Skip to main content
Glama

Varco — the approval gateway for AI agents

Your AI agents act on real business systems. You stay in control.

Varco sits between any MCP-compatible agent (Claude, Copilot, Cursor, custom agents) and your backend (ERP, or any REST/Odoo system) and enforces:

  • Per-agent permissions — each agent has an identity and sees only what it's allowed to; unregistered agents are rejected at the first tool call.

  • Autonomy thresholds — writes within policy (e.g. orders under €1,000) execute immediately and are logged; everything else waits for a human. Conservative by design: no threshold, no readable amount → always ask.

  • Human approval with review-and-edit — approvers see the request in plain language, can fix values before approving, and decide with one tap from the web app or Telegram (WhatsApp next).

  • Full audit trail — every read, request, approval, rejection and auto-execution is recorded. Built for EU AI Act art. 14-style human oversight.

AI agent ──MCP──▶ varco_mcp ──▶ SQLite state ◀── dashboard / Telegram ◀── human
                     │                                   │
                     └─ reads (audited)                  └─ writes ONLY after
                                 ▼                          policy or approval
                     backend: mock ERP · REST · Odoo (JSON-RPC)

Quickstart

python -m venv .venv
.venv/Scripts/python -m pip install -r requirements.txt   # mcp, httpx
.venv/Scripts/python test_varco.py                        # all suites: test_*.py
.venv/Scripts/python varco_dashboard.py                   # http://127.0.0.1:8420

The default config ships a mock ERP with sample data, four departments (Sales, Administration, Purchasing, Warehouse) and five agents — a full working demo with no external system.

Connect an agent (Claude Code example):

claude mcp add varco --scope project -e VARCO_AGENT=assistente-vendite -- <path>/.venv/Scripts/python <path>/varco_mcp.py

Related MCP server: AgentsGate

Configuration

Everything lives in varco_config.json: backend (mock, REST base URL, or "tipo": "odoo" — see varco_config.odoo.json for a ready-made Odoo mapping), entities, departments, agents with read/write permissions and soglie (autonomy thresholds per entity). Secrets never go in the config: API keys via ERP_API_TOKEN, Telegram via TELEGRAM_BOT_TOKEN + TELEGRAM_CHAT_ID.

Tests

Five self-contained suites, no external services required: test_varco.py (policy + approvals), test_dashboard.py (web app), test_varco_mcp.py (real MCP protocol round-trip), test_varco_rest.py and test_varco_odoo.py (backend adapters against local fake servers).

Docs in Italian

Product docs and the SMB demo script: README.it.md.

Roadmap

WhatsApp Business approvals · Odoo App Store module · hosted cloud (free / $99 / $399) · approval digests & bulk approve · per-approver web confirmation above a second threshold.

MIT licensed. Built in Italy 🇮🇹

A
license - permissive license
Not graded
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Human-in-the-Loop authorization gateway for AI Agents. Securely pause MCP workflows and route high-risk actions to human approvers via Slack or Email.
    117
    1
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables AI agents to securely call MCP tools with risk scoring, checkpoints, rollback, and approval workflows.
    17
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Provides a secure MCP boundary for AI agents, intercepting and validating tool calls, redacting secrets, and requiring human approval for sensitive actions with a tamper-evident audit trail.
  • F
    license
    Not graded
    quality
    C
    maintenance
    MCP server that provides a security gateway for AI agents, enforcing allow/confirm/deny policies on tool calls and requiring human approval for risky operations, with full audit logging.

View all related MCP servers

Related MCP Connectors

  • Runtime permission, approval, and audit layer for AI agent tool execution.

  • Control plane for autonomous software labor. Agents claim objectives over MCP with audit trail.

  • Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/williamselmo1993/varco'

If you have feedback or need assistance with the MCP directory API, please join our Discord server