Solutions · Financial services

Control where your agents share customer financials.

Give your agents access to customer financials for analysis and support. Use Wicket policies to block public or external sharing after they read those records.

Snowflake
Queries customer financialsSnowflake MCP · sensitive read
✓ Allow
Notion
Publishes the summary to a public pageNotion MCP · public page
✗ Deny
Notion
Publishes it to the finance team’s pageNotion MCP · internal page
✓ Allow

Why: customer financials read by the same identity.

Both servers connect through Wicket.

Choose which sharing attempts to block.

Use these policies to let your agents read the records they need while blocking their writes to the destinations below.

  • Board reporting

    An analytics agent queries customer financials for a board summary, then tries to publish it to a public Notion page.

    Snowflake
    Queries customer financialsSnowflake MCP · sensitive read
    ✓ Allow
    Notion
    Publishes to a public pageNotion MCP · public page
    ✗ Deny

    PolicyBlock writes to public pages after the same identity reads customer financials.

  • Customer support

    A support agent reads live payment records in Stripe, then tries to copy them into an external Airtable base.

    Stripe
    Reads live customer recordsStripe MCP · live records
    ✓ Allow
    Airtable
    Copies into an external baseAirtable MCP · external base
    ✗ Deny

    PolicyBlock writes to external bases after the same identity reads live Stripe records.

  • Off-hours access

    An on-call agent queries account balances at 02:14 on a Sunday, then tries to post the numbers to a Slack channel.

    Snowflake
    Queries account balancesSnowflake MCP · Sun 02:14
    ✓ Allow
    Slack
    Posts the numbers to a channelSlack MCP · Sun 02:14
    ✗ Deny

    PolicyAfter a sensitive read, allow sends only Monday to Friday, 08:00 to 18:00.

Set sharing rules for financial data.

Let your agents query customer records, then choose where they can publish the results. Test your draft policy against the last 24 hours of calls before enforcing it.

  1. 01

    Connect your financial tools

    Connect Snowflake, Stripe, Notion, Airtable, and Slack through Wicket. Your agents can continue using the same MCP tools.

  2. 02

    Choose the records to protect

    Scope your read policy to balance and transaction tables and live Stripe records. Leave test and aggregate tables outside that policy.

  3. 03

    Block public and external sharing

    Once an identity matches the read policy, block its writes to public Notion pages and external Airtable bases.

  4. 04

    Set a schedule for sharing

    Allow sends after a sensitive read only Monday to Friday, 08:00 to 18:00.

Show your auditors why a call was blocked.

Each denial links the agent and the analyst it acted for to the earlier read and the rule that blocked the call. Your risk team can review the decision in one record.

AUDIT-7C21B08 ✗ Denied
Who
analytics-agent · OBO dana@company.example
What
notion.create_page → public page
When
14:22:07 UTC · Notion MCP
After
snowflake.query · customer_balances · 14:20:51 UTC
Why
block-public-after-financials — customer-financials read matched earlier for this identity

Other solutions

Tell us what your agents need to access.

Wicket applies policies using earlier policy matches for the same identity. It does not classify message contents, and both MCP servers must connect through Wicket. We’ll help you plan custom MCP connections during onboarding.