Skip to main content
Create Free Account

AI in ComplyFlow

AI Assistants via MCP: Ask Your Record, Skip the Report.

Which sites reported incidents this month? Who is on site with an expired licence? Ask ChatGPT, Claude, or Copilot and the answer comes from your live record, within your token’s scopes and your own permissions. Read only.

  • Safety & HSE
  • IT & Data
  • Operations
  • Executive
Read only, on scoped tokens that expire within a year

The Answer in Seconds, From the Live Record, Nothing Changed.

The Model Context Protocol is an open standard that lets an AI assistant read another system safely. ComplyFlow ships an MCP server, so ChatGPT, Claude, Claude Code, GitHub Copilot, or any assistant that speaks MCP can read your record through a token you create: incidents, inspections, Workers, risks, plant, sites, and permits. Access is read only.

  • Your permissions, not more. A token can never see more than you can. The assistant reads your sites, with your role’s access.
  • Scoped and expiring. Eight read scopes, chosen per token. Expiry from 7 days to 1 year. Revoked the moment you confirm it.
  • Read only, by design. The MCP Server and personal API tokens look up and summarise. They cannot create, change, or delete anything in ComplyFlow.
A safety manager in a quiet open-plan office typing a question into an AI assistant on a laptop, a second monitor beside it showing a site map

How It Works

Three Screens That Carry the Feature.

The token you create, the assistant you connect, and the question answered from the record.

The Token, Scoped to What It May Read.

From the user menu, open API Tokens and choose New token. Name it, pick the scopes it may read, sites, staff, contractors, incidents, inspections, plant, risks, permits, and choose when it expires, from 7 days to 1 year. The token is shown once. Revoke it from the same screen and it stops immediately.

  • Eight read scopes, all read only
  • Expiry from 7 days to 1 year; up to 10 tokens per user
  • Shown once; revoked the moment you confirm

The Assistant, Connected in One Command.

In Claude Code, one command adds the ComplyFlow server with your token as an environment variable; or drop a small config file into the project. In VS Code, GitHub Copilot picks it up from a config file and asks for the token once. Node.js 20 or later is the only requirement on the machine.

  • Claude Code: one terminal command or one config file
  • GitHub Copilot in VS Code: a config file and Agent mode
  • ChatGPT, and any other assistant that speaks MCP

The Question, Answered From the Live Record.

A safety manager asks which sites reported incidents this month. The assistant reads the incident register through the token’s scopes and the manager’s own site permissions, and answers with the rows. Ask a follow-up, ask for a summary, ask it to compare two sites. It reads; it does not write.

  • The live record, not an export
  • Your sites and your role’s access, nothing more
  • Look up and summarise; never create, change, or delete

What It Is Worth

Time Saved, Nobody Else’s Report, Nothing the Assistant Can Break.

No figure here is a promise. The return depends on how many questions your team answers from ComplyFlow each week and how they answer them today, so bring that to the demo and we will work it through with you.

For the person asking the question

  • The answer where you already are

    Ask in the assistant you have open, not in a dashboard you have to build a filter in.

  • The live record, not last week’s export

    What the assistant reads is what ComplyFlow holds right now, on your permissions.

  • A follow-up, not a new report

    Ask for the same figure by site, by month, or against last quarter, in the same conversation.

For the business

  • Nothing can be changed this way

    The MCP Server and personal API tokens are read only. The assistant looks up and summarises; a person acts in ComplyFlow.

  • Control that IT can sign off

    Four layers: a token that expires and is revocable, scopes per module, the user’s own permissions and sites, and organisation isolation.

  • Fewer requests to the data person

    The safety manager answers their own question; the analyst is not building a one-off report for it.

  • The same record everything else uses

    The assistant reads the record the gate, the permits, and the approvals run on. There is no second copy to drift.

The return, in your numbers

  • Questions a week

    How often someone asks who is overdue, what happened at a site, or how many are uncleared.

  • How each is answered today

    A dashboard filter, an export to a spreadsheet, an email to the analyst. Against a sentence typed into an assistant.

  • Reports built by hand a month

    The board summary, the site comparison, the incident roll-up. Against asking for them.

  • What it costs, opens the Help Centre in a new tab

    The MCP Server is documented in the Help Centre with no separate charge published. AI usage has been included in Enterprise plans since 24 March 2026; ask us for your plan.

Where the Help Centre documents an item, its name links to the article.

How It Stacks Up

An AI Assistant on MCP Against the Ways Questions Are Answered Now.

Two ways a manager gets an answer out of the record today, and what each one cannot do.

A dashboard filter and an exportBuild the view, export it, tidy it in a spreadsheetAsking the analystA one-off report, when they get to it ComplyFlowOne record, your standard
The live record, not a copy Built inPartly Read through the Platform API as you ask
Asked in plain English, in the tool you already have open Not therePartly ChatGPT, Claude, or Copilot, through MCP
A follow-up without starting again Not thereNot there Ask by site, by month, or against last quarter in the same conversation
Limited to your own permissions and sites Built inPartly A token can never see more than you can
Cannot change anything Built inBuilt in The MCP Server and personal API tokens are read only
Nobody else’s time spent PartlyNot there The manager answers their own question

This compares ways of working, not named vendors. Nothing is changed in ComplyFlow in any column, including ours.

  • ISO 27001 certified ISO 27001Certified 2019
  • AWS Qualified Software Certified 2023
  • GDPR, General Data Protection Regulation Compliant 2020
  • Microsoft Okta Single sign-on

Security & Data

Certified, Audited & Hosted in Australia.

Your compliance record is the evidence you rely on when somebody asks, so where it lives and who can reach it matters. ComplyFlow is ISO 27001 certified, runs on AWS in Australia, and your people sign in with the accounts they already have.

Questions

Questions People Ask About the MCP Server.

What is MCP?

The Model Context Protocol, an open standard that lets an AI assistant read another system safely. ComplyFlow ships an MCP server that reads your data through the Platform API using a scoped token you create, so an assistant can look up and summarise your record.

Which assistants can connect?

ChatGPT, Claude, Claude Code, and GitHub Copilot, and any other assistant that speaks MCP. The Help Centre’s set-up guides cover Claude Code, which connects in one command, and GitHub Copilot in VS Code, which takes one config file.

Can the assistant change anything in ComplyFlow?

No. Access through the MCP Server and personal API tokens is read only. The assistant can look up and summarise incidents, inspections, Suppliers and contractors, Workers, risks, plant, sites, and permits. It cannot create, change, or delete anything.

How is it secured?

Four layers, as the Help Centre lists them: a personal API token that expires within a year and is revoked the moment you confirm it; scopes that limit the token to named modules, all read only; the permissions and site assignments of the Staff User who created it; and isolation between organisations. A token can never see more than you can.

Who can create a token?

A Staff User with API token management permission, from the user menu under API Tokens. Contractors and Workers do not create tokens. Each user can hold up to 10 active tokens, and each is shown once at creation.

What does it cost?

The Help Centre documents the MCP Server without a separate charge. AI usage has been included in Enterprise plans since 24 March 2026; for other plans, ask us. The MCP Access collection has the set-up guides.

Ask It Something on the Demo.

Book 30 minutes. We will connect Claude Code to a demo account in front of you and you can ask the record whatever you like.

  • ISO 27001
  • Hosted on AWS
  • Microsoft & Okta SSO
  • API & MCP
  • Data in Australia

Compliance you can prove, instantly.