Docusign processes over a million documents daily across $2 trillion in agreement workflows. As of September 30, all of that infrastructure is agent-accessible over MCP - no custom adapter code required. If you have been waiting for a clear sign that the enterprise MCP server wave is real and not a prototype party, this is it.
What an enterprise MCP server actually is
An enterprise MCP server is a vendor-run endpoint that lets any AI agent call a business system's real operations - not just read its records. What separates this group from hobby projects is what the server is allowed to do: execute work inside the platform, under the platform's own permission model, on behalf of an agent the vendor did not build.
That last clause is the load-bearing part. The MCP registry has nearly 2,000 entries. Most of them give an agent read access to something. These three give an agent governed write access inside platforms that run actual business operations.
Salesforce, ServiceNow, and Docusign: what each one ships
Salesforce took hosted MCP servers generally available on April 29, 2026. ServiceNow shipped a Now Assist MCP server before expanding the surface with Action Fabric on May 5, 2026.
Docusign announced on September 4 that its MCP Server will be generally available globally on September 30, making agreement intelligence and governed action callable natively from Claude, ChatGPT, Gemini, Copilot, Slack, and any MCP client.
The three have meaningfully different scope:
| Vendor | GA date | What an agent can do | Permission model |
|---|---|---|---|
| Salesforce | April 29, 2026 | Query data, run Flows, call Apex actions | User OAuth token; agent inherits authenticating user's permissions |
| ServiceNow | May 5, 2026 | Execute flows, playbooks, approvals, catalogs | AI Control Tower: identity-verified, role-scoped, audited per action |
| Docusign | September 30, 2026 | Analyze, send, and track agreements via Iris | Account-level admin controls; global multi-region infrastructure |
A Salesforce hosted MCP server is a Salesforce-managed endpoint that exposes your org's logic and assets - data, flows, Apex actions, queries, and more - to any AI client that speaks MCP. Salesforce handles hosting, authentication, and permission enforcement automatically. The practical implication: MCP tools run with the same permissions as the user who authenticated with the External Client App. An agent can do exactly what that user could do - no more, no less.
ServiceNow takes a different cut. Other platforms let agents read and write data. ServiceNow enables agents to execute governed work: flows, playbooks, approvals, catalogs - the full system of action. Every action runs through ServiceNow AI Control Tower, so it's identity-verified, permission-scoped, and fully auditable.
The MCP Server Console includes governance, consumption metering, managed OAuth, enterprise audit trails, session management, and role-based tool packages.
Docusign's angle is narrower but deeper inside a specific workflow. MCP connects to tools like Claude, ChatGPT, Gemini, Copilot, Slack, and Salesforce, giving agents governed access to past negotiations, accepted terms, clauses, and company policies within Docusign's Intelligent Agreement Management and CLM workflows.
The composability argument, and where it gets tricky
The downstream effect is composability. A Docusign plus Salesforce MCP integration means an agent can pull deal terms from the CRM, generate the contract, route it for approval, and send the envelope - without any custom glue code between systems. That end-to-end workflow existed before MCP. Building it used to take weeks of integration work. Building it now takes a day.
That is the genuine win. But here is the part most coverage skips: Forrester predicted that 30% of enterprise app vendors would launch their own MCP servers during 2026. The interesting part is not the count - it is that the hard problem has moved from integration to authorization.
Composability is only as safe as the weakest permission boundary in the chain. When your agent spans Salesforce, Docusign, and ServiceNow in a single workflow, the blast radius of a misconfigured token or a prompt injection event spans all three. The MCP spec's 2026-07-28 revision tightened OAuth alignment, but as a general rule, it's preferable to only expose a limited set of "safe" operations to agents via MCP rather than to allow full API access.
The non-obvious risk here is not that these servers are insecure - they all enforce user-level permissions - it is that the identity doing the authenticating matters enormously. If a shared service account owns the OAuth session, the agent inherits that account's access across every tool it calls. In a multi-system workflow, that surface is much wider than any single API integration used to be.
What teams should actually do before September 30
If your team uses Salesforce, ServiceNow, or Docusign and you are starting to wire up agents, the immediate practical steps are:
Audit which accounts will own MCP OAuth sessions. Shared service accounts are a risk; per-user tokens are the right default.
Start read-only. Only expose a limited set of "safe" operations to agents via MCP rather than allowing full API access. Expand scope only after you have reviewed logs from real agent activity.
Check your edition before building. For the Salesforce first-party route, you need a Salesforce Enterprise Edition org or above, a Salesforce administrator, an MCP-compatible client, and permission to create an External Client App.
For Docusign, the beta server has been live since at least February 2026. The GA on September 30 is a promotion, not a debut. If you want to test the integration before GA, the developer documentation is already live.
Log everything at the MCP layer, not just the application layer. ServiceNow's AI Control Tower makes this explicit; the same discipline applies if you're connecting a third-party agent to Salesforce.
The picture forming here is not that MCP is replacing REST APIs. It is that the major vendors are betting that agent-native, protocol-level access will become the default integration layer - and they want to own the governed endpoint rather than let teams build unreviewed open-source connectors. The MCP server list is beginning to read like an enterprise SaaS directory.
For teams already on these platforms, the question is not whether to connect agents to them. It is how to set the permission scope before something runs that you did not expect.
Enterprise MCP servers: common questions
What is an enterprise MCP server?
An enterprise MCP server is a vendor-managed endpoint that exposes a business platform's real operations - not just its data - to any MCP-compatible AI agent. The vendor handles hosting, authentication, and permission enforcement. The agent sends tool calls; the server executes them under the authenticated user's permission scope, with actions logged by the platform.
How does the Salesforce MCP server work with AI agents?
Salesforce hosted MCP servers are generally available for Enterprise Edition orgs and above. What started as a pilot and then a beta is now a production-ready capability. Any MCP-compatible client can securely connect to Salesforce with enterprise-grade authentication, governance, and admin control built in. Agents inherit the permissions of the user whose OAuth token is used.
When does the Docusign MCP server go generally available?
Docusign announced on September 4, 2026 that it will open its MCP Server to every AI agent on September 30. Agreement intelligence and governed action, powered by AI engine Docusign Iris, are callable from Claude, ChatGPT, Gemini, Copilot, Slack, and any MCP client.
What is the main risk of connecting AI agents to enterprise MCP servers?
The risk is not the protocol itself but the identity that owns the session. When an agent calls multiple MCP servers in a single workflow - say, Salesforce and Docusign in sequence - it acts under the permissions of the authenticating account across all of them. A shared service account creates a wide blast radius. Scope MCP sessions to real users where possible, start read-only, and review logs at the MCP layer before expanding action permissions.
How does ServiceNow's MCP server differ from Salesforce's?
Other platforms let agents read and write data. ServiceNow enables agents to execute governed work: flows, playbooks, approvals, catalogs - the full system of action. Every action runs through ServiceNow AI Control Tower, so it's identity-verified, permission-scoped, and fully auditable. Salesforce's model ties permissions to the authenticating user's existing access; ServiceNow adds a dedicated governance and metering layer on top.