sh-mcp/README.md

41 lines
1.9 KiB
Markdown
Raw Normal View History

# sh-mcp
Sea Haven MCP platform. A TypeScript monorepo of trust-tiered **MCP servers** that expose
Sea Haven's proprietary integrations as tools, plus the **Cognito/Google auth broker** and the
**rebuilt scheduled jobs**. This service replaces `seahaven-slack-bot` and `exec-aide`, which are
deprecated completely; the conversational surface becomes a configurable Slack task agent.
> **Status: DESIGN / PLANNING. Not built. No stack deployed.**
> The full design, auth architecture, scope matrix, and build plan live in
> [`docs/design.md`](docs/design.md). Read it before writing any code.
## Shape (planned)
- **MCP servers** (trust-tiered, remote HTTP, per-server IAM):
- `sh-mcp-ops` — read-mostly, agent-facing (WO/PO/site lookups, KB search, Google Maps,
Gmail/Calendar, tasks, reminders).
- `sh-mcp-finance` — sensitive, read-only, audited (QBO vendor search, payment lookups).
- `sh-mcp-physical` — DEFERRED, admin/out-of-band only (Lenel/Yealink/3CX control).
- **Auth** — Google Workspace is the single IdP; an Amazon Cognito user pool federated to Google
issues scoped, audience-bound JWTs; group → scope mapping via a pre-token Lambda. See design §2.
- **Jobs** — rebuilt proactive Lambdas (email classify/digest, KB syncs).
- **Language** — TypeScript everywhere (servers, packages, CDK, jobs).
## Open decisions
- Task-agent surface: Agentforce (recommended) vs marketplace Claude app vs custom Bolt assistant
(design §12). Drives the model + guardrail story.
- Endpoint exposure specifics (Slack egress ranges / WAF) — design §9 / §11.
## Layout (target)
```
packages/ shared + one package per integration
servers/ sh-mcp-ops, sh-mcp-finance (CDK stacks)
auth/ cognito, pre-token-lambda, group-sync-lambda
jobs/ rebuilt scheduled Lambdas
docs/ design.md (the canonical plan)
```
See [`docs/design.md`](docs/design.md) for the authoritative spec.