5 min read

What is an MCP server? Why Comprose built one for our policy management software

An MCP server acts as a bridge between a software and an AI assistant, such as Claude and Copilot. This connector lets your AI assistant actually understand a specific system, so instead of guessing, the assistant can ask and get a real answer back. Zavanta's new MCP server does this for your policy and procedure : employees ask questions in plain language and get answers pulled from your actual, current procedures, with your existing permissions intact and nothing used to train a model.

 

What is an MCP Server, and why did Comprose build one?

If you've spent time reading about AI tools like Claude or Copilot, you've probably run into the term "MCP server" and wondered what it actually means for your organization. Model Context Protocol, or MCP, is new enough that most policy and compliance teams haven't had a reason to think about it yet. Then their AI assistant needs to answer a question using the organization's actual procedures instead of a generic guess, and suddenly it matters.

That's the problem Zavanta's new MCP server solves. Here's what it is, how it works, and what we did to make sure connecting your policy library to an AI assistant doesn't come at the cost of your data's security.

What is an MCP server?

MCP is an open standard that lets AI assistants connect to outside systems and pull in real information instead of relying only on what they were trained on. Think of it as a translator that sits between an AI tool and a piece of software. The assistant can ask that software a question and get a real answer back.

An MCP server is the piece that makes a specific system, like Zavanta, understandable to an AI assistant. Without one, an AI tool has no way to know what's actually written in your policy manual. With one, it can look it up securely.

Why did Comprose build one for Zavanta?

AI assistants are moving fast, and the organizations that get ahead of that curve are the ones thinking now about how AI fits into the tools they already rely on. Comprose built the Zavanta MCP server so our customers aren't playing catch-up later. This isn't AI for its own sake; it's AI that works the way your policy library already works.

Employees ask questions about policy every day: what the expense limit is, who approves a vendor contract, how to complete a certain order processing form. Today, someone usually has to search through Zavanta directly to find the answer, or they turn to an AI assistant and get a response that sounds confident but isn't grounded in your actual procedures.

Neither is ideal. Searching takes time, and an AI assistant guessing at your policy is worse than not answering at all, because a wrong answer that sounds right is easy to trust.

The Zavanta MCP server solves this by letting employees ask their AI assistant directly and have it check the real, current version of your procedures before it answers. It's faster than searching and more reliable than guessing, and it does this without loosening the access controls or privacy protections already built into Zavanta. The response comes from your content, not from a language model's assumptions about what a typical company's policy might say.

How does it work in practice?

Say an employee opens Claude or another MCP-compatible assistant and asks, "What's our policy on remote work equipment reimbursement?" With the Zavanta MCP server connected, the assistant queries Zavanta, finds the relevant, currently approved procedure within their security and access status, and answers using that content, with a reference back to the source document.

The employee gets a direct answer instead of a search result to dig through. The compliance team gets confidence that the answer reflects the version of the policy that's actually in effect, not an outdated copy sitting in someone's inbox.

Does connecting Zavanta to an AI assistant put our content at risk?

This is the question we spent the most time on, and it's the right one to ask before turning on any integration involving your policy library.

Using Zavanta's MCP server, you can expect: 

  • It respects the same permissions your organization already has set up in Zavanta. An AI assistant can only retrieve content that the requesting user is authorized to see. It doesn't get broader access than the person using it.

  • Your content is not used to train any AI model. Information retrieved through the MCP server is used to answer the specific question asked, in that moment, and nothing more.

  • The connection is authenticated and scoped, so it isn't an open door between your document library and every AI tool on the internet. You control which assistants can connect and what they can reach.

None of this replaces good judgment about what belongs in an AI conversation. But it means the access controls you've already built into Zavanta carry over, rather than getting bypassed the moment AI enters the picture.

Who should turn this on?

If you are a Zavanta customer and your teams are already using Claude, Copilot, or similar assistants, the Zavanta MCP server will give employees answers grounded in that content rather than generic guesses. This closes the gap between what they're asking and what your actual procedures say.

It's a smaller step for organizations that already have their content structured and access controls in place in Zavanta. If your procedures are scattered across shared drives and email threads, an MCP server won't fix that on its own. Structured, current content is still what makes any AI integration useful.

Getting started

The MCP server is part of Zavanta's newest release, and it's available to current customers who want to connect an MCP-compatible AI assistant to their content. If you're curious whether it fits how your teams already work, or you have questions about the security model before turning it on, contact us to start a conversation.

 

 

Click me

 

FAQs


 

About Comprose

Large Logo - White Background (3)As the creators of Zavanta, Comprose helps organizations transform complex policies and procedures into clear, consistent, and easy-to-follow documentation. Our policy and procedure management software empowers teams to improve compliance, reduce risk, and streamline operations through a centralized, cloud-based platform.

We specialize in serving highly regulated industries—from financial services and credit unions to healthcare and government—by delivering purpose-built tools that enhance transparency, accountability, and audit readiness.

With over 30 years of experience, Comprose makes it easier for organizations to document what they do, how they do it, and why it matters. This helps employees stay aligned, and compliance becomes second nature.