← All posts

Agents · 7 min read

MCP explained: connecting AI to your tools safely

The Model Context Protocol gives AI assistants a standard way to reach your tools and data. Here's what it is, why it matters, and how to roll it out without opening security holes.

Subhash Nunna ·

Every useful AI assistant eventually needs to reach outside itself — to read a ticket, query a database or post a message. For years, each of those connections was a one-off integration. The Model Context Protocol (MCP) is an open standard that changes that.

What MCP is

MCP defines a common way for AI applications (clients) to talk to services that expose tools and data (servers). A server describes the tools it offers — their names, inputs and what they do — and any MCP-compatible client can discover and call them.

Build a connector once, and it works across every assistant that speaks the protocol.

Why it matters for organisations

Standardisation is what turns scattered experiments into a platform. With MCP, a company can:

  • maintain one connector per internal system instead of one per assistant
  • review and approve connectors centrally
  • give teams a catalogue of trusted tools to build on

The risks to plan for

Connecting AI to real systems raises real security questions:

  • Over-broad access. A connector that uses an admin token gives every user admin powers through the assistant.
  • Untrusted servers. A third-party server can describe its tools misleadingly or return content designed to manipulate the model.
  • Invisible actions. Without logging, nobody knows what the assistant did on a user’s behalf.

How to roll it out safely

  1. Run a registry. Keep an internal catalogue of approved MCP servers, with owners and versions. Block everything else by default.
  2. Use the user’s identity. Connectors should act with the calling user’s permissions, not a shared service account.
  3. Separate reads from writes. Expose read-only tools first; require confirmation for anything that changes data.
  4. Log every call. Record which user, which tool, which arguments and what came back.

MCP is quickly becoming the plumbing of enterprise AI. Treat it like any other integration layer — with ownership, review and observability — and it becomes an enabler rather than a risk.