The Msharti handbook
Msharti connects AI assistants to the systems your business runs on, and governs what they are allowed to do once connected. Everything here is organised around those two ideas: the access plane that reaches your systems, and the control plane that decides what happens there.
Simulated session · real MCP tool names · mcp.msharti.dev
Getting started
Read this first if Msharti is new to you.
Sign up, connect a system, connect an assistant, ask a real question. About ten minutes.
What is Msharti?The one-paragraph version, and where it fits next to the tools you already run.
What is MCP?The open standard that lets assistants discover and call tools.
Quick GuideConnect, query, secure, govern. The whole product in one read.
GlossaryEvery term this handbook uses, defined once and used consistently.
Platform
What the platform is made of, and how a request actually travels through it.
The access plane and the control plane, and what lives in each.
Request flowThe six stages every call passes through, in order, with no fast path.
The MCP gatewayOne endpoint, transport and sessions, tool discovery, injection scan, secret stripping.
Connectors & toolsWhat a connector is, what a tool is, and all 26 of them.
Tenants & API keysIsolation at the credential, the container and the database row. Key formats and rotation.
Deployment modelsManaged cloud, a private instance, or fully inside your own network.
Connect your AI
One URL, whichever assistant you use. OAuth is discovered from it, so there is nothing to paste.
What to have ready, how to verify it worked, and the usual failure modes.
ClaudeCustomize → Connectors → Add custom connector. Three steps.
ChatGPTDeveloper Mode, then a connector with OAuth.
Microsoft CopilotCopilot Studio with dynamic discovery, or an API key where DLP blocks it.
Cursor & custom MCPAny MCP 2025-03-26 client. Endpoints, PKCE and bearer format.
Agents & access
An agent is a credential bound to a role bound to a tool allowlist. This is how you build one that cannot exceed its brief.
End to end, including the step most teams skip: proving the denial works.
Roles & permissionsThe four built-in roles, custom roles, and how allowlists are evaluated.
Teams & seatsInviting people, seat limits, and the two-step offboarding that matters.
The console
Where the control plane is actually operated.
All nine screens, what each is for, and who can see it.
Governance & auditWhat is recorded, how to read it, and how to answer an auditor.
SecurityEncryption, isolation, gateway protections, residency and compliance.
Catalog & recipes
What Msharti connects to, and worked examples of it doing something useful.
26 connectors, 149 tools, 7 categories.
M-Pesa reconciliationCollections against invoices, end to end, in one question.
Supplier TCC sweepBulk tax-compliance checking across your supplier list.
Pipeline in CopilotA CRM pipeline summary inside the assistant your team already opens.
Reference
The details, without the surrounding explanation.
Every URL, header, key format and protocol detail in one page.
Limits & plansRate limits, row caps, data windows, token lifetimes, retention.
ChangelogWhat shipped, and when.
Still stuck?
We are a Nairobi team, so you are asking someone in your own time zone with your own context. Email [email protected], or book a demo if you would rather be walked through it.