An MCP integration makes capabilities available to a compatible AI client. Whether those capabilities are appropriate for a user, company, or task remains an application security decision. Connecting successfully is the beginning of verification, not its conclusion.
Before exposing company knowledge, identify the client, the user or connection identity, the allowed resources, and any tool that can change state. Separate a read-only source lookup from an action that publishes knowledge or modifies another system.
Write down the trust boundaries
List which parts you operate and which are controlled by other providers: the AI client, MCP endpoint, identity service, source store, and downstream tools. Note where credentials are issued, validated, stored, and revoked.
The MCP authorization specification describes authorization for the applicable protocol context. Check the deployed transport and supported client against the current requirements. Do not assume that one internal credential pattern establishes interoperability with every external client.
Define capabilities in business terms
Names such as search or write are too broad for a permission review. Ask what can be searched, whose documents are available, and what a write actually creates.
In Narravo's documented implementation, company-scoped connections expose approved context and source retrieval with bounded permissions. Suggested knowledge enters a review inbox rather than immediately replacing approved facts. That separation makes the consequences of a capability easier to understand.
Scroll sideways to view the full table.
| Capability | Boundary to verify |
|---|---|
| Retrieve company context | Correct company and approved knowledge scope |
| Search sources | User or connection permissions applied before return |
| Read a source | No access through guessed identifiers |
| Submit a suggestion | Creates reviewable candidate knowledge only |
| Publish or change a record | Separately authorized consequential action |
These checks describe a review method. They are not a claim that every MCP server uses Narravo's permission model.
Treat returned documents as untrusted content
A document can contain instructions aimed at the model. The application should treat those words as information from a source, not as authority to change credentials, expand permissions, or invoke an unrelated tool.
Keep server-side access checks independent of model choices. Review what data is actually returned to the client, because a prompt saying "do not reveal this" cannot undo disclosure that has already occurred.
The official MCP security guidance discusses protocol-level risks, including token handling. Use it alongside a review of your application and downstream systems; no single checklist establishes security for the entire deployment.
Test revocation and cross-company access
Create a test connection for one company and attempt to retrieve another company's known source identifier. The expected result is denial, not a plausible empty answer that conceals a missing check.
Revoke a connection and verify that subsequent requests are denied according to the intended revocation policy. Test expired credentials, malformed arguments, and requests for unpublished source states. Decide what should be recorded for investigation without logging unnecessary source content or secrets.
Narravo's project record includes checks for authentication errors, revocation, read-only behavior, and source isolation. Those support its engineering story; they are not a certification or a universal test result for other products.
Verify the deployed connection
A local protocol test cannot establish that a proxy, production database, or identity configuration behaves correctly. Exercise discovery, an allowed request, a denied request, and a revoked request against the actual deployment with approved test data.
Keep a clear owner for incidents and credential changes. Document how to disable the connection and how to distinguish a client failure from an application failure.
If you are connecting business knowledge to AI tools, MCP integration development can help define a capability boundary first. The companion company knowledge article explains the context-and-review loop before the security review.
Prepared with AI assistance using Paul’s documented project work and the linked sources. Examples are illustrative unless identified as project records.