Title: ADR-004 Version: 1.0 Owner: [TENANT_CONFIGURATION_REQUIRED — Security Architecture] Status: Accepted Last reviewed: 2026-09-07 Next review: [TENANT_CONFIGURATION_REQUIRED] Reviewers: Security, Architecture, AI Governance
Agents need access to external systems (calendar, email, HRMS, e-signature, document management, background verification, payroll, IT provisioning). Direct, broad credentials granted to the agent runtime would create a large blast radius if an agent is manipulated via prompt injection or a bug.
Each external system domain is fronted by its own isolated MCP server, independently deployed and authenticated (OAuth 2.1 / OIDC, short-lived tokens sourced from a vault — never long-lived static credentials). Tools are classified as read-only, propose-only, or approval-required write; only propose-only and read-only tools may be invoked by an agent without a synchronous human confirmation step, and any write to a sensitive system (e.g., sending an offer, creating an HRMS record) requires the workflow engine to have already recorded the corresponding human approval before the MCP call is permitted. Every MCP server enforces input validation, output sanitization, network egress allowlists, per-tool scopes, timeouts, retries, circuit breakers, and full audit logging of every call. See mcp-architecture.md and mcp-security-and-authorization.md.
Accepted.
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 2026-09-07 | Documentation package generation | Initial creation |