ArchitectureA supervised JVM-class runtime — OLTP on seven engines, OLAP on three. AI-native, MCP-native, observable as plain SQL.Read the architecture
Está viendo la edición Perú. Está viendo la edición Colombia. You're viewing the Pakistan edition. Cambiar a la edición global →Cambiar a la edición global →Switch to the global edition →

MCP refusals that explain themselves, and an audit that says why

Every MCP refusal now carries a kind from a closed list, hidden tools are logged by name, the MCP service can be switched per node without a restart, and each call records its tokens in both directions.

A governed agent surface refuses often, and a refusal nobody can explain is as costly as one that did not happen. An agent that cannot tell a missing tool from a forbidden one retries blindly; an operator who cannot see what was hidden cannot tell a policy from a fault. This release makes every refusal on the MCP surface classifiable, attributable and visible to the person who has to act on it.

One access decision, stated

  • One policy, applied twice. Whether a user may call a tool is decided by a single policy, applied when the tool list is built and again on the call, because a client can send a name it was never shown.
  • Absent, not struck through. A refused tool is left out of the list entirely; its name and parameters are themselves a disclosure.
  • Hidden tools named in the log. Each listing records which tools the policy withheld, for which user, world and target, and the catalogue page can show why a given tool is hidden.

Refusals with a kind

  • A closed list. Every refusal carries a kind, such as argument_missing, grant_refused, environment_refused or proof_failed, and names the argument it concerns, in the result's metadata beside the sentence written for the agent.
  • Recorded in the audit. The audit row keeps the refusal's kind, so refusals can be counted and trended by cause rather than read one at a time.
  • Tokens in both directions. Each call records the tokens of its request and its answer beside the byte counts, so the context an agent consumes is measured where it is spent.

The service as a live switch

  • Per node, without a restart. An administrator can enable or disable MCP on a node at runtime; a refused client receives a readable error it can display, not an opaque server failure.
  • A narrower front door. The unscoped MCP endpoint admits only callers holding the workspace role, checked before any session state is created, and every session is recorded when it opens and when it closes.

The effect is that the question "why could the agent not do that?" has an answer in the record, which is the premise of supervising an agent at all.

See the feature →

← All posts