MCP Write Tools: Rollout After Read-First
Read-first baseline (days 1–30)
Before any write tool ships to production MCP clients:
- Mail on account — forward-only policy live — mail on account
- Stage policy — definitions documented; zombie opps archived
- Top 10 accounts — read prompts weekly with consistent value
- Org MCP key — read scope only; rotated; not in public channels
- Prompt library — three to five approved read prompts published
Setup: Salestrics MCP, Cursor MCP playbook, API key governance.
Write readiness checklist
| Gate | Owner | Pass criteria |
|---|---|---|
| Data hygiene | RevOps | Active pipeline only; owners current |
| Mail policy | Sales ops | New externals from org mail on account |
| Read prompt ROI | RevOps | Two managers cite time saved from reads |
| Key governance | IT / RevOps | Rotation doc; offboarding same day |
| Executive sign-off | CEO / CRO | Written allowlist of first write actions |
Phased write rollout (days 31–60)
| Phase | Allowed writes | Scope |
|---|---|---|
| A | Tasks, internal notes | Top 10 accounts only |
| B | Hygiene flags, owner reminders | Active pipeline segment |
| C | Stage moves per defined rules | Named opps after manager review |
| D | Draft mail — human send | Templates approved by RevOps |
| E | Automated sends | Flows + human escalation paths only |
Skip phases — do not jump to E because Cursor can. Each phase runs two weeks minimum with audit.
Key and environment policy
- Org-owned keys — never personal tokens on shared laptops
- One key per client environment — Cursor production vs eval sandbox
- Write scope explicit — separate read-only key until phase C
- Rotation quarterly — or immediately after any suspected leak
- Offboarding — revoke MCP access same day as email — no exceptions
Architecture primer: agentic CRM guide and evaluate agentic CRM.
Approved write actions (starter allowlist)
- Create follow-up task on opp after Connect call — with due date
- Add internal note — never customer-visible without review
- Flag stale opp — no mail 14 days; does not auto-close
- Update next step field — text only; stage unchanged
Explicitly not on day-one allowlist: discount fields, stage to Closed Won, bulk updates, mail send without human approval.
Monthly audit ritual (30 minutes)
- Admin MCP logs — who ran write actions; which records
- Anomaly scan — bulk stage changes, after-hours writes
- Allowlist review — expand, shrink, or pause one action
- Token burn — write vs read ratio vs pool size — token governance
- Incident log — any wrong record mutation; root cause and policy fix
What goes wrong without policy
| Failure | Cause | Prevention |
|---|---|---|
| Stage chaos | Agent moves opps on bad data | Archive stale records first |
| Duplicate tasks | Same prompt run on whole book | Account-scoped prompts only |
| Customer mail errors | Write send without template | Phase D draft-only |
| Key leak | Key in Slack or GitHub | Org key + rotation |
| Pool exhaustion | Write loops on hygiene | Fix data; read-first |
Cursor and Claude Desktop specifics
Developers often connect MCP first — commercial teams follow. Align both:
- Cursor — read key in dev; production write key only after phase B
- Claude Desktop — same allowlist; no separate shadow policy
- Workflow prompts — publish in Admin; link MCP workflow prompts
- Eval accounts — never test writes on production top logos
Claude setup: Claude Desktop MCP.
Anti-patterns
- Write on day one — because the demo looked cool
- Shared key in #sales — rotation impossible
- No allowlist — “use judgment” scales badly
- Ignore desk — Resolve writes need same policy as CRM
- Writes before Connect rollout — meetings still off-graph
MCP prompt (write audit)
List MCP write actions in the last 7 days by user and record type. Flag any stage change on opps with no mail in 30 days — read only, for RevOps review.