claims.searchadaptix-billingSearch active claims with live risk scoring, tenant-scoped.
DEVELOPERS · MCP TOOL BROKER
The Adaptix MCP Tool Broker exposes typed operational intents behind server-side authorization. The model gets the tools the verified caller may use, writes remain approval-gated, PHI stays classified, and an unavailable downstream adapter returns a typed failure instead of fabricated data.
tools/list -> verify caller -> resolve policy -> filter catalog tools/call -> validate schema -> enforce PHI class -> resolve policy -> adapter | typed failureUnknown or unavailable is a real state. It is never rewritten as success.
THE SHORT ANSWERS FIRST
Typed domain tools over the operational platform — claims, charts, credentials, scheduling, documents, analytics, and audit — exposed through the Adaptix MCP Tool Broker rather than raw database or UI automation.
4 read tools are wired to live adapters today. Every other registered read returns a typed MCP_TARGET_UNAVAILABLE until its adapter ships — the manifest below marks each tool's real state, and nothing unavailable is marketed as available.
Server-side. Caller identity is verified outside the prompt, policy resolution decides tool visibility and execution per caller, and unknown or failed policy resolves to denial.
The broker is an MCP server in front of the platform's own authorized service APIs. It adds no privileges: a tool call succeeds only where the same caller's API request would.
Reads dominate the catalog (20 tools). The 5 write contracts are prepare/submit pairs: preparing returns a pending-approval id and changes nothing downstream.
Every write execution. A prepared claim correction, message, or statement becomes real only after human approval — model intent alone never executes.
The tool manifest and connection model on this page are the current public reference. A hosted docs portal is not published yet — for integration access and a working walkthrough, talk to us directly.
THE BOUNDARY MATTERS MORE THAN THE CHAT WINDOW
The broker does not accept prompt-supplied identity as authorization. Tool visibility and execution are resolved against verified caller context.
Policy timeout, DNS failure, malformed policy response, or unavailable authorization resolves closed rather than manufacturing access.
Write execution is disabled by default and the write contracts are approval-gated. Prepared actions do not become executed actions merely because a model requested them.
Tools that can traverse PHI are marked explicitly so the broker can enforce the caller's permitted data class before the downstream request is attempted.
TOOL MANIFEST · TYPED CONTRACTS
MCP_TARGET_UNAVAILABLE until their target adapter is actually available.claims.searchadaptix-billingSearch active claims with live risk scoring, tenant-scoped.
claims.getadaptix-billingFetch a single claim's live risk profile by claim id.
claims.get_statusadaptix-billingReturn the current payer claim-status observation for a claim.
claims.get_submission_historyadaptix-billingReturn the submission history for a claim (837 lifecycle).
claims.get_denial_historyadaptix-billingReturn denial history and CARC/RARC codes for a claim.
eligibility.get_resultadaptix-billingReturn the latest 270/271 eligibility result for a patient.
era.get_reconciliation_statusadaptix-billingReturn ERA/835 remittance reconciliation status for a batch or deposit.
billing.get_summaryadaptix-billingReturn the tenant billing summary for AR, aging, and KPIs.
billing.get_exception_summaryadaptix-billingReturn the tenant billing exception summary for queues, blockers, and aging.
epcr.get_chart_statusadaptix-epcrReturn the current state of a specific chart.
epcr.get_completion_gapsadaptix-epcrReturn field-level completion gaps blocking chart lock.
epcr.get_quality_findingsadaptix-epcrReturn NEMSIS quality-validation findings attached to a chart.
credentials.get_statusadaptix-workforceReturn the current credential status for a user.
credentials.get_expiringadaptix-workforceReturn credentials expiring inside the requested window.
scheduling.get_user_scheduleadaptix-workforceReturn the caller's upcoming tenant-scoped schedule.
scheduling.get_open_shiftsadaptix-workforceReturn open shifts the caller is credentialed and eligible to claim.
documents.get_statusadaptix-billingReturn delivery status of a generated document.
documents.search_authorizedadaptix-billingSearch documents the caller is authorized to see.
analytics.get_operational_summaryadaptix-coreReturn the operational summary for the tenant.
audit.search_authorized_activityadaptix-coreSearch authorized audit activity for the tenant.
claims.prepare_correctionadaptix-billingDraft a claim correction and return a pending-approval id; does not submit.
claims.submit_correctionadaptix-billingSubmit a previously prepared claim correction after human approval.
communications.prepare_messageadaptix-communicationsDraft an outbound message and return a pending-approval id; does not send.
communications.send_approved_messageadaptix-communicationsSend a previously prepared, human-approved message.
documents.prepare_statementadaptix-billingPrepare a patient statement or billing document; does not deliver it.
CONNECTION MODEL
Caller identity originates outside the prompt.
Validates tool schema and caller context.
Server-side authorization decides visibility and execution.
Only the authorized target receives the request.
Success, denied, PHI-not-permitted, policy-unavailable, or target-unavailable remains explicit.
POLICY RESOLUTION
POST /api/v1/ai/policy/resolve/toolALLOW -> tool remains visible / executable DENY -> request stops POLICY_UNAVAILABLE -> request stops PHI_NOT_PERMITTED -> request stops MCP_TARGET_UNAVAILABLE -> typed downstream failure
BUILD AGAINST THE CONTRACT THAT EXISTS