Tool & Runtime Security

MCP & Tool Security

Decide which agent may call which tool.

MCP gives agents capability. Xybern decides authority: which agent may reach which MCP server, which tool it may call, with what arguments, under what conditions and for how long. Every call is evaluated before it runs. MCP provides capability, Xybern provides authority.

Server and tool scope

Grant access to specific MCP servers and specific tools, not blanket capability. One agent may reach the finance server while another cannot, and a read tool can be allowed while a transfer tool is blocked.

  • Per-agent access to named MCP servers
  • Allow a read tool, block a write tool
  • No standing, all-tools access

Argument-level charter

Authorisation looks at the arguments, not just the tool. A transfer can be permitted only below a limit and only to approved counterparties, evaluated at the intercept before the call runs.

  • Constrain amounts, destinations and parameters
  • Context-aware rules, not just allow-lists
  • Checked before execution, not after

Delegation enforced through the chain

Access granted to one agent cannot silently propagate to another. Delegation rules apply to tool calls exactly as they do to any other action.

  • Tool access does not spread down a chain
  • Same boundary as every other action
  • Every call sealed to the vault

More in Tool & Runtime Security.

Related capabilities on the same authorisation layer. Every one is enforced before an action runs and sealed to the Provenance Vault.

1.0AI Gateway

Authorise every model call.

Learn more
2.0Runtime Containment

Contain or kill any agent, instantly.

Learn more
3.0Breakglass

Emergency access without invisible exceptions.

Learn more
4.0Temporal Windows

Authority that only exists when it should.

Learn more

See MCP & Tool Security in your workflow.

Put one workflow behind Xybern and watch every agent action authorised, and sealed to the vault.