MCP Tool Policies & Enterprise Governance
AVAILABLEEnforce granular security guardrails, allowlists, and execution approval workflows on tools exposed via Model Context Protocol (MCP) servers.
- Portal Page:
/projects/[projectId]/mcp-policies
Rendering diagram...
graph LR
ToolCall["Agent Tool Call (drop_table)"] --> PolicyEngine["Naagmani MCP Policy Engine"]
PolicyEngine --> Check{"Policy Decision"}
Check -->|Allowed| Exec["Execute Tool"]
Check -->|Blocked| Block["Reject (HTTP 403 Security Policy)"]
Check -->|Requires Approval| Notify["Pause & Notify Human Reviewer"]
Policy Types #
- Tool Allowlists & Blocklists: Explicitly allow or prohibit specific tools (e.g. allow
read_file, blockdelete_file). - Parameter Constraints: Restrict tool parameters (e.g., limit SQL queries to
SELECTstatements only). - Human-in-the-Loop Approvals: Pause destructive tool executions until an administrator approves the action.
- Rate Limiting: Cap the number of times an agent can invoke a specific tool per minute.
Next Steps #
- Configure content guardrails: AI Guardrails & Governance
- View security audit trail: Security Audit Logs