04 ·Agnidoot MCP

Your private MCP server for Odoo.
Connected isn't unrestricted.

Give Claude, ChatGPT and your own agents a governed route into Odoo. Eight of seventeen tools are on by default — every one of them read-only. Everything that changes anything is off until you turn it on.

Read-only by default Risk tiers 0–4 Nothing installed inside Odoo Odoo 16–19
17

Tools available

8

On by default
all read-only

0–4

Risk tiers on
every action

1

Correlation ID
across every call

The idea

Every agentic read and write, through one gate.

This is the chokepoint the rest of the platform is built on. Because every AI call to Odoo passes through it, the audit trail is complete by construction rather than best-effort — and a policy you set once applies to every AI your company uses.

Safe by default

Read-only until you decide

Search, get, aggregate, schema, resolve, diagnostics, export and trace — on from day one. Writes, business actions, deletes, attachments and introspection are each behind their own gate, off until switched on.

Governed writes

Preview, then approve

Risk tiers 0–4 on every action. A consequential call prompts a human — and if no human can be asked, it fails closed rather than proceeding quietly.

Provable

One trace, every client

Every call from every AI lands in one auditable timeline under a single correlation ID — refusals included.

Controls

What you can actually set.

Per-client scoped keys. Grant read, write or admin per key, so different agents and teams get different reach.
Quotas and licensing per key, so one runaway client can't consume the estate.
Whitelisted models and methods. No arbitrary code path is reachable — only what you allow.
Dry-run previews on writes and deletes, showing exactly what will change.
Write de-duplication — an AI retry cannot create two records.
Guarded deletes, off unless explicitly enabled.
Your Odoo permissions still apply. The agent can never exceed the connected user's own rights.
Multi-instance. One agent, many Odoo servers, each behind its own named scoped connection.
Human confirmation required — a client that cannot show a person the prompt is refused, not quietly served.
An audit web UI plus reporting, on your own infrastructure.

The honest comparison

Odoo 19 ships native MCP. That's good.

We're not going to pretend otherwise. Native MCP solves connectivity, and connectivity is becoming a feature rather than a product. The next question is how much governance you need around it.

The questionNative MCPAgnidoot MCP
Connect an AI client to Odoo
Read-only defaults with per-capability gates
Risk tiers on every action
Human confirmation, failing closed
Per-client scoped keys and quotas
One correlation ID across document, chat and write
A path into organisation-wide AI control

Use native MCP if you want one developer connecting one AI client to one Odoo. Use this if several people and several AI tools will touch the ERP, and somebody will eventually have to prove what they did.

Running it

Managed, or entirely inside your network.

Managed

We host the connection

The fastest start. Your team points their AI clients at it and works. No infrastructure to manage.

Fully private

One stateless container, your network

For regulated work: run it inside your own network, even air-gapped, with a local model. Nothing leaves your walls.

No footprint in Odoo. Connects via the standard API — no module, no plugin, no database change.
Any Odoo. Versions 16–19, Community or Enterprise, cloud or on-premise.
Stateless and simple. One container, no data retained.
Ships as your brand if you're a partner delivering it to clients.
What we will not claim

It governs the AI paths this platform owns. A person editing a record by hand inside Odoo is governed by Odoo's own permissions, exactly as before. And no penetration test has been performed — we'll hand your security tester the code and walk them through the enforcement points that exist today.

Every plan includes

Try it free for three months. Keep the support for a year.

No obligation, no card, no lock-in. And what comes with your plan isn't a discount — it's what it takes to make an ERP actually land.

Start free →
Weeks

Start in weeks

Not months. Your implementation is underway in your first week.

1 year

Free support

A full year included with every plan — not a paid add-on.

On-site

Training included

We come to you and train your team in the room, on your data.

100 hrs

Customisation

A hundred hours of our engineering, built into every plan.

No card to start  ·  No obligation  ·  Cancel any time in the three months  ·  Your data stays yours

Questions

Questions about connecting AI tools to Odoo.

What MCP is and why it matters

What is an MCP server, in plain language?
A controlled door. It lets AI tools your people already use — Claude, ChatGPT, or something you build — read and act on Odoo without handing them your database. Everything passes through one gate you own.
Why not just give the AI tool a database login?
Because a login has no memory and no judgement. The MCP server enforces read-only by default, scopes each key to what it should touch, inherits the requesting person's Odoo permissions, tiers actions by risk, and records every write.
Isn't this the opposite of keeping AI out of our data?
It is the alternative to pretending it isn't already happening. People paste ERP data into AI tools today with no controls at all. MCP makes that route official, narrow and auditable — and if you'd rather it stayed closed, the default is closed.
Odoo 19 ships native MCP. Why do we need this?
Native MCP is a good foundation. What it does not give you is scoped keys, risk tiers, per-person identity, quotas, cost attribution and a correlation-based audit trail across every tool that connects. That governance layer is what we add.

The technical detail

What can a connected tool actually do?
Exactly what you configure — nothing more. Reads are the default; writes are opt-in, scoped, previewed and audited. Every capability is switched on deliberately.
How is identity handled?
Requests carry the identity of a real person, not a shared service account, so Odoo's own record rules apply and the audit trail names a human.
Can we run it entirely inside our network?
Yes. It runs managed, or wholly inside your own infrastructure with local models — which is the default posture on Enterprise.
What is logged?
Who connected, what they asked for, which records were touched, what changed and what it cost — linked by one correlation ID. Prompt contents are not retained.

Getting started

Which edition includes MCP?
Enterprise. Standard covers implementation, in-Odoo document AI, agents and governed access; MCP and RAG are the two products Enterprise adds.
How do we pilot it safely?
Start read-only with one team and one tool. You get the value of AI reading real ERP data with no path to changing it, then open specific writes once you have seen the audit trail work.

Point your AI at a sandbox and try to break it.

Start read-only, widen deliberately, and watch every call land in one trace.

Book a demo

See it running on your own documents.

Thirty minutes, your paperwork, your questions. We will show you what it does — and, just as importantly, what it refuses to do.

Book a demo →