
Why people data and AI agents meet cleanly on MCP.
People data is different
An AI agent acting on employee records needs more than an API key. It needs scoped, auditable, permission-aware access, the difference between “read the org chart” and “read everyone’s salary.”
MCP gave us a way to expose exactly the right slice of data to an agent, with the same field-level permissions a human would face, and a log of every action taken.
Safe by construction
Building on MCP from day one meant we never had to bolt safety on afterwards. The boundary an agent respects is the same one your admins configured.

Written by
Lena Frost
Leads security and compliance at Northwind. Translates regulation into sensible defaults engineers and HR can actually live with.




