Triagic + Neo4j: ticket investigations over your knowledge graph, read-only
Run read-only Cypher against a Neo4j database and inspect its schema. The server is started with NEO4J_READ_ONLY=true, so the write tool is never registered. Triagic connects to Neo4j from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of Neo4j.
What you can ask
- Search Neo4j for what we already know about this customer's setup
- What does Neo4j record as the root cause of the last export incident?
- In Neo4j, which systems is the import worker connected to?
- Recall from Neo4j every note tagged with this account id
- What did we decide about the legacy export API, according to Neo4j?
What the agent can do
These are the 2 tools Triagic exposes from the Neo4j MCP server. Anything else the server lists is dropped at connect time.
- get_neo4j_schema
- read_neo4j_cypher
Connect in three steps
- 1
Mint a read-only credential in Neo4j
Create a dedicated user or token that can only read. Started with NEO4J_READ_ONLY=true, so the server never registers its write tool; only schema and read-cypher are exposed.
- 2
Add it in the Triagic portal
Integrations, then Add shared data source, then Neo4j.
- Connection URI: Aura: Instance details → Connection URI (neo4j+s://). Self-hosted: bolt:// or neo4j://, with +s for TLS.
- Username
- Password: Prefer a user granted only the `reader` role: the server refuses writes, but a read-only grant is the boundary that holds even if the server is misconfigured.
- 3
Let a desktop pick it up
Saving validates the shape of what you typed. The first desktop app to sync starts Neo4j locally and reports running or degraded with the error text.
Field-by-field setup, TLS options and the error table: Neo4j in the docs.
Read-only, by construction
Started with NEO4J_READ_ONLY=true, so the server never registers its write tool; only schema and read-cypher are exposed.
FAQ
- Can Triagic change anything in Neo4j?
- No. Started with NEO4J_READ_ONLY=true, so the server never registers its write tool; only schema and read-cypher are exposed. Give it a read-only credential as well, so the guarantee does not rest on one layer.
- What do I need to connect Neo4j?
- Connection URI, Username, Password. The desktop app on a member's machine starts the connection; the portal never holds a live process.
- Does Neo4j cost extra?
- No. Every connector is included in the seat price. Start a 14-day trial without a card.
Related integrations
- Neo4j knowledge graph memoryRead an agent memory graph stored in Neo4j by the mcp-neo4j-memory server: search entities, look them up by name, or read the whole graph. Create, add and delete tools are never exposed.
- MemgraphRun read-only Cypher against a Memgraph instance and inspect its node, relationship and enum schema. The server is started with MCP_READ_ONLY=true, which refuses CREATE, MERGE, SET, DELETE, REMOVE and DROP.
- GraphitiSearch a Graphiti temporal knowledge graph (Zep's open-source memory engine) for entities, facts and episodes. Connects to your own Graphiti MCP server over HTTP; the add, delete and clear tools are never exposed.
- Mem0Search and read the memories a Mem0 workspace holds for its users, agents and apps. Connects to Mem0's hosted MCP server with an API key; the add, update and delete tools are never exposed.
Try it on your own Neo4j
No card. Install the desktop app, connect Neo4j read-only, and triage a real ticket this afternoon.