Several recruitment ATS platforms now offer an MCP connection, including Crumblelead, Recruit CRM, Loxo, Manatal and Recruiterflow, although supported clients and actions differ. Choose on the work you can actually perform and the permissions applied to it, rather than the presence of an AI logo.
A chat window that can discuss a CV is useful. A chat window connected to the correct candidate, job and client records can do a different sort of work. It can answer a question using the agency's current database or make a supported change without another round of copying and pasting.
That difference also raises the stakes. Before connecting an assistant, establish what it can read, what it can change and whose authority it uses.
What is MCP in plain English?
Model Context Protocol is a standard way for an AI application to connect to outside data and tools. Think of it as an agreed connection between the assistant and another system. The ATS supplies the available operations; the AI application lets you request them in ordinary language.
MCP is not an AI model, a guarantee of accuracy or permission to access an entire company. The server's capabilities and its authorisation determine what is possible. Two vendors can both support MCP while offering very different access.
An in-app assistant is not automatically an MCP server. Neither is an API, a browser extension or an integration that copies a completed conversation into a record. Those can be useful, but they do not establish the same connection.
Which recruitment ATS platforms have verified MCP support?
This comparison was checked on 24 September 2026 against the vendor documentation listed in Sources. “Not confirmed” means we could not verify the claim in those sources; it does not prove that a capability is absent.
| Platform | What we could verify | Boundary to check |
|---|---|---|
| Crumblelead | Built-in server with 30+ tools; Claude, ChatGPT, Claude Code and other MCP clients | Role permissions, team data scope and revocable key |
| Recruit CRM | Native MCP; documented read and write operations; Business and Enterprise availability | Confirm the required plan and client connection with your account |
| Loxo | Native MCP; product page describes about 180 actions; pricing includes MCP in Core | Confirm permissions, available actions and the current package |
| Manatal | Native MCP for Enterprise Plus; documented Claude and ChatGPT connections | Official ChatGPT plugin and custom connections use different access models |
| Recruiterflow | Native Claude connection documented; read-only access through MCP | ChatGPT support and plan eligibility were not confirmed in the guide |
| Bullhorn | Third-party CData MCP connector documentation exists | A native Bullhorn MCP server was not confirmed |
| Crelate | Website labels MCP as coming soon | Do not treat the announcement as a live deployment |
| Vincere | Native MCP support not confirmed | Request current documentation and a demonstration |
This is a list of verified routes, not a claim that every ATS on the market has been tested. Connection availability can change faster than a procurement cycle. Ask the vendor to demonstrate the route you would buy, using the client your team intends to use.
Why does the connection method matter?
Manatal's documentation provides a useful example. Its official ChatGPT plugin uses individual user identity and permissions. Its custom MCP connection method uses an account-level credential with admin-level access. The same ATS name therefore does not tell you the security boundary of every connection.
Recruit CRM documents user-level authorisation and role permissions. Recruiterflow's Claude guide describes a read-only connection. Read-only can be a sensible choice if the immediate goal is asking questions about records, rather than updating them.
A third-party connector adds another supplier to assess. CData documents a Bullhorn CRM MCP route, but that should not be described as a native Bullhorn feature. Confirm deployment, maintenance, costs and responsibility for support before treating it as equivalent.
What can you realistically do with an ATS connection?
Start with a task you already understand. In Crumblelead, supported examples include adding a candidate from a CV, moving a candidate's stage, logging a note, setting a reminder, drafting outreach and pulling numbers from the workspace.
A request such as “Draft outreach for this candidate using the job briefing” still needs a recruiter to check the result. The connection provides access and actions; it does not supply knowledge that was never recorded. A missing salary expectation remains missing until somebody asks.
Similarly, a request to move a candidate needs the correct person, job and destination stage. Ambiguous names are a reason to clarify the request, not a reason to trust a confident response. Confirm the record after a change, especially during the first few trials.
Do not assume every platform in the table supports these examples. Recruiterflow's documented read-only route cannot be treated as a route for making changes. A server with many actions may still lack the particular operation your desk needs.
How should you test it before paying?
Pick two ordinary workflows and one awkward case. For example, ask for the position of a known candidate on a known job, try a supported update to a test record, then repeat with two candidates who share a name.
Agree the expected answer beforehand. Otherwise a polished response can look successful even when it used an old job, confused two records or omitted a qualification that matters to the client.
For a numerical question, compare the answer with the underlying report and its date range. Ask which records support a summary. If the assistant cannot establish the evidence, it should not become the source of truth for your Monday forecast.
Use a small, authorised test set. Expanding to real agency work should follow a successful trial of the actual permissions and record operations, not just a successful connection screen.
Which security questions should you ask?
The important question is whose access the assistant inherits. A consultant should not acquire access to information they cannot normally see just because they connected a different interface.
- Does the connection use the individual recruiter's identity or a shared account credential?
- Which records and operations can that identity access?
- Are write operations available, and how are they distinguished from reading?
- What evidence is retained when a supported change is made?
- How can the connection be revoked, and how will you verify that access has stopped?
- Which companies process the information, and what do their terms say about retention and training?
These are purchasing questions, not a claim that every server implements the same controls. Test the answers with a restricted user as well as an administrator. An administrator's successful demo tells you little about a consultant's boundaries.
Treat candidate CVs, notes and other retrieved text as information to examine. They should not become authority to disclose unrelated records or perform a new task. The human request and the permitted workflow should remain clear throughout.
Does the AI subscription matter?
Yes. An ATS may provide an MCP server while the AI application's available connection options depend on your account and workspace settings. OpenAI's connection documentation describes developer mode and administrator controls; it does not justify promising identical availability on every ChatGPT account.
Check both sides before buying: the ATS plan and the chosen AI application's connection requirements. If a supplier demonstrates Claude, ask separately about ChatGPT. Support for the protocol does not mean every client exposes every action in the same way.
Price also needs context. Manatal's verified MCP route requires Enterprise Plus, publicly listed from $55 per user per month on annual billing. Recruit CRM places its MCP offering on Business and Enterprise; confirm the USD quote because public price sources differ. Loxo lists MCP in Core, whose advertised $149 annual-billing entry rate was a limited new-customer offer when checked.
Where Crumblelead fits
Crumblelead has a built-in MCP server with 30+ tools for Claude, ChatGPT, Claude Code and other MCP clients. It respects the user's role, accesses only their team's data and uses a key that can be revoked at any time.
It fits perm-focused independent and small-to-mid agencies that want AI to help with desk administration. It is not built for large temp or contract staffing businesses needing timesheets, payroll or VMS integrations.
FAQ
Is an ATS with AI automatically compatible with Claude or ChatGPT?
No. An in-app assistant and an external MCP connection are different capabilities. Ask for documentation covering the client, plan and actions you intend to use.
Can an MCP connection update candidate records?
Some can, including Crumblelead's supported stage changes and note logging. Others are read-only, so check the specific server rather than assuming all MCP connections can write.
Is a third-party connector necessarily a bad option?
No, it may provide a useful route for an existing system. It does add a supplier and technical arrangement whose permissions, cost and support need checking.
How should we choose between action counts?
Start with your required workflow and test whether it works correctly. A smaller set of suitable actions can be more useful than a larger catalogue that does not cover the task.
Sources
Model Context Protocol introduction. Checked 24 September 2026.
https://modelcontextprotocol.io/docs/getting-started/intro
OpenAI connecting and testing MCP plugins. Checked 24 September 2026.
https://developers.openai.com/plugins/deploy/connect-chatgpt
Recruit CRM MCP. Checked 24 September 2026.
https://recruitcrm.io/recruit-crm-mcp/
Loxo MCP. Checked 24 September 2026.
https://loxo.co/products/loxo-mcp
Loxo pricing. Checked 24 September 2026.
Manatal MCP server documentation. Checked 24 September 2026.
https://support.manatal.com/docs/mcp-server
Manatal pricing. Checked 24 September 2026.
https://www.manatal.com/pricing
Recruiterflow connecting to Claude via MCP. Checked 24 September 2026.
https://help.recruiterflow.com/en/articles/15518332-connecting-recruiterflow-to-claude-via-mcp
CData MCP Server for Bullhorn CRM installation. Checked 24 September 2026.
https://cdn.cdata.com/help/HAK/mcp/pg_mcpinstall.htm
Crelate pricing. Checked 24 September 2026.
https://www.crelate.com/pricing
Access Vincere Evo pricing. Checked 24 September 2026.