Skip to content

MCP Governance Composer for Agent Tooling

Compose managed MCP governance packs with allow/deny lists, approval boundaries, and operator rollout checklists

MCP Governance Composer for Agent Tooling

Governance policy generated

{
  "mode": "allow-list",
  "summary": {
    "serverCount": 3,
    "highRiskServers": 1,
    "reviewRequired": [
      "filesystem"
    ]
  },
  "managedMcp": {
    "version": 1,
    "defaultEnabled": false,
    "servers": {
      "filesystem": {
        "enabled": false,
        "requiresApproval": true
      },
      "docs-search": {
        "enabled": true,
        "requiresApproval": false
      },
      "release-notes": {
        "enabled": true,
        "requiresApproval": false
      }
    }
  },
  "toolPolicy": {
    "defaultAction": "ask",
    "allow": [
      "docs-search",
      "release-notes"
    ],
    "deny": [
      "filesystem"
    ],
    "reviewRequired": [
      "filesystem"
    ]
  },
  "operatorChecklist": [
    "Confirm deny/review list with security owner.",
    "Enable managed policy rollout in read-only dry run first.",
    "Promote to enforce mode after 24h clean telemetry."
  ]
}

Updated . Provided as is. Check the output before you rely on it in production.

How to use MCP Governance Composer for Agent Tooling

  1. 1

    Paste MCP server inventory JSON

    Open the tool and paste your MCP server object in the editor. You can use either a root map of servers or an object with an mcpServers key.

  2. 2

    Choose governance mode and run compose

    Select allow-list, approve-on-write, or observe mode, then run Compose Governance. The mode controls default enablement and approval posture.

  3. 3

    Review high-risk and approval-required sets

    Inspect summary counts, reviewRequired list, and generated allow or deny buckets to confirm policy intent before rollout.

  4. 4

    Copy managed policy output into runtime config

    Copy the generated managedMcp and toolPolicy output and apply it to your governance configuration repository or deployment pipeline.

Questions and answers

What is MCP Governance Composer?
MCP governance is the set of rules deciding which Model Context Protocol servers an agent may use and which need approval. Paste an mcpServers JSON block and this tool flags high-risk servers by name and config, then outputs a managed policy, allow, deny and review lists, and an operator checklist.
How are high-risk servers identified?
The tool scans server names and config hints for sensitive capabilities such as shell execution, file writes, destructive commands, and unrestricted network actions. Matching entries are marked for approval review.
Does MCP Governance Composer store or send my data?
No. Processing runs in your browser. Your server definitions are not uploaded or persisted by the tool.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/mcp-governance-composer/

For automation planning, fetch the canonical contract at /api/tool/mcp-governance-composer.json.