README.md/case studies/c2 ameritas voice
Case study 02 / Agents Automation
A voice agent that resets passwords, through an MCP tool gateway
A Python/Flask backend sits behind a VAPI voice agent and exposes Active Directory and Mainframe actions as MCP tools, with least privilege and PII kept server-side.
At a glancec2 / ameritas
- Role
- [CONFIRM: role on this project]
- Client
- Ameritas
- Context
- [CONFIRM: internship or team context]
- Dates
- [CONFIRM: dates for this project]
- Status
- [CONFIRM: production status]
- Stack
- Python, Flask, VAPI, MCP (JSON-RPC 2.0), Active Directory, Mainframe
- Tested with
- [CONFIRM: how it was tested]
On this page
01Problem
Monthly password resets and account lookups were handled by hand, call after call, against Active Directory and the Mainframe.
The goal was a voice agent that does this work itself, without handing it broad access to either system.
02Constraints
- The actions touch Active Directory and the Mainframe, so each tool gets least privilege.
- PII stays server-side: the voice agent never holds it.
- The agent is a VAPI voice agent, so the backend has to expose its actions as tools the agent can call.
03Approach
Three layers, each with one job.
- Front door. A VAPI voice agent takes the call.
- Backend. A Python/Flask service runs the logic server-side.
- Gateway. Password resets and account lookups against Active Directory and the Mainframe are exposed as MCP tools over JSON-RPC 2.0, with least privilege.
04Decision
Expose the actions as MCP tools over JSON-RPC 2.0, with least privilege. The agent gets a short list of narrow tools instead of access to Active Directory or the Mainframe, and PII stays server-side.
[CONFIRM: what else was considered and why it was not taken]
[CONFIRM: what else was considered and why it was not taken]
Actions exposed as MCP tools over JSON-RPC 2.0 with least privilege; PII stays server-side.
05Evaluation
Placeholder[CONFIRM: how the agent and tools were tested, and what the checks covered.]
06Result
Monthly password resets and account lookups now run through the voice agent instead of by hand.
07What I'd do next
- Test every tool on its own. Each MCP tool has one narrow job, so each can carry its own checks before the agent ever calls it.
- Trace every call. The way I trace multi-agent runs with LangSmith at UNL ADMA, so a bad outcome points to the step that caused it.
- Audit the privilege. Re-check on a schedule that each tool still has only the access it needs.