Leave, attendance, people and policy — the whole of it behind one MCP endpoint. Your team asks their assistant. The assistant does the arithmetic, checks the policy, and writes the record.
Most HR software is a filing cabinet with a person scattered across nine drawers. This has one record for a person — and everything, every day worked, every day off, every balance movement, every promotion, hangs off it and reads back in one call. Teams nest above them, so “everyone in Engineering” means Platform and Storage too.
A team, department or division — and teams sit inside teams.
department follows their team's name automaticallyThe person, and the account they sign in with. There is no second user table to keep in step.
india, night-shift, senior — are how policies find their peopleOne row per kind of leave. The rules are a JSON document, because every company means something slightly different by them.
applies_to selects by tag, type, department or locationEvery movement in a balance, signed: opening, accrual, taken, adjustment, lapse, reversal.
One employee, one day, one row — with the punches kept inside it.
The days the company is closed, scoped the same way policies are.
Hired, confirmed, moved, promoted, paid differently, warned, reviewed, left.
Friday to Monday is two days, not four. A public holiday in the middle is free. Half a day is half a day. The day-by-day breakdown is stored on the request, so an argument about “that was only three days” is settled by reading it rather than by re-deriving it.
Not enough notice, no balance left, dates already booked, longer than the policy allows — you get all of it in one answer, each with the number behind it. And when a human has decided it is fine anyway, the refusal names the flag that overrides it.
Approving leave moves the ledger and marks the attendance days in one transaction. Cancelling posts a reversal and releases the days. A balance and a timesheet that disagree is the oldest bug in HR software; here it is not reachable.
Accrual looks at what each person should have been given by today, compares it with what their ledger already holds, and posts the difference. Run it nightly, run it twice, run it after a month of downtime — nobody gets double-credited.
An employee sees their own records. A manager sees their team’s. HR and admin see the organisation. Pay and personal details are redacted from everyone else — and it is the storage engine that enforces it, not each operation remembering to.
A department change is a transfer with a date on it. A salary revision is an event with the old figure and the new one. An attendance correction keeps what it corrected. Nothing has to be remembered into the record afterwards, because it was never not in it.
An agent that has to learn 216 endpoints learns none of them. It learns two, and asks the server about the rest at the moment it needs to know.
discover — learn the APITables, fields, allowed values, the filter language, every operation with its exact signature and a runnable example. Nine scopes, no guessing.
discover({ scope: 'operation', operation: 'leave.request' })
execute — do everythingAll CRUD, the whole leave loop, attendance, reports, onboarding, exits, access, mail. dry_run runs it and rolls back. idempotency_key makes a retry safe.
execute({ operation: 'employee.profile', params: { employee_id: '[email protected]' } })
Anywhere a person is wanted, a work email address or an employee code works as well as an id — because “approve Priya’s leave” is how the request actually arrives.
A short list is worth more than a long one that quietly includes everything.
Compensation is kept as a fact about a person, and every revision is an event in their record. There are no pay runs, no payslips and no statutory calculation — those are jurisdiction-shaped, and pretending otherwise would be worse than not doing it.
/mcp is the only door into the data. The web pages read through the same engine, with the same fences. There is no second surface to secure and no second set of rules to drift.
There is a records browser for the times you want to look at everything at once, and a page for managing access. Day to day, nobody opens either.
Every table, every filter, sorting, search, a date range, the columns you choose, inline editing, and CSV out. The counts on each filter are real — they say how many rows you would get if you picked it, given everything else already selected.
Statuses, departments, locations, policies, people and tags come down as options with counts behind them, so you never filter your way to an empty table by accident.
Every reference on the page is looked up and shown as the person or policy it stands for — one small query per table, not one per row.
The assistant sits next to the records rather than replacing them, pointed at this same server.
Real date and timestamptz columns, jsonb with GIN indexes on tags, and partial indexes that match the exact ordering a timeline is read in. The schema is generated from one file; there is no migration directory to keep in step.
Invitations, approval requests, decisions and password resets. If it is not configured, the operation says so and hands back the link rather than failing silently.
Policy questions answered from your actual policy records, year summaries built from real events, drafts you read before they are sent. With no key set, those operations say so and nothing else changes.
MCP clients register themselves and authorise with PKCE. Or mint an API key from your account page. Someone who leaves loses both, immediately.
Every row carries its organisation, and the filter is applied in the one path all data access goes through — so a query that forgets it is impossible rather than merely unlikely.
Deletes are soft and reversible, with the records that belong to a person going and coming back with them. Every row carries a version, so two edits racing cannot silently overwrite each other.
claude mcp add --transport http hr https://hrms.cleartrust.cc/mcp
Or add https://hrms.cleartrust.cc/mcp as an MCP server in any client that supports them — it will walk you through
signing in.