Business Operations Agent Kit
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Business Operations Agent KitWhat are we waiting on for Harborlight?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Business Operations Agent Kit
Try the zero-install live demo
Apply for a read-only adapter pilot using public-safe, synthetic details only. Pilot evaluation starts with a reviewed read-only source contract and preserves NO SEND / NO WRITE.
The live walkthrough uses two fake businesses, makes no application network
requests after its static assets load, and preserves NO SEND / NO WRITE.
A public-safe starter for building the kind of operations copilot a business owner can actually use:
“Where do we stand?”
“What changed?”
“Who has the ball?”
“What are we genuinely waiting on?”
“Does the inbox contradict the dashboard?”
“Draft the next request.”
“Which approved blank form should go with it?”
The kit is not a copy of a private business database. It is a harness-neutral policy core, a normalized evidence contract, an Agent Skill, and adapter patterns for Hermes, Claude, ChatGPT, and other MCP-capable systems.
Why this exists
WIMPER Ops Agent is the validated private reference implementation: it proved that a chat can reconcile process state, dashboard records, email evidence, document state, ownership, drafts, and packet workflows.
This repository is the product extraction. It contains no WIMPER customer records, credentials, private messages, proprietary database paths, or attachment contents. All examples are synthetic.
Related MCP server: abm-mcp
What works now
The starter exposes five read/prepare operations:
list_businessesget_business_statusget_missing_input_handoffprepare_email_draftprepare_attachment_manifest
It exposes no send or write tool.
Every case-specific operation requires an explicit business_id. Every result is visibly labeled NO SEND / NO WRITE, includes evidence locators and a state fingerprint, and declares what did not happen.
Try the zero-install browser walkthrough
Open the live walkthrough,
or open demo/index.html directly in a modern browser. The walkthrough uses
only the bundled synthetic results and makes no application network requests.
The checked-in demo/demo-data.js is generated from the same Python policy core
used by the CLI and MCP tools. Regenerate it after any core or fixture change:
.venv/bin/python scripts/build_browser_demo.pyThe browser-demo contract tests fail if the generated asset drifts from the executed synthetic workflows or exposes private source fields.
The demo shows:
a sourced status report;
one real task/document gap;
one exact recipient;
a proposed email draft;
one explicitly approved blank-template attachment proposal;
a second synthetic business where email and dashboard evidence conflict, causing the agent to suppress a duplicate request.
Run the synthetic Python and MCP demo
One-command evaluator with uv:
uvx --from git+https://github.com/mkhragudo/business-operations-agent-kit.git \
business-ops-agent demo --business harborlight-demoOr clone the repository and run the full contract suite:
python3 -m venv .venv
.venv/bin/pip install -e '.[test]'
.venv/bin/python -m unittest discover -s tests -v
.venv/bin/business-ops-agent list-businesses
.venv/bin/business-ops-agent demo --business harborlight-demoThe default test suite includes a real stdio MCP transport test. To run the same transport probe by itself:
.venv/bin/python scripts/test_mcp_integration.pyOr:
./scripts/demo.shPermission ladder
Level | Capability | Starter default |
0 | Inspect status and evidence | Enabled |
1 | Prepare drafts and attachment manifests | Enabled |
2 | Create a staged provider draft or generated document | Designed, disabled |
3 | Send or update a source system | Disabled; requires a separate approval and receipt contract |
“Prepare an attachment” in this starter means produce a verified manifest entry. The model never receives attachment bytes or filesystem paths.
Architecture
Hermes / Claude / ChatGPT / MCP client
|
shared Agent Skill
|
five narrow read/prepare tools
|
BusinessOperationsAgent core
|
OperationsSource protocol
|
email + dashboard + database + document adaptersThe included JsonDirectorySource is a synthetic reference adapter. A real deployment replaces it with a connector that normalizes private evidence into the same bounded records.
The wheel includes the same synthetic fixture for a wheel-only demo; a contract test prevents it from drifting from examples/synthetic.
Harness adapters
Hermes: install the shared Agent Skill and connect the local MCP server or use the CLI.
Claude Code: install the same Agent Skill under
.claude/skills/and connect the local stdio MCP server through project-scoped.mcp.json.Claude.ai: use project instructions plus an approved connector or remote MCP service for live data.
ChatGPT: use project instructions for behavior and an authenticated remote MCP Plugin for live systems. Uploaded project files alone are not a live email/database connection.
Other harnesses: implement the five-tool adapter contract or call the CLI.
See docs/INSTALL.md and docs/PLATFORM-MATRIX.md.
Before connecting live data, read docs/SOURCE-ADAPTER-GUIDE.md and docs/THREAT-MODEL.md. A production installation requires a dedicated restricted harness profile, read-only source credentials, field-level authority rules, and no generic tool that bypasses the policy core.
Safety invariants
Never silently select the first business.
Suppress draft and attachment proposals when the adapter's versioned freshness attestation is false.
Never call something missing without an open task or task-backed current-document gap.
Preserve communication/dashboard contradictions and suppress only the affected request.
Require one exact recipient before drafting external copy.
Reject sensitive, opted-out, suppressed, or do-not-contact recipient roles.
Propose only attachment IDs explicitly named by open work.
Exclude stale, path-escaping, sensitive, or unapproved files.
Never return raw message subject, sender, body, content digest, attachment path, or attachment bytes.
Never send, create a provider draft, or write a business record in the starter.
Repository map
src/business_ops_agent/: policy core, JSON adapter, approval semantics, CLI, optional MCP serverdemo/: zero-install static walkthrough and generated synthetic payloadskillsets/: shared Agent Skilladapters/: harness-specific packaging guidanceexamples/synthetic/: public-safe demonstration evidencetemplates/: owner configuration, process, and permission templatestests/: contract, privacy, contradiction, and zero-side-effect testsdocs/: contract, architecture, source-adapter guide, threat model, installation, and publication drafts.github/: read-only CI, manual demo-only Pages deployment, and public issue/PR intake
Contributing and security
See CONTRIBUTING.md for the local quality gate and public-data rules. Report
suspected vulnerabilities privately using the process in SECURITY.md; never
put credentials or real business data in a public issue.
Status
Version 0.1.0 is the initial public source release. The repository and static
demo contain synthetic data only. Live connectors, hosted services, provider
drafts, source writes, PyPI publication, and announcements remain outside this
release.
License
Licensed under the Apache License 2.0.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityBmaintenanceCustomer-hosted, read-only MCP server for Jobber operations workflows. It helps owners query Jobber for action lists, overdue invoices, stale requests, estimate/job follow-up, and safe read-only GraphQL validation.6321MIT
- Alicense-qualityCmaintenanceA read-only MCP server that provides tools to list and read devices, MDM servers, blueprints, configurations, apps, packages, users, and other resources from Apple Business Manager and Apple School Manager.MIT
- Flicense-qualityAmaintenanceRead-only MCP server that performs deterministic local preflights of agent-payment boundary documents and x402 v2 PaymentRequired JSON, and prepares unsubmitted public quote-request drafts without network calls or fund movement.
- FlicenseAqualityCmaintenanceMCP server that exposes MongoDB business data via tools for summary statistics, new users, and pending payments.3
Related MCP Connectors
Read-only MCP server for ClassQuill, a tutoring-business-management platform.
A paid remote MCP for hosted MCP server, built to return verdicts, receipts, usage logs, and audit-r
A paid remote MCP for CLI tool MCP, built to return verdicts, receipts, usage logs, and audit-ready
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/mkhragudo/business-operations-agent-kit'
If you have feedback or need assistance with the MCP directory API, please join our Discord server