GxP MDM MCP Server
Provides Cypher-based tools for querying a GxP computerized system inventory stored in Neo4j, including system details, blast radius, data lineage, validation gaps, risk checks, supplier risk, and change impact assessment.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@GxP MDM MCP ServerWhat's the blast radius if I change Veeva QMS?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
GxP MDM MCP Server - Cypher Tools for Claude / ChatGPT / Cursor
This MCP server exposes your Computerized System Inventory as a Knowledge Graph via Cypher queries. Any Claude/ChatGPT agent can now query GxP master data without hallucinating.
Architecture
Claude / ChatGPT / Cursor
|
| MCP (stdio)
v
mcp_server.py (14 tools)
|
| Cypher queries
v
Neo4j (or MOCK mode: NetworkX + JSON) <- your MDM golden recordWhy Cypher?
Blast radius is a graph traversal:
MATCH (start)-[:SENDS_VIA*1..3]->(downstream)— impossible in SQLData lineage for ALCOA+ investigations
Regulation ground truth — agent can only cite clauses returned by Cypher, prevents hallucination
Related MCP server: Fianu Compliance Intelligence MCP Server
14 Tools Exposed
Tool | Cypher | What it does |
| Custom | Safe read-only Cypher for exploration |
|
| Full inventory - auditors ask this first |
| Full subgraph | System + functions + e-records + supplier + interfaces |
|
| Killer app: What downstream GxP systems are impacted by change? |
| Reverse traversal | Where does data come from? |
|
| Anti-hallucination: only these clauses can be cited |
|
| API/file/manual interfaces with GxP flag |
|
| Non-validated GxP Direct systems |
|
| Overdue periodic reviews |
|
| E-sig, batch release, potency |
|
| Supplier audit status, SOC2 |
|
| Lineage for a record type |
|
| GxP Direct inventory |
| Composite | Orchestrates 3 Cypher queries + generates impact assessment per GAMP 5 / CSA |
Quick Start (No Neo4j needed - Mock Mode)
cd gxp_mdm_mcp_server
pip install -r requirements.txt
# Mock mode: uses JSON + NetworkX, no Neo4j required
python scripts/test_tools.py
# Should show:
# - List 4 systems
# - Veeva QMS details with downstream SAP
# - Blast radius: Veeva -> SAP
# - REJECT for audit trail purge
# - Minor for version upgradeMock mode is perfect for POC and Claude Desktop testing.
Prod Mode with Neo4j
# .env - set Neo4j creds
cp .env.example .env
# Edit .env with your Neo4j URI
# Start Neo4j
docker-compose up -d neo4j
# Load sample data + schema
python scripts/load_sample_data.py
# Test with Neo4j
python scripts/test_tools.py
# Start API harness (optional)
uvicorn src.api_server:app --reload --port 8000
# http://localhost:8000/cypher/list_all_systems
# http://localhost:8000/cypher/blast_radius?system_id=SYS-VEEVA-QMS-001Claude Desktop Config
Find your Claude config:
~/Library/Application Support/Claude/claude_desktop_config.json(Mac) or%APPDATA%/Claude/claude_desktop_config.json(Win)Add (use absolute path):
{
"mcpServers": {
"gxp-mdm-cypher": {
"command": "python",
"args": ["/absolute/path/to/gxp_mdm_mcp_server/src/mcp_server.py"],
"env": {
"NEO4J_URI": "",
"NEO4J_USERNAME": "neo4j",
"NEO4J_PASSWORD": "password"
}
}
}
}For mock mode, leave NEO4J_URI empty. For Neo4j, set to bolt://localhost:7687.
Restart Claude Desktop. You should see 14 tools under 🔌.
Try prompts:
List all GxP Direct systems in my inventory
> calls list_all_systems(gxp_impact="Direct")
What happens if I change Veeva QMS? Show blast radius
> calls get_blast_radius(system_id="SYS-VEEVA-QMS-001")
Assess this change: Enable audit trail purge after 7 years for Veeva QMS
> calls assess_change_impact -> should REJECT per 21CFR11.10(e)
Assess Veeva upgrade from 24R1 to 24R2 with no e-sig change
> calls assess_change_impact -> should be Minor per CSA low riskCursor Config
See config/cursor_config.json.example - add to .cursor/mcp.json
ChatGPT (with MCP support)
If using ChatGPT custom GPT with MCP, use config/chatgpt_mcp_config.json as reference. ChatGPT will call tools via stdio.
Cypher Queries - Ground Truth
All queries in src/cypher_tools.py. Key ones:
Blast radius (the moat):
MATCH (start:ComputerizedSystem {system_id: $system_id})
MATCH path = (start)-[:SENDS_VIA*1..$depth]->(downstream:ComputerizedSystem)
WHERE downstream.gxp_impact IN ['Direct', 'GxP Relevant']
RETURN downstream.system_id, length(path) as distanceRegulation anti-hallucination:
MATCH (s:ComputerizedSystem {system_id: $system_id})
OPTIONAL MATCH (s)-[:HAS_FUNCTION]->(f)-[:REGULATED_BY]->(reg)
RETURN collect(DISTINCT reg) as regulationsAgent must ONLY cite clause_ids returned here.
From POC to Production
Replace
data/*.jsonwith real Veeva Vault API + ServiceNow CMDB + OktaAdd write tools (with approval workflow) for updating validation_status
Add vector search tool for regulation RAG (embed GAMP 5 2nd Ed)
Add periodic review agent that calls
find_periodic_review_overdueon schedule
You now own the layer every CSV agent must query.
Troubleshooting
No module named mcp:pip install mcpClaude doesn't see tools: Check absolute path in config, restart Claude, check logs
~/Library/Logs/Claude/mcp*.logNeo4j connection fails: Falls back to mock mode automatically - check
NEO4J_URI
Good luck cornering the market.
NEW: Write Tools with Approval Workflow (GxP Compliant)
Why approval workflow?
21 CFR Part 11.50 and Annex 11 require:
2-person rule (requester != approver)
Reason for change (ALCOA+ Complete)
Electronic signature manifestation (who, when, meaning)
Immutable audit trail (who, when, old/new, reason)
All write tools enforce this.
Write Tools Added
Tool | What it does | GxP Control |
| Create pending change request | Logs REQUEST audit, requires reason >=10 chars |
| Approve + apply change | Enforces requester != approver, logs e-sig, updates system + next review date |
| Reject with reason | Logs REJECT audit |
| List pending QA approvals | |
| Full audit trail with e-signatures | 21CFR11.10(e), Annex 11.7 |
Example Workflow via Claude
You: Change Veeva QMS status to Validated - Change Implemented, reason: IQ/OQ passed for 24R2 upgrade, requested by qa.john
Claude calls:
request_validation_status_change_tool(system_id="SYS-VEEVA-QMS-001", new_status="Validated - Change Implemented", reason="IQ/OQ passed for 24R2 upgrade, evidence in Veeva Vault VP-2024-089", requested_by="qa.john@company.com")
-> Returns request_id CHG-VAL-A1B2C3, status Pending Approval
You: Approve CHG-VAL-A1B2C3 by qa.sarah, comment: Reviewed IQ/OQ, approved
Claude calls:
approve_validation_status_change_tool(request_id="CHG-VAL-A1B2C3", approver="qa.sarah@company.com", approval_comment="Reviewed IQ/OQ")
-> Applies change, updates sample_systems.json, creates audit trail with e-signature
You: Show audit trail for Veeva QMS
Claude calls:
get_audit_trail_tool(system_id="SYS-VEEVA-QMS-001")
-> Returns who, when, old/new, reason, electronic signature manifestationTry via API:
curl -X POST http://localhost:8000/request-status-change -H "Content-Type: application/json" -d '{"system_id":"SYS-VEEVA-QMS-001","new_status":"Validated - Change Implemented","reason":"IQ/OQ passed for 24R2 upgrade","requested_by":"qa.john@company.com"}'
curl -X POST http://localhost:8000/approve-status-change -d '{"request_id":"CHG-VAL-A1B2C3","approver":"qa.sarah@company.com","approval_comment":"Reviewed"}'
curl http://localhost:8000/audit-trail?system_id=SYS-VEEVA-QMS-001NEW: Scheduled Periodic Review Agent
What it does
Automatically:
Calls
find_periodic_review_overdueCypher daily at 8am (via APScheduler)For each overdue GxP Direct system, generates draft Periodic Review Report per GAMP 5 Section 6.5 and Annex 11.11
Saves draft JSON + logs audit trail CREATE_DRAFT
Each draft includes 10 sections auditors expect:
System description (from MDM)
Changes since last review (from mock Jira)
Deviations/incidents
Audit trail review (sample, immutable check)
User access review (dormant accounts)
Backup/restore test
Supplier review (SOC2)
Data integrity ALCOA+
Interfaces - blast radius from MDM graph
Conclusion + required actions
Tools
Tool | Purpose |
| Scan overdue (Cypher) |
| Scan + generate drafts for all overdue |
| Generate for one system |
| List drafts |
Run Scheduler
# Run once manually
python -c "from src.periodic_review_agent.agent import agent; print(agent.scan_overdue())"
# Generate drafts
python -c "from src.periodic_review_agent.agent import agent; print(agent.generate_drafts_for_overdue())"
# Run as daemon (daily 8am + every 6h demo)
python src/periodic_review_agent/scheduler.pyIn prod, replace APScheduler with Airflow DAG or Temporal workflow that calls the MCP tool run_periodic_review_scan.
Via Claude
You: Run periodic review scan
Claude calls run_periodic_review_scan() -> finds 2 overdue systems
You: Generate drafts for overdue
Claude calls generate_periodic_review_drafts() -> creates PR-SYS-VEEVA-QMS-001-2025-XXXX reports
You: Show me draft for Veeva QMS
> Returns full 10-section reportDrafts saved to data/periodic_reviews/PR-*.json - ready to upload to Veeva Vault as ValidationArtifact.
This v2 makes you audit-ready: writes are controlled, audit trail is ALCOA+, and periodic reviews are automated — exactly what QA directors pay consultants $200/hr for.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceEnables creating, managing, analyzing, and visualizing knowledge graphs with support for multiple graph types (topology, timelines, changelogs, requirements, knowledge bases, ontologies) including node/edge management and resource association.15191MIT
- FlicenseNot gradedqualityCmaintenanceEnables AI assistants to query software supply chain compliance data, including asset status, security vulnerabilities, and evidence lineage. It allows for natural language analysis of compliance posture, policy violations, and deployment blockers across an organization.
- AlicenseAqualityDmaintenanceConnects AI assistants to ServiceNow CMDB via natural language, enabling querying, dependency analysis, health auditing, CI lifecycle management, and configurable inspection.40MIT
- AlicenseAqualityDmaintenanceEnables AI to analyze, query, and manage a graph-based representation of software architecture for impact analysis, dependency tracking, and design.20121AGPL 3.0
Related MCP Connectors
AI knowledge graph for architecture, portfolio, and digital strategy management.
Shared, permission-aware company context for AI agents, with provenance, approvals and audit.
Runtime AI governance: decision gates, human approval, hash-chained audit, compliance mapping.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/saram-io/gxp_mdm_mcp_server_v2'
If you have feedback or need assistance with the MCP directory API, please join our Discord server