Spec Your First MCP Workflow, Read-Only
Objective: Write a one-page MCP workflow spec for a single high-value reporting task, scoped to exactly the tools it needs and staying read-only, before any developer touches a config file.
You're the growth marketer at TAC Security (TAC Infosec), a cybersecurity SaaS company. Your team burns roughly 6 hours a week manually joining HubSpot lead data with Google Ads spend to report cost-per-qualified-lead.
Follow the lesson's own advice: pick one task, connect only the tools that task needs, and start read-only. Draft the spec a developer would actually implement.
Before you start
What you'll need
Free path (everything below is enough to finish)
Free tier handles plain-language spec drafting without needing live MCP credentials
Free and easy to hand off to the developer who implements the config
The process
1 step
Step 01 of 01
The lesson's four workflow types run read-only analysis, read-and-recommend, semi-automated execution, and fully automated loops, in that order. Start at read-only and move right only as confidence in the workflow grows.
TAC Security's marketing team wastes about 6 hours a week manually joining HubSpot lead data with Google Ads spend to report cost-per-qualified-lead. Which workflow type should the first MCP spec target, and which two tools does it actually need connected?
Procedure
- State the single task in one sentence: weekly cost-per-qualified-lead report
- List only the data sources that task needs: HubSpot (leads) and Google Ads (spend), not all 6 tools in the stack
- Classify the workflow type as read-only analysis
- Draft a guardrail list even though this is read-only, for example never surface individual contact PII in the report
- Write the review checklist a human runs before the report goes to leadership
MCP WORKFLOW SPEC — Weekly CPQL Report (TAC Security) Task: Calculate weekly cost-per-qualified-lead by channel Tools connected: HubSpot MCP (read), Google Ads MCP (read) Workflow type: Read-only analysis Guardrails: - Report aggregates by channel only, never surfaces individual contact PII - No write actions enabled in this spec Review checklist: - Confirm lead-qualification criteria matches this week's definition before publishing - Spot-check 2 rows against the raw CRM export
Healthy
The spec touches exactly 2 tools and stays entirely read-only for the pilot.
Unhealthy
The spec tries to connect all 6 stack tools and requests write access on day one.
What this means
A spec scoped to one task and two tools ships in a week; a spec scoped to the whole stack stalls in infrastructure planning, per Mistake 1.
So what do I do about it?
| Symptom | Action | Effort |
|---|---|---|
| Draft spec lists every tool in the marketing stack | Cut the tool list to only what the one stated task requires | 5 min |
Final deliverable
A one-page MCP workflow spec (task, tools, workflow type, guardrails, review checklist) ready to hand to a developer for implementation.
See a reference example
TBO Tek — MCP Workflow Spec: Weekly Supplier Campaign Pacing Report Task: Flag supplier ad groups pacing over 90% of monthly budget by Wednesday Tools connected: Google Ads MCP (read), internal supplier-dashboard MCP (read) Workflow type: Read-only analysis Guardrails: - No budget changes; the AI surfaces a list only - Report includes supplier ID and pacing percentage, no contact-level PII Review checklist: - Confirm pacing percentages against the Ads UI for 2 supplier accounts - Verify all flagged ad groups are still active
Success criteria
You're done when you can:
- Spec names exactly the tools the one stated task needs, not the full stack
- Workflow type is correctly classified as read-only analysis
- Guardrails and a human review checklist are both present even though no write access is requested