Your staff already use AI. Give them governed access instead of guesswork.
MCP Connect lets Claude, ChatGPT, and Microsoft Copilot answer questions from your institution's origination data — safely. Read-only in v1.0, every query audited, no applicant personal information leaves Cotribute, and access scoped to each employee's Cotribute staff account and flow permissions over OAuth 2.0.
Governed by design, not by policy memo
Read-only v1.0
MCP Connect v1.0 is strictly read-only. AI assistants can look up and summarize — they cannot create, modify, or delete anything. Guardrails are architectural, not configurable away.
Every query audited
Each question, each tool call, and each response is logged to your institution's audit trail — an examiner-ready record of exactly how AI touched your data.
Aggregate figures only
No applicant personal information leaves Cotribute — this version returns aggregate figures only. Staff get answers; models never see applicant records.
Role-scoped over OAuth 2.0
Role-scoped access using your existing Cotribute staff account and flow permissions, over OAuth 2.0. A member services rep and a lending manager see only the flows their roles allow.
Works with the AI you chose
Claude, ChatGPT, and Microsoft Copilot connect through the open Model Context Protocol — no proprietary chatbot to license or train your staff on.
~15 minutes per client
Connecting an approved AI client takes about 15 minutes. Governance is centralized, so adding a user doesn't mean a new security review.
What teams do with it
90-second answers
"What does our application pipeline look like today?" Answered in seconds from live origination data — instead of a swivel-chair search across systems to assemble the same picture by hand.
Unstall the queue
"Which applications have been stalled for more than a week?" Lending managers surface stalled, pending, and unread volumes across the pipeline with one question — and clear them before applicants walk.
Audit pack on demand
"How are approvals trending over the last 30 days?" Compliance teams read approval and volume trends in minutes — with the query log itself serving as evidence of governed AI use.
Built for the compliance conversation
FFIEC expectations
Access controls, logging, and vendor accountability map to FFIEC guidance on technology service providers — with documentation your IT examiner can review.
GLBA safeguards
No applicant personal information leaves Cotribute — this version returns aggregate figures only — and access is role-scoped, supporting your GLBA Safeguards obligations: staff see what their function requires, and nothing more leaves the perimeter.
SR 11-7: out of scope by design
MCP Connect retrieves and summarizes data — it does not score, decision, or replace a model in your credit process. That keeps v1.0 outside typical SR 11-7 model-risk scope; we provide the documentation for your model risk team to make that determination.
NCUA 2026 posture
As NCUA sharpens its focus on AI governance heading into 2026, MCP Connect gives credit unions a concrete answer: read-only access, full audit trail, role-scoped access over OAuth 2.0, and aggregate-only responses — governed AI, documented.
Cotribute is SOC 2 Type 2 certified. Trust & Security → · Trust Center ↗
Pricing — published, not gated
| Plan | Price | Best for | Includes |
|---|---|---|---|
| Starter | $0 — included with AI Growth Agents | Institutions already running AI Growth Agents | Governed read-only access, audit logging of every query, aggregate-only responses, role-scoped access over OAuth 2.0 |
| Plus | $9,600/yr | Institutions adopting MCP Connect standalone | Everything in Starter for your full team, with support included |
| Enterprise | Custom | Multi-entity institutions and advanced requirements | Custom scoping, security review support, and enterprise controls |
Connect Cotribute to Claude
Cotribute is available as a connector in Claude, ChatGPT, and Microsoft Copilot via the open Model Context Protocol. Setup takes about 15 minutes.
Server URL
https://mcp.cotribute.co
Before you connect
- Your institution must have an active Cotribute MCP plan — Starter, Plus, or Enterprise. A Cotribute administrator enables this from Settings; staff cannot connect until it's on.
- You need an existing Cotribute staff account with an assigned role. Access is automatically scoped to the application flows you're already permitted to see.
In the Cotribute admin settings this feature appears as Cotribute MCP.
Connect in Claude
- In Claude, open Settings → Connectors and choose to add a custom connector.
- Paste the server URL above.
- Sign in with your Cotribute staff email and password when prompted. If your email address exists at more than one institution, you'll be asked to choose which one to connect.
- Start a new conversation so Claude picks up the new connector.
Authentication uses OAuth 2.0 — Claude never sees or stores your Cotribute password.
What you can ask
- "What does our application pipeline look like today?"
- "Which applications have been stalled for more than a week?"
- "How are approvals trending over the last 30 days, and which flow has the most applications?"
What the connector can and cannot see
This version is read-only and returns aggregate figures only — counts, trends, and alert totals across your application pipeline. It exposes three tools: pipeline metrics, 30-day trends, and stalled/pending/unread alerts.
It cannot create, modify, or delete anything, and it does not return applicant personal information. If you ask for an individual applicant's name, email, or other personal details, the connector will decline — by design. Use the Cotribute portal for application-level work.
Every query is logged to your institution's audit trail.
Usage limits
Each tool call consumes one credit against your monthly allowance: Starter 250, Plus 2,500, Enterprise 25,000. You'll see a notice as you approach your limit. Service is not interrupted if you exceed it — Starter accounts are prompted to upgrade, Plus and Enterprise continue with overage.
Troubleshooting
| Symptom | What to do |
|---|---|
| "Not enabled" when you run a query | Your institution's MCP plan tier isn't set. Ask a Cotribute administrator to enable it in Settings. |
| Connector appears but returns no tools | Start a new conversation — Claude only picks up newly added connectors in a fresh thread. |
| Queries return zeros or fewer flows than expected | Results are scoped to the flows your role can access. Ask an administrator to review your flow permissions. |
| Asked for an applicant's name or email and got a refusal | Expected. This version is aggregate-only; use the Cotribute portal for applicant-level detail. |
| Sign-in fails or loops | Confirm you're using your Cotribute staff email with email login enabled, then contact support. |
Support — help@cotributemail.com
Frequently asked questions
RiskCan an AI assistant change or delete data through MCP Connect?
No. MCP Connect v1.0 is read-only by architecture. Assistants can query and summarize origination data; there is no write path — no creating, modifying, or deleting records through the connector.
ComplianceWhat audit trail do we get?
Every query is logged to your institution's audit trail — who asked, what was asked, which tools were called, and what was returned. The log doubles as evidence of governed AI use for examiners and internal audit.
ComplianceDoes MCP Connect fall under SR 11-7 model risk management?
v1.0 retrieves and summarizes data; it does not score applicants, make credit decisions, or feed a decisioning model. That places it outside typical SR 11-7 model scope, and we supply documentation so your model risk management team can make and record that determination themselves.
ITHow does access control work?
Role-scoped access using your existing Cotribute staff account and flow permissions, over OAuth 2.0. Each employee's AI assistant can only reach the flows their role allows, and no applicant personal information leaves Cotribute — this version returns aggregate figures only.
ITHow long does setup take?
About 15 minutes per client. Connect an approved AI assistant — Claude, ChatGPT, or Copilot — sign in with your Cotribute staff account over OAuth 2.0, and governed access is live. No custom development.
CFOWhat does it cost?
Starter is included at $0 with AI Growth Agents. Plus is $9,600 per year standalone. Enterprise is custom for multi-entity or advanced requirements. Pricing is public — no call required to see it.
Give your team governed AI access
Review pricing, or talk through rollout with our team.
