Walter and MCP
A jobsite runs on a dozen systems. The connector between them shouldn’t be the thing that loses the citation.
The Model Context Protocol is becoming the common way for agents and the systems they work in to reach each other. Walter is built to sit on it in both directions — answering questions from the agents your team already uses, and reading the systems that speak it.
Where this stands. MCP support is on the roadmap and is not shipping yet. This page describes how we intend it to work and the rules it will inherit — not something you can connect to today. If you have a system you would want on the other end of it, that shapes what we build first.
Two directions
Walter on both ends of the connection.
The protocol is symmetric, and so is the plan. One direction opens the project record to the tools around it; the other lets Walter read those tools without inventing a new set of rules for what it finds there.
Walter as a server
Your project record, answerable by the agents you already use.
The Construction Brain becomes something your other tools can ask questions of — the RFI log, the deadline board, the current set, the unpaid-scope report — and every answer comes back carrying the same revision-pinned citations it would in Walter's own chat.
Walter as a client
One more way a fact can arrive, held to the same standard.
Where a system you run already speaks MCP, Walter can read it the way it reads an API, an inbox, or a portal — as a channel with recorded provenance, not as a shortcut that skips the checks the other channels go through.
What it inherits
A connector is where guarantees usually go to die. These four don’t.
Opening a system to other agents is normally the moment its permission model gets replaced by an API key that can see everything. These rules govern Walter today, and any connector we ship is built inside them rather than beside them.
A connection is a person, never a master key
Walter filters what it retrieves against the signed-in user's permissions before the model sees anything. A connected agent inherits exactly one person's view of the project — there is no service account that quietly sees every project and every margin.
The transport never upgrades the truth
How a fact reached Walter is recorded separately from what its source is worth. Arriving through a connector does not make a number more authoritative than the executed document it came from, and it does not make it less.
Nothing binding leaves through a tool call
Money commitments, contractual notices, regulatory filings, and lien waivers always stop at a person. That ceiling is enforced in code, not in a prompt, so it holds no matter which client is on the other end of the connection.
Citations survive the hop
Answers carry the exact drawing revision, spec section, or contract clause they rest on. If the record cannot support a claim, the answer is “not in the project record” — the same as it would be anywhere else in Walter.
What would you point at it?
We’re deciding what the first connection should reach for. If your team already runs agents against your project systems, the shape of that stack is the most useful thing you could tell us.