mohannadibrahim.dev

README.md/case studies/c2 ameritas voice

Case study 02 / Agents Automation

A voice agent that resets passwords, through an MCP tool gateway

A Python/Flask backend sits behind a VAPI voice agent and exposes Active Directory and Mainframe actions as MCP tools, with least privilege and PII kept server-side.

At a glancec2 / ameritas

Role
[CONFIRM: role on this project]
Client
Ameritas
Context
[CONFIRM: internship or team context]
Dates
[CONFIRM: dates for this project]
Status
[CONFIRM: production status]
Result
28% less manual call handling
Stack
Python, Flask, VAPI, MCP (JSON-RPC 2.0), Active Directory, Mainframe
On this page
  1. Problem
  2. Constraints
  3. Approach
  4. Decision
  5. Evaluation
  6. Result
  7. What I'd do next

01Problem

Monthly password resets and account lookups were handled by hand, call after call, against Active Directory and the Mainframe.

The goal was a voice agent that does this work itself, without handing it broad access to either system.

02Constraints

  • The actions touch Active Directory and the Mainframe, so each tool gets least privilege.
  • PII stays server-side: the voice agent never holds it.
  • The agent is a VAPI voice agent, so the backend has to expose its actions as tools the agent can call.

03Approach

Three layers, each with one job.

  1. Front door. A VAPI voice agent takes the call.
  2. Backend. A Python/Flask service runs the logic server-side.
  3. Gateway. Password resets and account lookups against Active Directory and the Mainframe are exposed as MCP tools over JSON-RPC 2.0, with least privilege.
SERVER SIDE: PII STAYS HERE VOICE VAPI agent takes the call tool call BACKEND Python / Flask logic stays server-side JSON-RPC 2.0 MCP TOOLS Tool gateway least privilege SYSTEM Active Directory resets, lookups SYSTEM Mainframe account lookups VOICE VAPI agent takes the call tool call SERVER SIDE: PII STAYS HERE BACKEND Python / Flask JSON-RPC 2.0 MCP TOOLS Tool gateway least privilege SYSTEM Active Directory SYSTEM Mainframe
Fig. 1The voice agent never talks to the systems directly. Every action goes through an MCP tool in the Flask backend, and PII stays on the server side of the dashed boundary.

04Decision

Expose the actions as MCP tools over JSON-RPC 2.0, with least privilege. The agent gets a short list of narrow tools instead of access to Active Directory or the Mainframe, and PII stays server-side.

Alternatives considered
[CONFIRM: alternative 1]not taken

[CONFIRM: what else was considered and why it was not taken]

[CONFIRM: alternative 2]not taken

[CONFIRM: what else was considered and why it was not taken]

MCP tool gatewaychosen

Actions exposed as MCP tools over JSON-RPC 2.0 with least privilege; PII stays server-side.

05Evaluation

Placeholder[CONFIRM: how the agent and tools were tested, and what the checks covered.]

06Result

28%less manual call handling

Monthly password resets and account lookups now run through the voice agent instead of by hand.

07What I'd do next

  • Test every tool on its own. Each MCP tool has one narrow job, so each can carry its own checks before the agent ever calls it.
  • Trace every call. The way I trace multi-agent runs with LangSmith at UNL ADMA, so a bad outcome points to the step that caused it.
  • Audit the privilege. Re-check on a schedule that each tool still has only the access it needs.