MCP Hub
Back to servers

HR MCP Server

An HR management server that provides access to employee directory information, sensitive PII, and salary data through a scope-based authorization system. It enables users to view, search, and update employee records and organizational charts using tools mapped to specific permission levels.

glama
Updated
Mar 24, 2026

HR MCP Server

An HR MCP Server built with FastMCP that exposes employee directory, profile, salary, and PII data through scope-based authorization.

Scopes

ScopeDescription
readerAccess non-PII employee data (name, department, job title, office, etc.)
writerUpdate employee records
restrictedAccess PII / sensitive data (salary, address, tax info, bank details, etc.)

Scope mapping to tools

ToolRequired Scopes
list_employeesreader
get_employee_profilereader
search_employee_directoryreader
get_org_chartreader
get_employee_piirestricted
get_employee_salaryrestricted
get_employee_full_recordrestricted
get_department_salary_summaryrestricted
update_employee_profilewriter
update_employee_salarywriter + restricted
update_employee_contactwriter + restricted
whoami(any authenticated user)

Setup

pip install fastmcp

Running

# STDIO mode (for MCP clients)
python server.py

# Or via FastMCP CLI
fastmcp run server.py

Mock Data

The server ships with 7 mock employees across departments (Engineering, Data Science, HR, Finance, Operations, Executive). All data is in-memory via hr_data.py.

Deploying to Azure Container Apps

Prerequisites

  • Azure CLI (az) installed and logged in
  • Docker installed
  • An existing Azure Container Registry (ACR)
  • An existing Container App Environment

1. Build and push the Docker image

.\build-and-push.ps1 -AcrName <your-acr-name>

This builds the image and pushes it as <your-acr-name>.azurecr.io/hr-mcp-server:latest.

2. Deploy the Container App

az deployment group create `
  --resource-group <your-rg> `
  --template-file infra/container-app.bicep `
  --parameters `
    environmentId="/subscriptions/<sub-id>/resourceGroups/<rg>/providers/Microsoft.App/managedEnvironments/<env-name>" `
    acrLoginServer="<your-acr-name>.azurecr.io" `
    appInsightsConnectionString="<optional-connection-string>"

The Bicep template (infra/container-app.bicep) creates a Container App with:

  • External ingress on port 8000
  • System-assigned managed identity for ACR pull
  • Application Insights telemetry (optional)

3. Grant ACR pull permissions

After deployment, assign the AcrPull role to the Container App's managed identity:

# Get the principal ID from the deployment output
$principalId = (az containerapp show --name hr-mcp-server --resource-group <your-rg> --query identity.principalId -o tsv)

az role assignment create `
  --assignee $principalId `
  --role AcrPull `
  --scope /subscriptions/<sub-id>/resourceGroups/<rg>/providers/Microsoft.ContainerRegistry/registries/<your-acr-name>

4. Restart the Container App

After the role assignment propagates, restart to pull the image with the managed identity:

az containerapp revision restart --name hr-mcp-server --resource-group <your-rg>

Reviews

No reviews yet

Sign in to write a review