Machine intelligence · Agentic AI · Governed swarm management

Protocol guide · MCP 2026-07-28

Model Context Protocol: scope, controls, and enterprise use

MCP standardizes a connection surface between model applications and contextual capabilities. It does not decide which business actions are allowed, which identity should act, how outputs are evaluated, how spend is bounded, or who retains human authority.

EnterpriseGovernmentPartners

Published Updated Reviewed By LongTermIntelligence.com

Direct answer

What is the Model Context Protocol?

#

MCP is an open protocol for connecting language-model applications with external contextual capabilities. In the reviewed 2026-07-28 specification, a host manages one or more clients that communicate with servers exposing capabilities such as resources, prompts, and tools. MCP standardizes communication; it does not provide complete governance, authorization, evaluation, budgeting, recovery, or human approval.

  • Use MCP to reduce one-off integration contracts.
  • Keep server discovery, identity, authorization, tool policy, and execution isolation explicit.
  • Record the exact protocol version and capabilities implemented.

Source basis: reviewed official references are listed on this page and in the source ledger. Interpretation and implementation guidance retain the stated assurance boundary.

Page role

Use this guide as the versioned protocol reference

This page summarizes the reviewed MCP specification, host-client-server roles, capability boundaries, and production review questions. It is the canonical standards page for protocol scope; the linked Field Note carries the broader architectural argument.

  • Confirm the exact specification version implemented.
  • Use the checklist to review servers, tools, data, identity, and execution isolation.
  • Do not infer governance or safe business action from protocol conformance.

Architectural boundary

MCP capability versus control-plane responsibility

The cleanest design treats MCP as one protocol inside a larger operating system.

ConcernMCP contributionSurrounding responsibility
Connection modelDefines host, client, server, messages, and capabilities.Choose deployment topology, trust boundaries, network policy, tenancy, and ownership.
Resources and promptsProvides standardized ways to expose context and reusable prompts.Classify data, authorize access, preserve provenance, redact sensitive content, and govern retention.
ToolsProvides a mechanism for servers to describe callable capabilities.Approve tools, validate parameters, limit side effects, sandbox execution, and require human authority where needed.
Identity and authorizationSupports protocol-level mechanisms and implementation choices.Issue task-scoped identities, enforce least privilege and least agency, rotate credentials, and audit delegation.
ObservabilityCreates protocol events that can be instrumented.Define traces, metrics, redaction, retention, evaluation, alerts, and incident procedures.
ReliabilityStructures requests and responses.Design retries, idempotency, checkpoints, circuit breakers, fallbacks, budgets, and recovery.

MCP production review

Questions before connecting an MCP server

A server expands the system boundary and supply chain.

  • Who owns and operates the server, and how is its software provenance verified?
  • Which resources, prompts, and tools are exposed, and to which agent identities?
  • Are tool schemas and side effects typed, validated, and independently authorized?
  • Can untrusted content influence instructions or tool parameters?
  • Where does code execute, what network egress is allowed, and how is the environment isolated?
  • What data can leave the host, server, tenant, or jurisdiction?
  • How are messages traced without recording unnecessary secrets or personal data?
  • What happens when the server is unavailable, compromised, changed, or removed?
  • Which protocol and implementation versions are recorded in the AIBOM?

Primary-source basis

Official references

Verify the version, status, and scope in the named primary sources before implementation or publication.

Model Context Protocol · Official Protocol Specification

Model Context Protocol Specification — 2026-07-28

The reviewed MCP specification defines an open protocol for connecting language-model applications with contextual resources, prompts, and tools through host, client, and server roles.

Status
Current Reviewed Version
Published
2026-07-28
Reviewed
2026-08-01

Use boundary: MCP is an interoperability protocol, not a complete agentic control plane, governance program, or security guarantee.

Open official source

Model Context Protocol · Official Protocol Guide

Model Context Protocol architecture

Official architectural orientation for MCP components and message flows.

Status
Current
Reviewed
2026-08-01

Use boundary: Treat implementation and security controls as separate design responsibilities.

Open official source

OWASP GenAI Security Project · Official Security Taxonomy

OWASP Top 10 for Agentic Applications

A community-developed taxonomy covering ten major agentic application risk areas, from goal hijacking and tool misuse through memory poisoning, cascading failures, and rogue agents.

Status
Current
Published
2025-12-09
Reviewed
2026-08-01

Use boundary: Use as a threat-oriented taxonomy and mitigation aid, not as a certification or guarantee of security.

Open official source

Official-source citations establish provenance and scope. They do not establish LongTermIntelligence.com certification, endorsement, legal advice, client outcomes, or a guarantee that a control is effective.

Private local search

Find machine intelligence, agentic AI, swarm management, services, industries, use cases, definitions, or research

Press / to open search when focus is not in a form field.

Search runs locally against the public site index.