AI & Automation

What Is MCP? A Plain Answer for Business Owners.

MCP is a standard that lets an AI assistant read from and act in your business tools. Here is what it costs through Zapier, where the risks sit, and a simple test for whether to wait.

·

MCP, the Model Context Protocol, is an open standard for connecting AI applications such as Claude or ChatGPT to outside systems: files, databases, search tools and business software. This post explains it in plain English, what changed in the July 2026 version, what it costs through Zapier, the risks of giving an assistant access to your systems, and a simple test for whether you need it now. If you want an MCP connection built around your own tools and data, that is the work of our LLM and MCP integrations service, and the cautions below apply to that work too.

What MCP is, in plain English

MCP is a shared plug standard that lets an AI assistant reach your data and tools, so a connection built once can work with many AI applications. The project's own documentation compares it to a USB-C port: USB-C gives devices one standard way to connect, and MCP gives AI applications one standard way to connect to external systems.

There are two sides. An MCP server is a program that sits in front of one system, such as a calendar, a database or a CRM, and lists the tools an AI application may call there. The AI application, such as Claude, connects to that server through a small component called an MCP client, asks what tools are available, and calls them when your request needs them. The documentation gives examples like an agent that can access your Google Calendar and Notion, or a company chatbot connected to several databases so staff can analyze data by asking questions.

What it looks like in a small business

In practice, MCP lets the assistant look things up and act in the systems where your work already lives, so you stop copying data into a chat window by hand. Here is an illustration, not a client story: a small bookkeeping office wants to chase late invoices.

Without MCP, the owner exports a list of overdue invoices, pastes it into a chat, and copies the drafted reminders into email by hand. With an MCP connection to the accounting system and the mailbox, the owner asks which invoices are 30 days overdue, and the assistant calls a lookup tool to find out. Drafting an email would be a second tool, and you decide separately whether it may draft only or also send.

What changed in the July 2026 specification

The July 28, 2026 release changed how MCP works underneath, and it is mostly news for people who build and host servers. The maintainers describe a move from a two-way, stateful design to a stateless request and response design, so any request can be handled by any server instance behind a plain load balancer. The release also formalizes an extensions framework, with Tasks joining MCP Apps and Enterprise Managed Authorization, and sets a twelve-month minimum window for deprecations. The maintainers call it the most important release since remote MCP first launched over a year ago. If you use a ready-made connector, the practical question for your vendor is which version of the specification it supports.

What MCP costs through Zapier

Through Zapier, MCP use comes out of your normal task allowance (see Zapier's MCP documentation): each successful tool call uses two tasks, and failed calls do not count. Zapier's pricing page lists a Professional plan from $19.99 a month, billed annually, with 750 tasks a month. At two tasks per call, that allowance covers at most 375 successful calls a month, and fewer if your Zaps already use tasks. Zapier's free plan also includes MCP, with 100 tasks a month, which is enough for a small test. These are list prices as read on October 2, 2026 and can change, so check the page before you plan around them.

Zapier also says its MCP tools run through the same app connections as your Zaps, under workspace access controls, user permissions and audit history. A custom MCP server built for your own systems is a different cost. GrossiWeb quotes those after a scoping call, sized by the number of tools and data sources exposed and the permissions and testing they need.

The risks of giving an AI assistant access

The main risk is simple: an assistant can do whatever its access allows, so the permissions you grant set the limit. The MCP specification says there should always be a human in the loop with the ability to deny tool invocations. It adds that clients should prompt for confirmation on sensitive operations, show tool inputs before calling the server, and log tool usage for audit.

The project's security guidance, written for the people who build MCP servers and clients, recommends a least-privilege approach: start with a minimal set of permissions covering low-risk read operations, and ask for more only when a task first needs them. It warns that broad permissions granted up front make a stolen access token more damaging, because it opens tools and data the task never needed. The maintainers' August 2026 roadmap post also notes that MCP authorization is still built around a person approving access in a browser, while more and more callers are agents running as cloud workloads. That is a reason to be most careful with unattended assistants that can change things.

  • Start read-only. Let the assistant look things up before it can change anything.
  • Separate tools that send, delete, publish or pay from tools that only read, and require your approval for the first group.
  • Give the assistant its own account with limited rights instead of the owner's login.
  • Keep a log of every action and read it weekly for the first month.

A simple test: do you need it now, or can you wait?

You can wait if a fixed workflow already does the job, because a workflow is simpler to build and to audit than an assistant choosing its own actions. A workflow automation handles tasks whose steps are the same every time. MCP earns its place when you want to ask in plain language and have an assistant choose among several actions across more than one system.

  1. Does the task need judgment about which action to take next? If the steps are the same every time, a workflow is the better fit.
  2. Does the work cross two or more systems that your staff bridge by copying and pasting? If it lives in one system, check first whether that system's own reports or search already answer the question.
  3. Can you name the exact actions the assistant may take and the person who reviews them? If you cannot, wait until you can.

Yes to all three means a small, read-only pilot is reasonable now. If the job runs many steps by itself, you are in custom AI agent territory, where the same permission rules apply with more force. Our post on why most AI tools waste your time covers the cost of tools that sit apart from the systems your team already uses.

What to do this week

Start with your own work, not with a connector. These five steps show whether an assistant has anything worth reaching into, and they keep the first test small.

  1. List three tasks where someone copies information between two systems, and note how often each happens.
  2. For each one, write the exact actions an assistant could take and mark which need a person's approval.
  3. If you try a connector, use a test account, read-only access and a small task budget, then check usage after a week.
  4. Ask any vendor which MCP specification version its connector supports and what its logs record.
  5. To decide where to begin, use the automation and scale page, which is built for that question.
← Back to all articles
What our clients say

Real businesses. Real results.

“GrossiWeb completely transformed our online presence. Our website is faster, cleaner, and actually drives leads now. The SEO improvements were immediate, and the strategy behind everything was clearly built for growth, not just aesthetics. If you want real results, Grossi Consulting delivers.”
Auto ServicesBuckhead Imports
“I had been courting a high profile business prospect, but after a few months my prospect was becoming increasingly distant. One morning after I had made some follow up calls, my prospect called me right back stating he had seen a news story about my company on Google news. This is the type of instant gratification and credibility I have experienced working with Grossi Web.”
Financial ServicesDorfman Capital
“Thanks to the Talent and Professionalism of Grossi Web, I have turned a dream into a successful aviation company. I continuously receive compliments on the corporate site and AirExpress brand. Grossi Web developed a highly targeted marketing campaign that has resulted in international exposure and attaining clients who were previously unreachable!”
AviationHumes McCoy Aviation

Want to apply this to your business?

Book a free 30-minute strategy call. We'll take the ideas in this post and show you exactly how they apply to your specific situation.

No commitment. No sales pressure. Just clarity.