Skip to content

MCP ecosystem

Connect your tools
without handing over
control.

Over the Model Context Protocol, souveraen.ai reaches the systems your teams work in: the ticket system, the wiki, the CRM, the database. Every tool comes from the reviewed Marketplace and only goes live once you approve it.

  • A reviewed Marketplace
  • No change without approval
  • Every call logged
Business systems run through a reviewed MCP broker into an approved workspace

How it goes

Set it up once,
then use it every day.

Your IT team does the first three once. Your team lives the fourth one every day.

What we check beforehand
  1. 1

    Pick a tool

    Your IT team searches the Marketplace for the tool a team needs, the ticket system or the wiki, say.

  2. 2

    Set the scope

    You see the schema, the risk class and the permissions the tool asks for, and you narrow the scope to one tenant and one workspace.

  3. 3

    Give approval

    Nothing connects until you approve it. Without your approval the server stays in the catalogue and never runs.

  4. 4

    Use it and read it back

    The team works with the tool, every call appears in the log, and every change leaves a record in the approval inbox.

What MCP is in souveraen.ai

Every tool arrives with its own limits.

A tool is registered as an MCP server, and in doing so it states which calls it accepts, how risky they are and which workspace it belongs to.

One tool, one schema

Because what a tool expects and returns is written down, the agent cannot call it however it sees fit.

Sorted by risk

A tool is given its risk class when it is registered. Reading calls and calls that make changes then follow different rules.

Tied to permissions

A connection holds for one tenant and one workspace. It is not a general door into another system.

Nothing runs unnoticed

Every call is logged and every change produces a record. Withdrawing an approval takes effect at once, not at the next restart.

One way in, not many endpoints

Everything passes through one place.

Every approved server runs through one internal broker. The platform opens no arbitrary endpoints to the outside, names are qualified uniquely per server, and a single tool can be switched off without exposing the rest of the same connection.

  • Unambiguous tool names
  • Switchable one by one
  • Withdrawal takes effect at once
Many tools run into the platform through a single reviewed broker

Reading and changing

Looking something up is less risky than changing it.

So we treat the two differently: a tool that only reads need not ask. The moment one changes something in your own system, you decide first.

AspectReading toolsTools that make changes
What happensThe tool fetches information and reports back.The tool changes something in your own system.
Before the callThe connection is already bound before the agent plans.You see the change it intends to make as a preview.
ApprovalGranted with the approval of the connection.Also required for each individual case.
AfterwardsThe call appears in the log, with the passages it used.A record lands in the approval inbox.

The sourced search across your company knowledge is itself connected as an MCP tool. Approved third-party applications can use it, and the passages come with it.

The MCP Marketplace

The tools your team already uses.

Many vendors support the protocol. Which servers run at your site is settled by the admission review and by your own approval in your tenant.

See the integrations

GitHub

  • Code
  • Reading

Jira

  • Issues
  • Changing

Confluence

  • Wiki
  • Reading

Notion

  • Notes
  • Reading

Salesforce

  • CRM
  • Changing

SharePoint

  • Files
  • Reading

MongoDB

  • Data
  • Reading

Grafana

  • Metrics
  • Reading

Docker

  • Operations
  • Changing

Examples from the MCP ecosystem, with the product marks of the respective vendors. They are not partnerships, certifications or confirmed compatibilities, and say nothing about an integration being in place. Availability, permissions and approval are checked per server in your tenant.

Admission review

What a server has been through before you see it.

A public directory lists whoever has registered. For the Marketplace we review every server ourselves and write down the result.

  • Every server is reviewed before admission; origin, version, digest and transport are recorded.
  • For local operation, servers are qualified on arm64, mirrored and pinned to a fixed digest.
  • The reviewed servers sit in the signed offline package of the appliance. No server is fetched at runtime.
  • Outbound traffic is denied by default for every server; only what the tool genuinely needs is allowed.
  • Credentials live in the approved credential store, not in the tool definition.

Different per operating model

How far a tool reaches depends on where it runs.

No external broker service is involved without the explicit approval of your tenant.

Compare the operating models
Operating modelWhere the servers come fromWhat that means for you
Private SparkReviewed, mirrored and pinned servers from the offline package.No internet connection needed.
Air-Gap EnterpriseThe same servers, delivered in the signed offline package.Completely sealed off.
European On DemandA hosted broker service in addition, optional.Only after a review of data residency, data processing, sub-processors, credential custody and deletion.

Common questions

What usually comes up before the first approval.

Can we use any MCP server from the internet?

Not unreviewed. We admit servers after a documented review, mirror them and pin them to a fixed digest. An entry in a public directory is not a sufficient basis for trust.

Does the appliance fetch tools from the network?

No. For Private Spark the reviewed servers sit in the signed offline package. Fetching anything at runtime is ruled out.

Can an agent change something in our systems without asking?

No. Reading tools fetch information and report back. Tools that make changes are tied to an approval: you see the change it intends to make beforehand and get a record afterwards.

Can anyone in the company connect something from the Marketplace?

No. The Marketplace shows reviewed servers. One of them goes live only after an approval in your tenant, which only the roles you designate for it can grant.

How does this differ from an integration connector?

An integration reads a file store into your knowledge base. An MCP tool carries out a single call in one of your systems. The two are kept apart.

Is souveraen.ai available as an MCP server for other applications?

Yes. souveraen.ai offers its sourced search as an MCP tool, so approved third-party applications can use it. Access holds for one tenant and one workspace, and brings its passages with it.

MCP ecosystem

Which tools should join in?

Send us the list of systems your team uses every day. We will check which of them are already in the Marketplace and what permissions they would run with in your tenant.