InsightsIntegration boundaries

MCP integration security: what to check before connecting

A practical review of MCP identities, scopes, source permissions, tool actions, revocation, and suggested learning before connecting company knowledge.

An MCP integration makes capabilities available to a compatible AI client. Whether those capabilities are appropriate for a user, company, or task remains an application security decision. Connecting successfully is the beginning of verification, not its conclusion.

Before exposing company knowledge, identify the client, the user or connection identity, the allowed resources, and any tool that can change state. Separate a read-only source lookup from an action that publishes knowledge or modifies another system.

Write down the trust boundaries

List which parts you operate and which are controlled by other providers: the AI client, MCP endpoint, identity service, source store, and downstream tools. Note where credentials are issued, validated, stored, and revoked.

The MCP authorization specification describes authorization for the applicable protocol context. Check the deployed transport and supported client against the current requirements. Do not assume that one internal credential pattern establishes interoperability with every external client.

Define capabilities in business terms

Names such as search or write are too broad for a permission review. Ask what can be searched, whose documents are available, and what a write actually creates.

In Narravo's documented implementation, company-scoped connections expose approved context and source retrieval with bounded permissions. Suggested knowledge enters a review inbox rather than immediately replacing approved facts. That separation makes the consequences of a capability easier to understand.

Scroll sideways to view the full table.

CapabilityBoundary to verify
Retrieve company contextCorrect company and approved knowledge scope
Search sourcesUser or connection permissions applied before return
Read a sourceNo access through guessed identifiers
Submit a suggestionCreates reviewable candidate knowledge only
Publish or change a recordSeparately authorized consequential action

These checks describe a review method. They are not a claim that every MCP server uses Narravo's permission model.

Treat returned documents as untrusted content

A document can contain instructions aimed at the model. The application should treat those words as information from a source, not as authority to change credentials, expand permissions, or invoke an unrelated tool.

Keep server-side access checks independent of model choices. Review what data is actually returned to the client, because a prompt saying "do not reveal this" cannot undo disclosure that has already occurred.

The official MCP security guidance discusses protocol-level risks, including token handling. Use it alongside a review of your application and downstream systems; no single checklist establishes security for the entire deployment.

Test revocation and cross-company access

Create a test connection for one company and attempt to retrieve another company's known source identifier. The expected result is denial, not a plausible empty answer that conceals a missing check.

Revoke a connection and verify that subsequent requests are denied according to the intended revocation policy. Test expired credentials, malformed arguments, and requests for unpublished source states. Decide what should be recorded for investigation without logging unnecessary source content or secrets.

Narravo's project record includes checks for authentication errors, revocation, read-only behavior, and source isolation. Those support its engineering story; they are not a certification or a universal test result for other products.

Verify the deployed connection

A local protocol test cannot establish that a proxy, production database, or identity configuration behaves correctly. Exercise discovery, an allowed request, a denied request, and a revoked request against the actual deployment with approved test data.

Keep a clear owner for incidents and credential changes. Document how to disable the connection and how to distinguish a client failure from an application failure.

If you are connecting business knowledge to AI tools, MCP integration development can help define a capability boundary first. The companion company knowledge article explains the context-and-review loop before the security review.

Prepared with AI assistance using Paul’s documented project work and the linked sources. Examples are illustrative unless identified as project records.

Sources & further reading

Your next useful system

What could work
better?

Bring the business problem.
We’ll figure out the right next move.

Discuss a project