Skip to content
Academy
Marketing Academy · Field Work●AI in Marketing
MiniBuild the Asset· 25 minutes

Spec Your First MCP Workflow, Read-Only

TAC Security (TAC Infosec)

Objective: Write a one-page MCP workflow spec for a single high-value reporting task, scoped to exactly the tools it needs and staying read-only, before any developer touches a config file.

You're the growth marketer at TAC Security (TAC Infosec), a cybersecurity SaaS company. Your team burns roughly 6 hours a week manually joining HubSpot lead data with Google Ads spend to report cost-per-qualified-lead.

Follow the lesson's own advice: pick one task, connect only the tools that task needs, and start read-only. Draft the spec a developer would actually implement.

Before you start

What you'll need

Free path (everything below is enough to finish)

Claude
FreemiumDraft the workflow spec and config skeleton

Free tier handles plain-language spec drafting without needing live MCP credentials

Google Sheets(optional)
FreeTrack the guardrail list and review checklist as a living, shareable doc

Free and easy to hand off to the developer who implements the config

The process

1 step

Step 01 of 01

Starting with a single read-only workflow before expanding access

The lesson's four workflow types run read-only analysis, read-and-recommend, semi-automated execution, and fully automated loops, in that order. Start at read-only and move right only as confidence in the workflow grows.

TAC Security's marketing team wastes about 6 hours a week manually joining HubSpot lead data with Google Ads spend to report cost-per-qualified-lead. Which workflow type should the first MCP spec target, and which two tools does it actually need connected?

Claude— Draft the spec directly in Claude as a plain-language brief, then a config skeleton

Procedure

  1. State the single task in one sentence: weekly cost-per-qualified-lead report
  2. List only the data sources that task needs: HubSpot (leads) and Google Ads (spend), not all 6 tools in the stack
  3. Classify the workflow type as read-only analysis
  4. Draft a guardrail list even though this is read-only, for example never surface individual contact PII in the report
  5. Write the review checklist a human runs before the report goes to leadership
Sample output
MCP WORKFLOW SPEC — Weekly CPQL Report (TAC Security)

Task: Calculate weekly cost-per-qualified-lead by channel
Tools connected: HubSpot MCP (read), Google Ads MCP (read)
Workflow type: Read-only analysis
Guardrails:
- Report aggregates by channel only, never surfaces individual contact PII
- No write actions enabled in this spec
Review checklist:
- Confirm lead-qualification criteria matches this week's definition before publishing
- Spot-check 2 rows against the raw CRM export

Healthy

The spec touches exactly 2 tools and stays entirely read-only for the pilot.

Unhealthy

The spec tries to connect all 6 stack tools and requests write access on day one.

What this means

A spec scoped to one task and two tools ships in a week; a spec scoped to the whole stack stalls in infrastructure planning, per Mistake 1.

So what do I do about it?

SymptomActionEffort
Draft spec lists every tool in the marketing stackCut the tool list to only what the one stated task requires5 min
EitherYou or a developer can handle this, depending on your access.

Final deliverable

A one-page MCP workflow spec (task, tools, workflow type, guardrails, review checklist) ready to hand to a developer for implementation.

See a reference example
Sample output
TBO Tek — MCP Workflow Spec: Weekly Supplier Campaign Pacing Report

Task: Flag supplier ad groups pacing over 90% of monthly budget by Wednesday
Tools connected: Google Ads MCP (read), internal supplier-dashboard MCP (read)
Workflow type: Read-only analysis
Guardrails:
- No budget changes; the AI surfaces a list only
- Report includes supplier ID and pacing percentage, no contact-level PII
Review checklist:
- Confirm pacing percentages against the Ads UI for 2 supplier accounts
- Verify all flagged ad groups are still active

Success criteria

You're done when you can:

  • Spec names exactly the tools the one stated task needs, not the full stack
  • Workflow type is correctly classified as read-only analysis
  • Guardrails and a human review checklist are both present even though no write access is requested