI data. For qualifying introductions that result in a paid data license, our partners receive 25% of the platform fees SourceX collects, up to $100,000 per referred company. The company that owns the data receives its own licensing proceeds separately from this.

If you work with established US-based operating companies, a next step could be to use our free [/tools/company-fit-checker] to assess their potential suitability for data licensing. To learn more about our referral program, please visit our [/partners] page.

Related MCP guides

Sources

Vendor capabilities change. Check current official documentation before relying on any product detail.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

What's the difference between an ERP's native API and an MCP server?

An ERP's API provides raw, developer-focused access to data objects. An MCP server creates a semantic layer on top of the API, exposing specific business "tools" (like "get_customer_balance") that AI assistants can understand and use safely, with built-in permissions and logging. This makes the data accessible to AI without custom development for every query. You can learn more about how [MCP compares to a standard API](/resources/mcp/mcp-vs-api).

Can I use MCP to write data back to the ERP, like creating a journal entry?

While some MCP servers support write actions, this introduces significant risk and complexity. It requires robust validation logic, error handling, and often multi-step user confirmation. Most initial MCP consulting engagements should focus exclusively on read-only access to ensure data integrity and build client trust.

Does implementing MCP for a client give me, the consultant, rights to their data?

Absolutely not. As the consultant, you are a data processor acting on your client's explicit instructions. Access is granted solely for the purpose defined in your engagement contract. The client retains full ownership and control of their data at all times. Any discussion of licensing data to third parties is a completely separate process that requires explicit, executive authorization from the client company.

How long does a typical ERP MCP engagement take?

A well-scoped initial project focused on 3-5 key reports for a single department can often be completed in 2-4 weeks. This timeline typically includes discovery, technical setup, validation testing, and user training. More complex projects involving multiple data sources, custom tool development, or write-back capabilities will require a longer timeline.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Facts checked 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment