Design for a read-only MCP server that exposes the accounting data
to Claude (or another MCP client) via stdio: project layout, DI
wiring, year/mandator scope handling, tool catalog with input/output
schemas, packaging + Claude Desktop config, and three privacy modes
(Full / Aggregate / Local) covering what actually leaves the machine
when a hosted-model client relays tool results to its model provider.
Not implemented; PR sequencing sketched at the end of the doc.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>