Enterprise HRMS AI Assistant with Model Context Protocol (MCP)
Enterprise HRMS assistant built on Claude and MCP with strict RBAC isolation
Architected and built an enterprise AI assistant embedded into a Human Resource Management System using the Model Context Protocol (MCP). Implemented multi-layered role-based access control (RBAC), dynamic tool schema filtering based on user JWTs, PostgreSQL Row-Level Security, and immutable audit logging across payroll, leave, and hiring workflows.
Engineering team structure and leadership.
How the engineering organization was structured, staffed across disciplines, and directed through delivery.
Overall technical leadership, custom Python orchestration, and MCP security boundary design
Claude 3.5 prompt engineering, MCP tool servers (Leave, Directory, Reviews, Hiring), evaluation suites
PostgreSQL Row-Level Security, enterprise SSO JWT integration, and SQL audit logging
Provided hands-on technical leadership over 5 engineers while personally writing core backend orchestrators and MCP server code
Architected the Model Context Protocol (MCP) server cluster spanning Leave, Payroll, Org Directory, Reviews, Policy, and Hiring
Engineered the security architecture that dynamically filters tool schemas based on user JWT claims before sending context to Claude
Implemented PostgreSQL Row-Level Security (RLS) guaranteeing cryptographic data isolation across organizational tiers
Built a comprehensive database audit pipeline logging 100% of LLM tool calls, arguments, user identities, and execution statuses
Measured operational outcomes.
Concrete reliability benchmarks and performance metrics delivered to production.
Permission Enforcement
Audit Coverage
Tool Ecosystem
Security Model
Architectural decisions & implementation.
Target Architecture & Implementation
How the system was designed, structured, and deployed
Designed a multi-tier defense architecture using Model Context Protocol (MCP). When an employee authenticates, their verified JWT role dynamically filters which MCP tool schemas are presented to Claude—ensuring the model cannot even attempt to call unprivileged functions. At execution time, MCP servers validate user identity and permissions, while PostgreSQL Row-Level Security (RLS) restricts database queries strictly to the requester's authorized records. Every tool invocation, parameter, and timestamp is permanently recorded to an immutable audit table.
System Component & Infrastructure Ledger
Detailed breakdown of runtime dependencies, protocols, and architectural roles
Reasoning and tool orchestration
Decoupled, auditable business logic
Deterministic state and fallback handling
Row-Level Security (RLS) enforcing tenant and employee record isolation
Session caching, token budgeting, and conversational context storage
Corporate Single Sign-On (SSO)
Individual network isolation
Regulatory compliance and access tracking
"The MCP architecture gave our security review team the confidence to approve an AI assistant in HRMS. The permission boundaries are mathematically enforced, not just prompted."
Enterprise Human Resource Management Platform