DEV Community

Cover image for Build a Security Questionnaire App With ToolJet MCP
Athulya R for ToolJet

Posted on Originally published at blog.tooljet.com

Build a Security Questionnaire App With ToolJet MCP

Introduction

Every enterprise deal brings a long security questionnaire, and most security and sales engineering teams still answer it from scratch. This tutorial shows how to build a security questionnaire app with ToolJet MCP for a B2B software company in Dublin. The app keeps an approved answer library with owners and review dates, matches each question in an uploaded questionnaire to the closest approved answer, and exports the completed pack as a PDF filled into the customer's own form. An AI agent generated it as a structured ToolJet application, with data, queries and interface together, so the team can keep editing it as the process changes.

Security questionnaire pack builder in ToolJet showing reused, tailored and new answer counts

The pack builder for a Northwind Bank questionnaire: 21 reused, 1 tailored and 3 new answers, 100 percent complete, with the pack register below.

Approved answer library with owners, review dates and stale flags

The answer library with owners, review dates and stale flags, filtered by category and review status.

Library submissions waiting for compliance lead approval

Library submissions from pack work, waiting for the compliance lead to approve or reject.

How the Answer Library and Pack Builder Work

The first page is a working answer library with filters for category and review status, a stale flag on older entries, and an editor that opens the selected answer with its review cycle and history. The second page is the pack builder, where you enter the customer and deal, upload a questionnaire, and match each question to the closest approved answer. Unmatched questions stay visible at the top, each match shows a confidence score, and the sales engineer can accept the suggestion, swap in another library answer, tailor the wording for that pack, or submit a new answer for review. A summary strip tracks reused, tailored, new, and unmatched work, then the finished pack downloads as a PDF filled into the customer's own form.

  • Searchable approved answer library with category and review status filters
  • Stale flags, owner fields, and review dates on each answer
  • Questionnaire upload, parsing, and matching with confidence scores
  • Pack-level tailoring, new-answer submission, and review handoff
  • Filled PDF export plus a pack register and activity log

Get Started With ToolJet MCP

Want to build it yourself? Start with the ToolJet MCP repository for setup instructions, supported agents, and everything you need to follow along.

The Consolidated Prompt to Rebuild the App

The build took several passes before the shape settled. The requirements are consolidated into one prompt here, so you can reproduce the same app in a single shot.

Build a polished internal app called Security Questionnaire Desk in ToolJet.

Keep it to two pages: Answer Library, showing approved answers with search, category and review status filters, a stale flag, and an editor with history; and Pack Builder, where a sales engineer uploads a customer's questionnaire, matches each question to the closest approved answer with a confidence score, groups unmatched questions at the top, and downloads a filled PDF.

Use a muted Nordic palette, calm and restrained, with dense two-column working areas, compact rows, clear hierarchy, and status colours only where they help.

Use PostgreSQL for the approved answer library, answer history, roles, library submissions, and pack items. Use ToolJet DB for the pack register and the pack activity log.

The compliance lead is the only person who can approve, change, or re-approve a library answer, and that rule should be enforced in the database. Sales engineers can build packs and tailor wording for one customer without changing the master answer.

How ToolJet MCP Builds the Questionnaire App

ToolJet MCP takes the questionnaire requirements and works through the whole application, so the data model, pages, components, queries, and wiring land as one structured ToolJet application inside ToolJet, not as a loose bundle you assemble later. Enterprise app building does not end at the interface, because data connectivity, workflows, permissions, deployment, and ongoing change are the rest of the job, and the generated app sits on a runtime that carries those where supported rather than handing you a codebase to operate yourself. The path stays open, so you can move from AI generation to visual editing and code when a specific rule or pack behaviour needs it.

The File Upload Issue We Fixed

The upload step looked broken because the file picker refused every questionnaire file. The picker had been limited to image/*, so PDFs never reached the parser. Switching the control to PDF, XLSX, and CSV fixed the flow.

PostgreSQL and ToolJet DB Tables Behind the App

The app ended up with seven tables. cqa_answers stores the approved answer library with the owner and last reviewed date, cqa_answer_history records each change, cqa_roles maps the compliance lead and sales engineer roles, cqa_submissions holds new answers waiting for review, cqa_pack_items stores each questionnaire item and its match, and cqa_packs plus cqa_pack_log live in ToolJet DB for the pack register and activity trail.

Page Components What they cover
Answer library 28 Answer table, filters, answer editor with history, submissions review
Pack builder 18 Upload, matching table, answer panel, summary, pack register

What ToolJet MCP Generated

Metric Result
Pages 2
ToolJet DB + PostgreSQL tables 7
Queries 30
Components 46
Code files to maintain 0
Repair cycles 2
Final validation 0 errors

Security Questionnaire Desk component tree generated by ToolJet MCP
The components ToolJet MCP created, in the ToolJet inspector

Industries That Answer Security Questionnaires

Any B2B software or services company that sells to regulated buyers runs this process: SaaS vendors answering bank and insurer due diligence, managed service providers handling NIS2 and DORA supplier reviews, health tech companies answering hospital procurement, and fintechs filling out partner bank onboarding forms. The common thread is a small security team answering the same questions for many deals.

Roles and Access in the Built App

Two roles, stored in PostgreSQL. The compliance lead is the only person who can create, change, re-approve or approve answers in the library, and the database functions refuse those writes from anyone else. Sales engineers can search the library, build packs, swap or tailor wording inside a pack and submit new answers for review, but tailored wording stays in the pack and never changes the master answer.

ToolJet Database: Built-In PostgreSQL Storage for Full-Stack Apps

A Security Questionnaire Desk app needs somewhere to keep its records, and ToolJet Database gives it a built-in, PostgreSQL-backed database with no separate server to provision or connect. Builders can create tables, relate them and query them from the same platform where the app is built.

The pack register and activity log live in ToolJet DB, while the answer library stays in PostgreSQL, so the team keeps the working records inside the same app without a separate database server.

Flow: create ToolJet Database tables in the database editor, query them from the app in GUI or SQL mode with no connection setup, and run them on ToolJet Cloud or your own PostgreSQL

ToolJet Database: Built-In PostgreSQL Storage for Full-Stack Apps

Tables, Data Types and Relationships

  • ToolJet Database overview: keep tables in a secure database that is only accessible within your ToolJet organization, on both ToolJet Cloud and self-hosted deployments.
  • Database editor: create tables and edit, search, filter and sort rows in a spreadsheet-like interface.
  • Supported data types: serial, varchar, int, bigint, float, boolean, date with time and jsonb columns, with an automatic serial id primary key on every new table.
  • Foreign keys: link tables and choose what happens to a row when the referenced row is updated or deleted, keeping referential integrity.

Querying ToolJet Database from Apps

  • GUI and SQL queries: list, filter, sort, aggregate and group rows in GUI mode, or write SQL directly in the SQL editor.
  • Works like any data source: ToolJet Database queries bind to components and events the same way as other data sources, without connection setup.
  • Self-hosted configuration: on your own deployment, ToolJet Database runs on a PostgreSQL database you configure and is exposed to the app through PostgREST.
  • Schema export: export table schemas to a JSON file.

This lets the Security Questionnaire Desk app go full stack in one platform, with data, logic and UI together, while external databases can still be connected later. Table limits vary by plan on the ToolJet pricing page.

Enterprise Features for Your Security Questionnaire App

A security questionnaire app handles approved answers, customer details, and review notes. ToolJet covers that governance at the platform layer, so you configure it once instead of rebuilding it in every app.

  • SSO and SCIM: sign in with SAML, OIDC or LDAP, and provision users automatically
  • Role-based access control: scope permissions to the app, the data source, and each query
  • Audit logs: track every login, edit, and approval decision for compliance review
  • Air-gapped deployment: self-host on Docker or Kubernetes so your data stays in your network
  • Multiplayer editing: several builders work on the same app, with versioning and Git sync
  • ToolJet AI inside your own deployment: run the AI features in your tenancy rather than a shared service

You could add a notification layer with ToolJet Workflows. For example, a workflow could fire when a new answer is submitted, post a Slack message to the compliance lead, send a Gmail message to the sales engineer, and write the review note back to cqa_submissions.

Final Takeaways

This build gives security and sales engineering teams one place to maintain approved answers, compare uploaded questionnaires against that library, and export a filled PDF for the customer form. The result is a repeatable flow for sales engineering and compliance, instead of rewriting the same material for each deal. ToolJet MCP turns the requirements into a real, editable ToolJet application, so the team can keep adjusting the library, matching behavior, and pack output as the process changes. That is the useful part of the build, because the app stays alive after the first pass.

Try ToolJet MCP

Build your own security questionnaire desk with ToolJet MCP, then request a ToolJet demo for your answer library and pack flow.

FAQs

What is ToolJet MCP in this build?

ToolJet MCP takes the questionnaire requirements and turns them into a structured app inside ToolJet. For this desk, the library, pack builder, matching logic, and PDF output live together instead of becoming a loose codebase you have to assemble elsewhere.

What does the answer library page show?

It shows the approved answer set with search, category filters, review status, and a stale flag for items past their review cycle. Opening a row reveals the answer text, owner, review interval, keywords, and change history in one editor.

How do you reproduce the build from the prompt?

Use the prompt in this article as the full specification and build the two pages, tables, and matching rules in one pass. The consolidated prompt captures the page layout, review flow, and PDF output so you do not have to reconstruct the shape from notes.

Do you need to write code for questionnaire matching?

You do not need to handwrite the whole app. The screens come from visual components, while parsing uploaded files, scoring matches, and filling the exported PDF use code where the workflow needs logic in this build.

What happens to the app after the agent finishes?

The generated app stays as a structured ToolJet application, not a one-off code dump. The runtime carries the data connections, workflows, permissions, deployment, and ongoing change where supported, so you keep editing the same app as the process changes.

Can the app use PostgreSQL and ToolJet DB together?

Yes. The answer library, history, roles, submissions, and pack items live in PostgreSQL, while the pack register and activity log sit in ToolJet DB, which keeps operational state separate from the review content for the team.

Can several teammates work on the same app at once?

Yes. ToolJet supports multiplayer editing, so several builders can work on the same app, with versioning and Git sync. In daily use, the compliance lead maintains the master answers while sales engineers build packs from them.

Top comments (0)