Your staff already use AI. Give them governed access instead of guesswork.
MCP Connect lets Microsoft Copilot, Claude, and ChatGPT answer questions from your institution's origination data — safely. Read-only in v1.0, every query audited with 7-year retention, PII masked by default, and access scoped to each employee's role through Microsoft Entra or Okta.
Governed by design, not by policy memo
Read-only v1.0
MCP Connect v1.0 is strictly read-only. AI assistants can look up and summarize — they cannot create, modify, or delete anything. Guardrails are architectural, not configurable away.
Every query audited
Each question, each tool call, and each response is logged with a 7-year retention period — an examiner-ready record of exactly how AI touched your data.
PII masked by default
Personally identifiable information is masked before it ever reaches the AI assistant. Staff get answers; models don't get Social Security numbers.
Role-scoped via Entra / Okta
Access rides on your existing identity provider. A member services rep and a lending manager see only what their roles allow — same as in your other systems.
Works with the AI you chose
Microsoft Copilot, Claude, and ChatGPT connect through the open Model Context Protocol — no proprietary chatbot to license or train your staff on.
~15 minutes per client
Connecting an approved AI client takes about 15 minutes. Governance is centralized, so adding a user doesn't mean a new security review.
What teams do with it
90-second answers
"Where is this member's application stuck, and what do they still need to submit?" Answered in seconds from live origination data — instead of a swivel-chair search across systems while the member waits on hold.
Unstall the queue
"Show me applications stalled more than 48 hours and why." Lending managers surface stuck files, missing documents, and pending verifications across the pipeline with one question — and clear them before applicants walk.
Audit pack on demand
"Assemble the verification history for these applications." Compliance teams pull decision trails, screening results, and documentation in minutes — with the 7-year query log itself serving as evidence of governed AI use.
Built for the compliance conversation
FFIEC expectations
Access controls, logging, and vendor accountability map to FFIEC guidance on technology service providers — with documentation your IT examiner can review.
GLBA safeguards
PII masking by default and role-scoped access support your GLBA Safeguards obligations: staff see what their function requires, and nothing more leaves the perimeter.
SR 11-7: out of scope by design
MCP Connect retrieves and summarizes data — it does not score, decision, or replace a model in your credit process. That keeps v1.0 outside typical SR 11-7 model-risk scope; we provide the documentation for your model risk team to make that determination.
NCUA 2026 posture
As NCUA sharpens its focus on AI governance heading into 2026, MCP Connect gives credit unions a concrete answer: read-only access, full audit trail, identity-based scoping, and PII controls — governed AI, documented.
Cotribute is SOC 2 Type 2 certified. Trust & Security → · Trust Center ↗
Pricing — published, not gated
| Plan | Price | Best for | Includes |
|---|---|---|---|
| Starter | $0 — included with AI Growth Agents | Institutions already running AI Growth Agents | Governed read-only access, audit logging with 7-year retention, PII masking, Entra/Okta role scoping |
| Plus | $9,600/yr | Institutions adopting MCP Connect standalone | Everything in Starter for your full team, with support included |
| Enterprise | Custom | Multi-entity institutions and advanced requirements | Custom scoping, security review support, and enterprise controls |
Frequently asked questions
RiskCan an AI assistant change or delete data through MCP Connect?
No. MCP Connect v1.0 is read-only by architecture. Assistants can query and summarize origination data; there is no write path — no creating, modifying, or deleting records through the connector.
ComplianceWhat audit trail do we get?
Every query is logged — who asked, what was asked, which tools were called, and what was returned — and retained for 7 years. The log doubles as evidence of governed AI use for examiners and internal audit.
ComplianceDoes MCP Connect fall under SR 11-7 model risk management?
v1.0 retrieves and summarizes data; it does not score applicants, make credit decisions, or feed a decisioning model. That places it outside typical SR 11-7 model scope, and we supply documentation so your model risk management team can make and record that determination themselves.
ITHow does access control work?
MCP Connect integrates with Microsoft Entra and Okta. Permissions are scoped by role, so each employee's AI assistant can only reach the data their existing role allows. PII is masked by default before any response reaches the assistant.
ITHow long does setup take?
About 15 minutes per client. Connect an approved AI assistant — Copilot, Claude, or ChatGPT — authenticate through your identity provider, and governed access is live. No custom development.
CFOWhat does it cost?
Starter is included at $0 with AI Growth Agents. Plus is $9,600 per year standalone. Enterprise is custom for multi-entity or advanced requirements. Pricing is public — no call required to see it.
Give your team governed AI access
Review pricing, or talk through your identity provider and rollout with our team.
