The Vantage View | Salesforce

SS&C's Black Diamond MCP Server: The Door Nobody Approved Yet

Written by David Cockrum | Sep 18, 2026, 12:00:01 PM

Quick Answer

 

Three wealthtech vendors — Vanilla, FinTurk, and SS&C — shipped agentic AI features in the same week, InvestmentNews reported on September 10, 2026. The headlines went to the agents. The detail worth an RIA's attention is smaller: SS&C's Black Diamond AI now ships a Model Context Protocol (MCP) server, letting advisors connect the platform's data to whatever outside AI tool their firm chooses, instead of SS&C's own interface alone. Read that again — your portfolio data now has a door into whatever AI tool an advisor decides to open. That connection runs on its own credentials and its own permissions, not the advisor's. For a $1–5B RIA mid-evaluation, the question isn't which assistant is smartest — it's which system holds the household record, and who signs off before the next connection opens.

Key Takeaways (TL;DR)

  • What happened: Vanilla, FinTurk, and SS&C all shipped agentic or AI-assisted wealthtech features in the same week (InvestmentNews, Sept. 10, 2026).
  • The real story: SS&C's Black Diamond MCP server, which pipes platform data out to outside AI systems — a shift from "AI inside our app" to "our data, in whatever model you like."
  • The operator detail: an MCP connection runs as itself, under its own credentials and permissions — not as the advisor who clicked "connect."
  • Why it matters: this is a books-and-records and access-governance question before it's an AI-capability question.
  • The cost of waiting: InvestmentNews separately reports firms burn 15–20 hours a month reconciling data across disconnected systems for compliance reporting alone — exactly what these tools promise to erase, and can quietly widen if left ungoverned.
  • Best for: RIA COOs and CCOs mid-evaluation of a wealthtech AI tool or MCP connection.
  • Bottom line: evaluate the connection, not just the assistant — credentials, permission scope, approval workflow, logging, and system of record.

SS&C Just Opened a Door Nobody Approved Yet

Ahead of the Future Proof Festival, three wealthtech vendors shipped AI upgrades the same week, all aimed at the manual work advisors do catching issues in client accounts, InvestmentNews reported. Vanilla expanded its AI assistant, VAI, to scan an advisor's entire client roster — not just the largest accounts — for unfunded trusts, outdated beneficiary designations, and insurance gaps against a client's estate tax exposure; the company told InvestmentNews its extraction engine has processed 60,000+ estate documents and modeled 32,000+ estates, with client-identifying data never reaching a language model. FinTurk launched PortfolioSolver, which turns plain-language constraints into rules for a deterministic trade optimizer, and Vigil, which flags failed data syncs, cash thresholds, and unanswered client emails in the background.

And SS&C released Black Diamond AI: natural-language data queries, proactive account summaries, and an agentic assistant, all running on the company's existing AI Gateway governance layer. Buried in that announcement is the detail that matters most — a Model Context Protocol (MCP) server for Black Diamond, "letting advisors pull the platform's data into whatever AI system their firm already uses rather than being confined to SS&C's own interface," as InvestmentNews put it. Sean Hendler, director of performance reporting at HB Wealth, told the publication the new server "fits perfectly into our broader AI strategy, allowing advisors to seamlessly integrate quality Black Diamond data with information from other key sources."

Two of these three launches are "AI inside the platform." One is "data out, to any AI you like."

Why MCP Is the Real Story — Not the Agents

For two years, wealthtech vendors have competed on whose AI assistant is smartest inside their own app. An MCP server is a different move: a standard way for a platform to expose its data to any AI system that speaks the same protocol, not just the one the vendor built. (Our guide to what the Model Context Protocol is and how it connects AI to business data covers the mechanics.) In practice, a firm could point Black Diamond's data at Claude, an internal tool, or whatever it standardizes on next year — without waiting on SS&C to build that integration.

That's a genuinely useful shift. One well-governed data connection that any approved AI tool can use beats a dozen one-off integrations, each with its own login and its own blind spot. It's also a shift most $1–5B RIAs haven't been asked to evaluate, because until this week the AI conversation with a platform vendor was about features, not plumbing. Once a platform ships an MCP server, the question changes from "which assistant should we use" to "who else can now reach our data, and on what terms."

The Operator Detail: A Connection Isn't the Advisor

Here's the part that's easy to miss under the product headlines. When an advisor asks an AI tool to pull data through an MCP connection, the request doesn't necessarily travel on the advisor's own login — it travels on whatever credential (an API key, an OAuth token, a service account) was set up to authorize that connection. That credential carries its own permissions, which may be broader than the advisor's, narrower, or simply undocumented. The agent runs as itself, not as the person who opened it.

That's why "who can see this record" and "what can this connection retrieve" are two different questions with two different answers. It doesn't stop at approval, either: connections can change behavior afterward, through a routine vendor update or, in adversarial cases, a maliciously modified tool definition — a risk we cover in our guide to MCP tool poisoning and rug-pull attacks. None of this makes MCP unsafe. It makes MCP something that needs an owner, a review date, and a permission map — the same discipline your firm already applies to a new custodian feed or vendor with system access.

The Books-and-Records Questions Most $1–5B RIAs Haven't Asked

SS&C's announcement is genuinely useful technology arriving ahead of a governance conversation most mid-sized RIAs haven't had yet. Before approving a Black Diamond MCP connection, or any platform's equivalent, walk through five questions:

Question Why it's a books-and-records issue What to ask
Agent identity & credentials Regulators and auditors need to know whose action produced a record — a person's or a system's. What credential authorizes this connection, and is it tied to a named owner?
Permission scoping An over-scoped connection can expose more households than the advisor who requested it could ever see. Does the connection inherit the advisor's own access, or a separate, broader grant?
Connection approval workflow Ungoverned connections accumulate the way shadow IT always does — one advisor, one tool, no ticket. Who signs off on a new connection: compliance, IT, or both?
Logging & supervision If an AI tool can read or write client data, supervision needs to see it the same way it sees email or trades. Is every prompt, retrieval, and write action logged and reviewable?
System of record Once data flows both directions, "which system is authoritative" stops being obvious. If Black Diamond and the connected AI tool disagree, which one wins?

Why This Is Urgent Now, Not Next Quarter

InvestmentNews reported separately this month that firms spend 15 to 20 hours a month reconciling information across systems for compliance reporting alone, according to Conor Curtis, head of product at Practifi — a burden he said can offset whatever time savings new AI tools were meant to create. Disconnected systems, he added, also introduce risk: "conflicting growth assumptions, duplicate client records, and incomplete histories can become compliance problems."

That's the exact overhead an MCP connection promises to erase — one governed pipe instead of a dozen manual exports. Left unmanaged, it's also how that overhead quietly gets worse: more systems reachable, more copies of the household record in circulation, less clarity about which one is correct. The fix isn't slower AI adoption — it's governing MCP connections centrally instead of approving them one advisor request at a time.

An MCP Evaluation Checklist for RIAs Mid-Evaluation

  1. Get the credential model in writing. Ask the vendor what identity a connection authenticates as before the first advisor connects anything.
  2. Map permission scope before, not after. Define what a connection can read and write ahead of approval, rather than reverse-engineering it later.
  3. Name an approver. Require COO or CCO sign-off, or both, in the same workflow as any other vendor with data access.
  4. Require full logging. Every prompt, retrieval, and write action, tied to the credential that produced it — reviewable like trade and email supervision.
  5. Pick the system of record, in writing. Decide once which platform is authoritative, before two systems disagree.
  6. Ask about tool-definition integrity. Confirm the vendor pins and monitors what a connection can do, since that can change after approval.
  7. Start narrow. Named users, named data, read-only where possible.
  8. Put a review date on the calendar. Treat approval as a checkpoint, not a one-time event.

Proof This Discipline Pays Off

Governance and integration discipline done well doesn't slow a firm down — it makes scale possible. A $30B+ independent RIA came to Vantage Point with a legacy Salesforce environment that had become the actual bottleneck, advisors juggling five-plus disconnected systems just to assemble one client picture. A phased Financial Services Cloud reimplementation across 14 integrations delivered 95% adoption within 90 days, 350% better data completeness, and a 27% cut in administrative task time (see the full anonymized case study). The lesson transfers to MCP directly: connecting more systems isn't the risk. Connecting them with no plan for who owns the record, and who approved the wire, is.

How Vantage Point Helps

Vantage Point isn't in the business of talking RIAs out of AI. We're in the business of making the connection defensible before an auditor asks. For firms evaluating a Black Diamond MCP server or any AI tool wired into the household record, we build the permission map, approval workflow, and logging model alongside your compliance team — through our compliance and security solutions and system integration and data migration services. Senior consultants only — no junior handoffs; the experts you meet are the experts who deliver.

Evaluating a Wealthtech AI Connection?

 

Before you approve the next MCP connection, get the credential model, the permission scope, and the logging plan in writing. Vantage Point's senior consultants can run that review alongside your compliance team in weeks, not quarters. Contact Vantage Point to schedule a books-and-records readiness session, or explore our compliance and security solutions to see how we support RIAs end to end.

Frequently Asked Questions

What is SS&C's Black Diamond MCP server?

It's a Model Context Protocol server SS&C added to Black Diamond AI, announced the week of September 10, 2026. It lets advisors connect Black Diamond's platform data to an outside AI system their firm chooses, instead of only using SS&C's own built-in AI features.

What is the Model Context Protocol (MCP), in plain terms?

MCP is an open standard, created by Anthropic, that lets AI systems connect to business tools and data through one common protocol instead of a custom integration for every pairing. When a platform ships an MCP server, outside AI tools can request its data directly, with the platform's own permissions and logging controlling what they get.

Does an MCP connection see exactly what the advisor who set it up sees?

Not necessarily. A connection authenticates on its own credential — an API key, OAuth token, or service account — which carries its own permission scope. That scope can be broader or narrower than the advisor's own access, so it has to be checked and documented separately rather than assumed.

Who should approve a new MCP connection at an RIA?

Treat it like any other vendor with access to client data: named sign-off from compliance and operations leadership, typically the CCO and COO, not an individual advisor's IT request. The approval should record what the connection can access, who owns it, and when it will be reviewed again.

How is an MCP server different from the AI features already inside a platform like Black Diamond?

Built-in AI features keep data and processing inside the vendor's own application. An MCP server does the opposite: it opens platform data to whatever external AI system the firm connects, which is more flexible but shifts the access-control question from the vendor's interface to the firm's own governance.

How much does disconnected data actually cost an advisory firm?

InvestmentNews reported firms spend 15 to 20 hours a month reconciling information across systems for compliance reporting alone, citing Practifi's head of product, Conor Curtis — overhead that can erase whatever time an AI tool was supposed to save if the underlying systems stay disconnected.

What's the first step before connecting Black Diamond, or any platform, to an outside AI tool?

Get the credential and permission model in writing before the first connection goes live: what identity it authenticates as, what it can read and write, who approved it, and how it's logged. That documentation is the real deliverable, not the AI feature itself.

Sources

Vantage Point is a boutique CRM consulting firm helping businesses transform with Salesforce, HubSpot, and AI — 150+ clients, 400+ engagements, and a 4.71/5 average engagement rating. Learn more at vantagepoint.io.