binky-control/workplans/BINKY-WP-0005-qonto-mcp-integration.md
tegwick 892c174b7a
Some checks failed
Work Records / validate (push) Has been cancelled
BINKY-WP-0005: OH/T05 runbook and lane-scaffold notes for Qonto MCP
Prepare first-pull path after DEC-2026-004: copy-paste founder provision,
CCR apply, catalog promote, and CostRunRate update steps. T05 still waits
on Red-lane API key provision.
2026-07-21 21:26:25 +02:00

3.9 KiB

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
BINKY-WP-0005 workplan Qonto MCP integration: bank account as agent-readable finance source infotech binky-control active codex the-custodian 2026-07-19 2026-07-21 6139db83-5d4b-4492-a77f-fc9550a0a4f9

Connect the company Qonto account to the agent infrastructure via the self-hosted qonto/qonto-mcp-server (API key + organization ID), read scopes first — payments/transfers are Red lane forever. Originates from AWQ-010 (founder direction 2026-07-18: "integrations like this should help with the automated company approach a lot" — arrange soon). Credential lane via ops-warden/OpenBao (tenants/binky/qonto), same custody pattern as company-email (integrations/company-email-openbao.md); no claude.ai native integrations — harness/MCP lane only. Main accounting stays DATEV Unternehmen Online (DUO): Qonto MCP complements, does not replace, the DUO/StB lane. The working MCP is a substantive argument FOR keeping Qonto despite plan cost (OH-2026-003).

Task: Qonto MCP capabilities and docs review

Review the Qonto MCP options (hosted mcp.qonto.com OAuth connector vs. self-hosted qonto/qonto-mcp-server with API key), tool surface (read vs. write), authentication shape, transports, and plan/API prerequisites. Recommend the variant compatible with the corporate access policy (harness/MCP lane, no native claude.ai connectors). Output lands in integrations/qonto-mcp.md. Green lane (docs only).

id: BINKY-WP-0005-T01
status: done
priority: high
state_hub_task_id: "e066a222-1608-45ce-96a7-cbf191a39a9b"

Task: Credential lane design — ops-warden/OpenBao custody

Design the OpenBao lane tenants/binky/qonto (fields QONTO_API_KEY, QONTO_ORGANIZATION_ID), warden catalog entry, and the founder Red-lane provision procedure — mirroring the company-email-imap pattern. Metadata and design only; no secret values, provisioning is founder Red lane. Green lane.

id: BINKY-WP-0005-T02
status: done
priority: high
state_hub_task_id: "261e4b34-24a2-4324-950d-881d78333b5d"

Task: Consumer design — rhythm sessions and CostRunRate feeds

Specify how rhythm/finance sessions consume the MCP: real balance and transaction pulls replace manual Qonto statement pulls; resolve the TBC rows in finance/CostRunRate.md (desk rent, Qonto plan cost); feed the OH-2026-003 cost-vs-usage answer. Read-only tool allow-list at harness level; write tools (cards, invoicing) stay disabled. Green lane.

id: BINKY-WP-0005-T03
status: done
priority: medium
state_hub_task_id: "6c4a475d-9db7-4488-8563-10c82fa78f51"

Task: DecisionQueue entry for Red-lane provisioning

Prepare the founder approval package: DEC entry covering API key creation in the Qonto dashboard, OpenBao provision, and the read-only boundary. Note the DUO complement (not replacement) and the OH-2026-003 tie-in (check API/plan prerequisites while in the dashboard). Green lane.

id: BINKY-WP-0005-T04
status: done
priority: medium
state_hub_task_id: "51364e7c-e842-4bcb-a0bb-6f4ceebe264b"

Task: First read-only pull and CostRunRate update

After founder provisioning: promote the warden catalog to active, run the first read-only balance/transaction pull through the harness lane, update finance/CostRunRate.md TBC rows (desk rent, Qonto plan) with verified figures, and log evidence metadata. Blue lane.

2026-07-21 prep (agent): CCR-2026-0008 + policy + agent-high-risk-boundary deny path (railiance-platform); ops-warden catalog binky-qonto-api draft + playbook; OH/T05 copy-paste runbook in integrations/qonto-mcp.md. Still blocked on founder Red-lane (OH-2026-003): API key + bao kv put, then CCR metadata apply + first pull.

id: BINKY-WP-0005-T05
status: wait
priority: medium
state_hub_task_id: "e4b2119b-6f89-44d8-879d-73bf225307f7"