Project ยท AI

Least-privilege AI tooling: the SIGNALS MCP server

Giving an AI assistant read/write access to exactly one spreadsheet and nothing else.

The September 2026 edition of Earthchain's SIGNALS newsletter, "Who's doing the chasing?"

SIGNALS is Earthchain's monthly newsletter for sustainability teams, sharing practical lessons on using data and automation to support better decisions and real action.

The September 2026 edition,
The September 2026 edition, "Who's doing the chasing?"

Each edition is planned and written in a Google Sheet. I wanted Claude to draft and edit editions directly, without giving an AI agent the keys to the whole Google account. That account also holds a CRM sheet with customer names, emails and phone numbers.

The approach

Instead of a general-purpose Sheets integration, I built a small Model Context Protocol server that is deliberately narrow:

  • It's bound to a single, hard-coded spreadsheet ID. No tool accepts an ID as input.
  • It holds only the Sheets scope, not Drive, so it can't list or open other files.
  • Its tools are shaped around the editorial job (list editions, read an edition, write a field, lint copy against the house style), not around raw cell access.

Why it matters

This is the pattern I recommend to teams adopting AI agents: design the tool surface around the task, and make the dangerous thing impossible rather than merely discouraged.

Working on something in fintech, AI or climate?

I help founders and teams shape products, untangle architecture and get to market. Short advisory calls or hands-on engagements.

Talk to me about a project