Skip to main content

MCP Security

Overview​

MCP Security is the connector-governance side of AI Agent Safety. It helps you decide which AI connectors and MCP servers are allowed, monitored, or blocked, so automation only reaches the integrations you trust.

Why this matters​

AI agents become powerful, and risky, through their connectors. A connector can read data or take actions on your behalf. Not every connector should be trusted by default. MCP Security lets you govern them deliberately.

What you can use it for​

  • Keep an inventory of the AI connectors in use.
  • Mark connectors as sanctioned or unsanctioned for your company.
  • Hold back or review unapproved connectors and MCP servers.
  • Require approval before high-impact connector actions run.

How it works​

Dralvia maintains a connector inventory where each connector carries a sanctioned status. Each workspace adds its own governance overlay on top of the global inventory: a connector can be marked sanctioned, monitor, or blocked for your workspace without changing the shared catalog. Unsanctioned connectors can be surfaced for review, and high-impact actions can require human approval before they proceed. Every decision is recorded as evidence.

How to use it​

In the UI:

  1. Open AI Agent Safety in the platform.
  2. Review the connector inventory. Each connector shows its sanctioned status and whether it is allowed for your workspace right now.
  3. Set a control on a connector: sanctioned (allow), monitor (allow but record), or blocked. Add a note so reviewers know why.
  4. For high-impact agent actions, use the trust check so a human approves before the action runs.

By API (workspace API key required):

  • GET /api/agent/connectors/inventory: the connector inventory with each connector's sanctioned_status, your tenant_control, and allowed_now.
  • GET /api/agent/connectors/governance: your workspace's connector controls.
  • POST /api/agent/connectors/governance with { "connector_id": "<id>", "control": "sanctioned|monitor|blocked", "note": "..." } to set a control (the global inventory is never modified).
  • DELETE /api/agent/connectors/governance/<connector_id> to clear a control.
  • POST /api/agent/trust/check with the proposed action (and optional connector, target_url, prompt) returns an agent_decision, risk_score, and risk_level so a high-impact action can be gated for human approval.

Evidence and privacy​

Each governance decision and trust check is recorded as evidence your reviewers can audit. Controls are workspace-scoped: a workspace only ever reads and writes its own overlay, and the shared connector catalog is never changed by a workspace. Notes you add are stored with the control for context.

How to test it​

  1. GET /api/agent/connectors/inventory and confirm you see connectors with a sanctioned_status and allowed_now.
  2. POST /api/agent/connectors/governance to mark a connector blocked, then re-read the inventory and confirm allowed_now is now false for it.
  3. POST /api/agent/trust/check with a high-impact action and confirm the response returns a decision and risk level.
  4. DELETE the control and confirm the connector returns to its default status.

How to roll back​

Remove a workspace control with DELETE /api/agent/connectors/governance/<connector_id> (or clear it in the AI Agent Safety console) and the connector reverts to its global sanctioned default. Removing controls is immediate and does not affect other workspaces.

Troubleshooting​

  • A connector is unexpectedly held: check whether your workspace set it to blocked, or whether the sanctioned-connectors-only policy flag is on and the connector is not sanctioned.
  • unknown_connector (404) when setting a control: you can only govern connectors that exist in the global inventory; check the id from the inventory endpoint.
  • Trust check returns 404 agent_trust_check_disabled: the trust-check policy flag is off for the environment.

Limitations​

Dralvia governs the connectors and actions it integrates with, with approval gates and evidence. It does not control every possible connector or provide full AI agent runtime control outside the surfaces it integrates with. High-impact action gating applies to actions routed through the trust check.

What Dralvia does and does not claim​

Dralvia governs the connectors and actions it integrates with, with approval gates and evidence. It does not claim to control every possible connector or to provide full AI agent runtime control outside the surfaces it integrates with.