ToolJet has published a second worked example of an agent building a whole internal application, and this one is bigger than the first. In Build Inventory and Pricing Command Centre with ToolJet MCP, Athulya R hands ToolJet’s MCP server a merchandising app and gets back three pages, 10 database tables, 23 queries, and 40 components, with one repair cycle for a table column width and no validation errors on the first build. The line is the same one as the geofence post this series covered eleven days ago, and it is the company’s thesis: “The agent works through the whole application, not the screen: the data model, the queries, the component tree and the wiring between them all land as one structured ToolJet application.” The contrast is stated plainly: “A generated codebase hands you files first and integration work later.”
There is no cost figure this time, only the build counts, which are observations rather than claims. What is new is the governance in the generated app. Repricing goes through a modal that enforces a price band and requires a reason, and “the price band is also enforced on the server by the write query itself,” which is the part a reviewer should check for in any agent-built app. Role-based access is applied at the platform and the app level so that “merchandisers, category heads and finance users share the same application without sharing the same write paths.” A price-change audit table and purchase requests round it out. Zero code files to maintain is the headline number, and the honest version is that the application is the artifact and the platform is the runtime.
The catalog’s view of ToolJet has not changed since the last post, and that is the finding. The ToolJet provider page lists 4 API pages, all of them the External API for managing the platform: the app this story generates is an object on the ToolJet Applications API, and the merchandiser, category head, and finance roles are the ToolJet Groups API. The MCP server dimension is lit. The agentic access profile maps 23 operations, 15 of them acting.
The Kin Score is 44.4, developing band, down from 46.5 on September 25. Discoverability carries it at 65.0 and contract quality at 56.4. Developer ergonomics is 23.8, exactly where it was, because the External API still authenticates with a static token in an environment variable. The Agent Readiness score is 22.9, agent-aware, and the unlit list is unchanged: error semantics, OpenAPI examples, agent skills, every identity dimension. Two posts in eleven days have shown an agent building governed applications with roles, audit tables, and server-side write rules. The API that governs those applications from outside still has none of that written down. The apps keep getting better. The door has not changed.