Title: MCP Security and Authorization Version: 1.0 Owner: [TENANT_CONFIGURATION_REQUIRED — Security Architecture] Status: Draft Last reviewed: 2026-09-07 Next review: [TENANT_CONFIGURATION_REQUIRED] Reviewers: Security, Architecture
Defines authentication, authorization, and safety controls for every MCP server in mcp-architecture.md.
| Tier | Definition | Authorization requirement |
|---|---|---|
| Read-only | Query external data, no side effects | Skill-level scope grant only |
| Propose-only | Produces a draft/suggestion, no external side effect until a separate confirmation step | Skill-level scope grant only |
| Approval-required write | Performs a real side effect on a sensitive external system (send offer for signature, create HRMS record, send candidate email) | Skill-level scope grant and the Workflow Engine must confirm a recorded human approval exists for the corresponding workflow action before the Tool Gateway permits the call |
mcp/tool-schemas/hr-tools.schema.json) before dispatch.Each MCP server has an explicit network egress allowlist limited to its specific vendor endpoint(s); no MCP server has general internet egress.
Timeouts, retries with backoff, and circuit breakers are applied per MCP server independently (see resilience-and-disaster-recovery.md); a failure in one server does not cascade to others.
Every MCP tool invocation (request, scope used, outcome, latency) is logged to the audit trail (see audit-log-specification.md), including denied calls (e.g., approval-required write attempted without a recorded approval).
sequenceDiagram
participant Skill
participant TG as Tool Gateway
participant WF as Workflow Engine
participant MCP as MCP Server (approval-required write tool)
Skill->>TG: Request write tool call (e.g., send offer for signature)
TG->>WF: Check: is there a recorded approval for this action/subject?
alt Approval recorded
WF-->>TG: Confirmed
TG->>MCP: Execute call
MCP-->>TG: Result
else No approval recorded
WF-->>TG: Denied
TG-->>Skill: Blocked - approval required
end
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 2026-09-07 | Documentation package generation | Initial creation |