Before Connecting AI to Odoo 20, Decide What It May Do
Imagine a warehouse manager asking an AI agent, “How much of this product is available, and are any units reserved?” The first question is whether the agent can read that information. The next question matters more: if the manager asks, “Create a sales order for this customer,” can the system create or change a record?
Odoo 20 documents an MCP server that lets an external AI agent read or modify data in an Odoo database by calling exposed tools. Odoo, AI MCP server Odoo announced Odoo 20 on September 24, 2026, in its “Meet Odoo 20” article. The MCP connection still requires a database owner to decide what is exposed; it should not be copied from a demo into production without that decision. Odoo, Meet Odoo 20
The question is not only which AI client to connect. The owner must decide which tools the client can see, who owns the API key, and how much permission that Odoo user needs.
How Odoo MCP reaches the database
In Odoo’s workflow, a user configures the client with server details and an authentication key. After a successful connection, the client requests the AI tools or Server Actions that have been exposed. The user then gives a plain-language instruction, the client asks the server to invoke a relevant tool, and the result comes back to the user. Odoo, AI MCP server
The documentation describes what the MCP server can do. It does not establish that every agent will interpret a prompt the same way, or that every tool will be available in every database. The system owner should test the actual client, Odoo version, installed modules, and configuration before use.
The key point is that the AI does not receive a separate, floating permission. Each request uses an API key to authenticate the identity and permissions of an Odoo user. That user’s permissions form the basic boundary for what the client can ask the server to do.
The decision is in the tools and the permissions
Once connected, an Odoo database exposes five basic tools to the client by default: AI Tool: Get Fields, AI Tool: Get Models, AI Tool: MCP Retrieve initial context, AI Tool: Search, and AI Tool: Read group. Odoo, AI MCP server
The remaining tools stay hidden until someone exposes them in Settings > Technical > Server Actions by selecting Available in MCP in the Usage tab. That is the point at which a team should inventory the possible actions. Exposing a tool expands the set of actions the client can see and may call.
Enersys recommends starting with work that reads information, such as checking stock or finding a sales-order status. Consider record creation and edits separately. Whoever exposes a tool should be able to answer which process it supports, which user needs it, and what evidence will reveal an incorrect result.
“Connected to MCP” does not mean “the AI can do everything in Odoo.” The real boundary depends on the exposed tools and the API-key user’s permissions. Those settings must be checked in each database.
Readonly is not a security wall
An Odoo Server Action form includes a Readonly Tool checkbox for a tool that the team considers not to write or modify existing data. Odoo says the checkbox advises the client that the tool can be invoked without explicit user approval.
The limitation is precise: Odoo also says that enabling Readonly Tool does not hide the tool from the AI client and does not act as a security rule that forces the tool to be read-only. Odoo, AI MCP server
A team should therefore not use the checkbox in place of code review or permission review. If a tool affects data or a business process, test it with the account that will actually be used, inspect the database result, and decide where the client must ask for approval. A client being allowed to invoke a tool automatically does not mean Odoo approves every agent action, or that the action is safe in every context.
A practical example before production use
The following is a hypothetical example. It does not describe Enersys’s current database configuration.
Suppose a warehouse team wants an AI agent to answer questions about available and reserved stock. The team could start with a dedicated Odoo user whose permissions cover only the relevant models and companies. It would expose the tools needed to find and read that data, then test that the agent sees the intended warehouse quantities but not purchase prices or another company’s records.
If the team later wants the agent to create or edit a sales order, that should be a separate decision. The team needs to define who can approve it, which customers are in scope, which fields cannot change, and how the created records will be reviewed. Exposing a create or edit tool does not follow from selecting Readonly, and using an administrator’s API key simply because it is convenient is a poor starting point.
The evidence from testing should be more than a screenshot showing a successful connection. Keep the prompts that could read data, the requests that were rejected, the data that was returned, the result of each create or edit, and the owner responsible when a result differs from the expected outcome.
A least-privilege rollout checklist
- Define the work before exposing a tool. State whether the agent will read, search, open a view, create, or edit something. Do not begin with the available tool list and then look for a use.
- Create a dedicated MCP user. Give the account only the permissions the work needs. Keep it separate from an administrator account and review company, warehouse, model, and field access.
- Give every exposed tool an owner. Record who approved it, why it is exposed, and how it will be disabled if the work ends or testing fails.
- Separate read from write. Begin with read tasks. Record creation or edits need their own test cases and accountable owner. Do not treat Readonly as an access-control mechanism.
- Treat the API key as the user’s credential. Odoo says a key can have a validity duration and is shown to the user only once when generated. Store it through a controlled method, not in a shared chat or broadly accessible file. Odoo, AI MCP server
- Test requests that should fail. Use the MCP account to search outside its scope, create a record without permission, edit a restricted field, and invoke a tool that has not been exposed. The result should reject the request or limit the data as designed.
- Plan a stop and review path. Decide how to disable a tool, revoke or replace a key, inspect records created or changed, and review the setup after a role change, module change, or client upgrade.
MCP can make Odoo data easier to reach through natural language. The rollout should start with a concrete question: “Which data may the agent touch, through which tool, under whose permissions?” Once the team can answer that and has evidence from a test database, it can decide whether to expand from reading into writing.