Connecting external AI clients over MCP
How an AI client such as Claude Desktop or Claude Code can read your HaloPSA tickets, usage analytics, documentation and support memory through QuantumOps, and how its requests to change tickets wait for an Administrator's approval.
Written By Chris Scaminaci
Last updated About 2 hours ago
QuantumOps can act as a set of MCP servers. MCP, the Model Context Protocol, is the standard way an AI client such as Claude Desktop or Claude Code connects to outside tools and data. Once a client is connected, a person can ask it about your tickets, AI usage, documentation or support memory in plain language. This page is for Administrators who are deciding whether to allow that.
This is available on request from TechPulse. It is not self-service: no QuantumOps screen creates the access token a client needs. TechPulse supplies the token procedure and the server addresses for your instance.
Before you start: your organisation's HaloPSA connection must be set up, because the HaloPSA server reads through it. The other servers have their own conditions, listed under "What each server needs" below.
What each server offers
QuantumOps offers four servers. A client shows each one under the title given here, and it sees only the tools of the server it connected to.
QuantumOps HaloPSA
- Look up a Halo ticket returns one ticket with its status, summary, client, agent and actions.
- Ticket action history returns the notes, replies and status changes of a ticket.
- Search Halo tickets finds tickets by keywords, optionally by status and date range.
- Tickets for a client lists the tickets of one client.
- Request a ticket note and Request a ticket update ask QuantumOps to change a ticket. They never change it directly; see "Approve a change an AI client asked for".
- Approval request status reports what became of one of those requests.
QuantumOps Analytics
Read-only reporting for a date range (the last 30 days unless the client asks for another, up to a year):
- AI usage summary, Daily usage trend and Cost by function and day show tokens, calls and recorded cost.
- Model fallbacks and AI latency show where a different model answered and how fast calls were.
- Chat quality summary and Tool usage in chat show how Qubit chat is used across the extension, the web app, Slack and Teams.
- Triage quality shows how triage is performing for the date range. Recent Agent Runner runs lists the latest runs of your Agent Runners instead: 20 unless the client asks for more, up to 200.
These are the same kinds of figures you see in AI Usage Analytics.
QuantumOps Documentation
Read-only access to the documentation your organisation synced from IT Glue, Hudu and SharePoint:
- Search documentation finds documents by meaning, optionally limited to one client and to some of those sources.
- Read a document returns the cleaned text of one document that a search found.
- List documentation sources shows which sources are synced and whether search is available.
QuantumOps Support Memory Graph
Access to support memory, also called the memory graph:
- Search support memory, Entity context card, Entity timeline, Find past resolutions, Traverse the graph and Memory graph schema read facts and past resolutions.
- Remember a fact records a statement that a person asserts. By default only Administrators can use it, and it takes effect straight away.
- Forget a fact retires a fact or resolution so it is no longer used. It needs the Administrator role and an explicit confirmation from the client, and the entry is kept as history rather than deleted.
Both of these tools are switched off while support memory is off for your organisation.
How access works
The client sends an access token with every request. The token belongs to one user of your organisation, and the client acts as that user with that user's roles. A token that does not belong to your organisation is refused.
- HaloPSA lookups and searches use your organisation's stored HaloPSA connection, not the user's own HaloPSA permissions. A client can therefore read whatever that connection can read.
- Analytics tools need the Administrator role, because usage data covers the whole organisation.
- When a server cannot do something, it tells the client why in plain words.
Approve a change an AI client asked for
A client can never change a HaloPSA ticket directly. When it asks for a note or an update, QuantumOps queues the request and returns a reference to the client; nothing changes in HaloPSA until an Administrator decides.
- The client sends the request. It can add a reason, which the approver sees.
- In the browser extension, open More, then the Approvals tab. See Approvals tab.
- Read who asked, the reason, the exact arguments and when the request expires. For a note, check whether it is hidden from the end user.
- Select Approve to let it run, or Deny to refuse it.
When you approve a note, QuantumOps posts it through your HaloPSA connection with a closing line that names who asked and who approved. The note is internal unless the client asked for it to be visible to the end user. A visible note shows that closing line to the end user too, including who asked, which is normally an e-mail address.
When you approve an update, QuantumOps applies the fields and adds a hidden note to the ticket that lists the changes, who asked and who approved. An update request can change exactly these fields: status, assigned agent, priority, category, team, ticket type and custom fields. A request that names anything else is refused as a whole and nothing is applied.
The client can ask Approval request status at any time. The status is one of Pending, Approved, Denied, Expired or Consumed. Consumed means the request was approved and carried out, and the answer includes what happened, or why it failed.
To switch these requests off entirely, add a rule in Tool Governance: choose New Policy, set Surface to Copilot and Effect to Deny, and enter halo_request_* as the Tool pattern. That one pattern covers both request tools. The client is then told that nothing was changed. An Allow rule does not skip the approval. Requests from external clients also appear in the Tool Governance audit list. This Copilot is the Tool Governance surface for outside AI clients, not the Copilot card on the Ticket Dashboard.
What each server needs
Keep the token safe
Treat a token like a password, because the client acts as the person it belongs to.
- Do not paste a token into a shared chat, a ticket or a screenshot.
- Never give a client your HaloPSA keys. The servers use the connection your organisation already stored.
- Prefer a token for a user with only the roles the client needs. A token for an Administrator can read the analytics and record or forget support memory.
- Ask TechPulse how to renew a token and how to stop one that has leaked.
Ask TechPulse for access
Write to TechPulse at support@techpulsecloud.com. Say which AI client you want to connect, which user it should act as and which of the four servers you need. TechPulse supplies the token procedure and the server addresses for your instance.
Related pages
- Approvals tab: where an Administrator approves or denies a request.
- Tool Governance: the rules and the audit list for tool calls.
- Documentation Hub: the documentation the documentation server searches.
- Support memory: what the memory server reads.
- AI Usage Analytics: the figures behind the analytics server.
Was this helpful?
Still need help? Ask the team