---
title: "Why our AI connector will never show you another franchisee's numbers"
description: "We let our team ask every Sneeze It tool a question from inside Claude or ChatGPT. Before we built the door, we wrote down who may never walk through it, and what may never come back out."
section: Inside Sneeze It
author: David Steel
published: 2026-10-10T20:15:33.567Z
url: https://one.sneeze.it/blog/why-our-mcp-never-shows-another-franchisees-numbers
tags: ["inside-sneeze-it", "mcp", "ai-safety", "franchise-data", "privacy"]
---

# Why our AI connector will never show you another franchisee's numbers

_We let our team ask every Sneeze It tool a question from inside Claude or ChatGPT. Before we built the door, we wrote down who may never walk through it, and what may never come back out._

A franchise system is a group of businesses that share a brand and very little else. Each owner has their own lease, their own payroll and their own ad results. They compare notes at the annual conference, but nobody wants their cost per lead read out loud to the owner two towns over.

That is the problem with plugging AI into marketing data. The assistant is happy to answer any question it can reach. If it can reach everything, it will eventually answer the wrong person. So when we built one connector that lets our team ask every Sneeze It tool a question from inside the chat they already use, we started with the rules about what it must refuse, and only then wrote the parts that answer.

The connector is called the Sneeze It MCP. MCP, the Model Context Protocol, is the open standard that lets AI assistants call outside tools. You add one address to Claude, ChatGPT or Claude Code, sign in with your Sneeze It account, and the assistant can ask our products real questions: which ads are waiting on approval, how crowded a 15-minute drive around an address is for a gym. It is [live at mcp.sneeze.it](https://mcp.sneeze.it), for the Sneeze It team only today.

:::stats
about 70 | tools a fully permissioned staff member can reach
13 | tools that cost money, each behind a hard monthly cap
3 | assistants supported out of the box: Claude, ChatGPT, Claude Code
source: Sneeze It MCP code, counted October 10, 2026
:::

## One door, three questions

The connector holds no client data of its own. It is a doorway. Every question passes three checks, two on the way in and one on the way out, and the answer comes from the product that owns it: Studio for ads, Audience for markets, the Hub for locations, Coach for weekly performance readings, and the Brain for lessons.

:::flow "How a question gets answered"
You ask | In Claude or ChatGPT, in plain words
Who are you? | Your Sneeze It account decides which tools you get
Which records are yours? | No scope means no data tools at all
The product answers | Studio, Audience, Hub, Coach or Brain
Which fields may leave? | Everything not on the approved list is removed
:::

The first check is about tools. Someone with view-only access to a product gets tools that read. An editor also gets tools that create drafts. Change a person's access on our People page and their tools change within about a minute. Of the built-in tools, 35 only read and 21 create or change something.

The second check is about records, and it is the one this post is named for.

## Default deny, at the level of the record

Most software asks "is this person allowed into this app?" That is not good enough for a franchise system. A franchisee is allowed into the app. The real question is which rows inside it belong to them.

So every person has a scope: whose records they may see. For verified Sneeze It staff, that can be the whole book. For anyone else it is designed to be named brands, named locations or named clients, and nothing more. The rule we wrote first is the simplest one: **no scope means no data tools at all**. Not a blank screen, not an error after the fact. The tools are not offered.

When a person with one client asks about another client's ads, the request is refused before anything is fetched. The other client's data never travels to the connector, so it cannot leak out of it.

:::pullquote
No scope means no data tools at all. The safe answer is the default, and every exception has to be written down.
:::

That is why the door is staff only today. We built it so franchisors and owners could one day ask their own questions from their own assistant. We are not opening it to anyone outside Sneeze It until record-level scoping has been proven in use. A franchise system should expect that order from anyone who plugs AI into its data: prove the walls, then open the door.

:::figure wide
![A franchise office at night with a row of locked filing drawers, one per location; a single drawer glows magenta and stands open while the rest stay shut.](/blog/media/7fd3f98339e61e05e8b7f1ad.jpg)
Each person reaches their own drawer. The others are not locked after the fact; they are never opened.
:::

## The numbers our AI is never allowed to say

The last gate is a filter, and it applies to everyone, staff included.

Every tool lists the exact fields allowed to leave it: an ad's headline, copy, status and image, for example. Everything else is removed before the assistant ever sees the answer. There are no wildcards. If a product adds a new field tomorrow, that field stays hidden until a person adds it to the list on purpose.

This is how we keep internal numbers internal. Markup, true spend, cost and margin are never sent through the connector, to anyone. Our own team cannot pull them into a chat window by accident, which means they cannot paste them into a client email by accident either.

:::compare "Pasting data into a chatbot" "Asking through our connector"
Whatever you paste goes in, for whoever you are. A spreadsheet with forty locations is forty locations, including the ones the reader should not see. Internal columns ride along unless someone remembers to delete them.
---
The assistant signs in as you. It reaches only your records. Each answer is trimmed to approved fields, so markup, spend, cost and margin never arrive. Every request is logged.
:::

## Drafts, caps and a log

Two more rules shape what the AI can do, not just what it can see.

**Nothing spends money uncapped.** No tool may start a paid job on its own. Thirteen tools cost money, such as generating an image or pulling ads from Meta's public Ad Library, and each is allowed only because the product behind it holds a hard monthly cap. None of them are available at view level.

**Nothing reaches a client without a person.** When the AI makes an ad, an email, a landing page or a video, it lands as a draft. A person approves it before a client sees it. A lesson someone teaches Studio through the connector can change how it writes for a client, but it can never add an offer, a price or a review.

Every tool call is logged: who asked, which tool, what it looked up, and whether it was allowed. The log is how we learn which tools earn their place. It does not see the conversation. We see the tool calls the assistant decides to make, never what you typed around them.

## Why build this at all

Our team already lives in Claude and ChatGPT. Without a connector, the honest workflow is copy and paste, and copy and paste has no walls. We would rather give people a door that knows who they are than ask them to remember the rules every time.

It also changed how fast we can move. Products publish their own tool lists, so when the Hub and Coach joined they brought their tools with them and the connector itself did not change. We went from the first commit on September 24 to Brain tools on October 5, 23 commits in about two weeks, and every rule in this post is enforced in code and covered by tests. If you want to see how the products behind it fit together, start with [the overview of every Sneeze It tool](/blog/inside-one-an-agency-that-runs-on-its-own-software). For the same discipline applied to reporting, read [an AI that cannot invent a number](/blog/an-ai-that-cannot-invent-a-number).

:::takeaways "What this means if you run 20 locations"
- Ask any agency that uses AI on your data one question: can it show one owner another owner's numbers? The right answer is "no, and it is enforced per record," not "we are careful."
- Insist on default deny. A person with no assigned locations should get nothing, not everything.
- Internal numbers should be filtered by an allowlist, so a new field stays hidden until someone chooses to show it.
- AI that can spend money should only do it behind a hard cap, and AI that writes for your brand should only make drafts.
- Our connector is staff only today. We will open it to clients when record-level scoping is proven, not before.
:::

:::cta button="See the MCP" href="https://mcp.sneeze.it"
See what your assistant can and cannot see.
The public page walks through it with sample data only.
:::
