iVendNextDevelopers Request a sandbox

A manager's AI assistant on our MCP server — the recipe

The till's price before and after the manager's yes

The manager asks for the 10% off AirPods promotion and says yes: the till's price drops by 10%, and the promotion reads Active in Desk.

This recipe lets a store or area manager ask an AI assistant "what sold in the Durban store yesterday?" — and, when the manager says so, "put the 10% off AirPods promotion on". It is for a retailer's IT person, a partner, or our own team. Reference implementation: samples/s10_ai_manager/ (two profiles of our MCP server, a scripted assistant standing in for the AI, the tests).

Three rules shape it.

When to use it. When a manager should read the shop's figures, and perhaps switch a promotion or change a price, by asking in plain words.

Steps

  1. Make the manager a key with only the rights they need. In the shop, give the manager's user a role that can read sales, closings, stock, profiles, items, prices and promotions, and — only if they may change them — write promotions and price rows. The profile cannot give more than the role has: a reader's key that says yes is refused by the shop. Generate the user's API key and secret in the usual way. ⚠ A price changed here skips any approval. If the shop runs price approvals (approvals), leave price rows out of the manager's write rights and out of the profile: an approval binds only the service that applies it.

  2. Pick the profile and start the server — outside the shop.

    • profile_read.json lets the assistant look: 6 tools, 3 record types, and no write exists in it.
    • profile_writes.json adds one write: switch a promotion on or off, or change a price-list row.

    The profile can only take away from the server. It names the tools (with the words the assistant reads for each) and the record types the general record tools may touch. For a write, it also names the one field of each type that may change ("Promotion Bonus Buys Master": ["active"], "Item Price": ["price_list_rate"]). A profile that offers the general record tools but names no record types is refused at start. The shop's permissions for the key still apply on top.

    IVN_BASE=https://shop.example python3 tools/mcp_server/server.py --http 127.0.0.1:8130 --profile samples/s10_ai_manager/profile_read.json
    IVN_BASE=https://shop.example python3 tools/mcp_server/server.py --http 127.0.0.1:8130 --profile samples/s10_ai_manager/profile_writes.json --writes
    

    An AI desktop app that starts its own tool servers gets the same command without --http, with IVN_BASE, IVN_KEY and IVN_SECRET in its environment (tools/mcp_server/README.md). Put HTTPS in front of the server before anyone else reaches it.

  3. Connect the assistant. It reads the profile's instructions and each tool's words. They tell it to add sales up in the shop, never to list them, and to show the preview and ask before any change. Any assistant that speaks the Model Context Protocol will do.

  4. Check it with the scripted assistant before a person uses it. samples/s10_ai_manager/assistant.py plays the manager's sentences with fixed rules, so you can test the whole path with no AI account. Run the laptop tests (python3 -m unittest discover -s samples/s10_ai_manager/tests), then try it against a staging shop.

How a write is guarded

  1. On a read-only server the write tool is not even listed, and a write call to one is refused.

  2. The first call has no confirm: nothing is sent. The server returns a preview of the exact change (method, address, body). The assistant shows the manager that preview in words and asks.

  3. Only after a yes does the assistant call again with confirm: true. The shop then checks the manager's rights. One confirmed write is one line on the audit log, with a fingerprint of the manager's key (first four characters and a hash — never the key, the secret, a record's name or any value).

    What the manager sees, and what the till then does. The conversation itself is text (see the sample's README). On the till, the same basket before and after the yes, then the promotion in Desk:

    the till before

    Before: the AirPods at full price on the till.

    the same basket after the yes

    After the yes: the same AirPods 10% lower, the promotion marked on the line.

    the promotion on, in Desk

    The promotion, Active, in Desk.

  4. ⚠ The server cannot see a person. confirm is the assistant's promise that the manager said yes. Use an assistant that asks before it calls a tool marked as changing things, and read the audit log.

What the manager can ask (the scripted assistant's sentences)

What sold in the Durban store yesterday? · Show me the closing for the Durban store on 2026-10-03 · How many CABLE-USBC-1M are in the Durban store? · Put the 10% off AirPods promotion on / Take the 10% off AirPods promotion off · Change the price of PP-MGR-ITEM to 120.

A real assistant understands far more; these are the ones the tests pin. It does not guess: two promotions that fit, or two stores called the same, are named back to the manager and nothing is changed.

⚠ Privacy. The profile fences the general record tools: which record types, and which fields of a write. The named read tools (sales, stock, profiles, items) return any field the manager's key may read. So a customer's name or phone on a sale reaches the AI provider if the assistant asks for it. The server does not fence read fields. Narrow it in the shop (the role: no right on the customer fields), or tell the assistant, in the profile's words, which fields to ask for.

What is refused, and why

Technical notes

Proven on our test bench.

Notes moved from the steps

What was proven where

This page in the kit