Four MCP surfaces
1. Builder Account MCP
Operates on the builder’s BuildWithHQ account and SaaS portfolio: account administration, app portfolio, resource state, deployments, catalog interactions, and other builder-authorized capabilities.
2. Developer VM MCP
Assists development inside the isolated developer environment using only approved tools/gateways. It can help edit/build/test code and interact with the controlled development surface without turning unrestricted internet or production secrets into default capabilities.
3. SaaS Application MCP
Builds/operates one SaaS application using that app’s authorized records, modules, workflows, APIs, AI, and management capabilities.
4. End-Customer MCP
Exposes only the tools/actions the end customer is permitted to use inside the SaaS. Tool discovery itself should be filtered so unauthorized capabilities are not advertised.
Product model
The builder may package customer-facing MCP access and skills as part of the SaaS offering. All four surfaces should reuse one capability/security/audit model rather than becoming four separate authorization systems.