Model Context Protocol

MCP for the enterprise

The Model Context Protocol (MCP) is becoming the standard way for AI applications to use business systems. Adopted carelessly, it becomes a new, unmanaged attack surface. Engineered properly, it becomes the governed capability layer of your AI platform.

What MCP is

MCP is an open protocol that connects AI applications to external systems. An MCP server exposes three kinds of things: tools (actions the model can call), resources (data it can read) and prompts (reusable instructions). An MCP client — an assistant, an agent or an IDE — discovers and uses them through one consistent interface.

For remote servers, MCP specifies OAuth-based authorization, so access can be tied to a real user identity instead of a shared key.

MCP complements APIs — it does not replace them

Your APIs remain the contract for data and business logic. MCP sits on top, describing those capabilities in a way models can understand and call. In the Cardim Intelligence Stack, MCP is layer 3: above the data platform and APIs, below the tools catalog, skills and agent loops.

How to govern MCP

Treat every MCP server as a production integration with an owner.

  • Registry — one internal list of approved MCP servers, owners, versions and data classification
  • Allow-listing — clients may only connect to registered servers and approved tools
  • Scoped tokens — OAuth with least-privilege scopes, short-lived tokens and on-behalf-of user identity
  • Logging — every tool call recorded with caller, arguments and result, with PII redaction and retention rules
  • Change control — tool descriptions and permissions reviewed like code

Security risks to design for

MCP inherits the risks of letting a model act on your systems.

  • Prompt injection — instructions hidden in documents, emails or web pages that try to steer the model
  • Tool poisoning — malicious or altered tool descriptions that trick the model into unsafe calls
  • Excessive agency — tools with more permissions than the task needs, or actions without human approval
  • Data leakage — sensitive data returned to a model or client that should not see it

How Cardim engineers MCP

We build MCP servers on top of your existing APIs and data platform, integrated with Entra ID or your identity provider, deployed through CI/CD, with a registry, allow-listed tools, scoped permissions, tracing and evaluation from day one. High-risk actions require human confirmation.

MCP questions

Is MCP a replacement for our APIs?

No. MCP describes and exposes capabilities to AI applications. The business logic and data contracts stay in your APIs, which MCP servers call.

Is MCP secure enough for enterprise use?

The protocol supports OAuth-based authorization, but security depends on implementation: least-privilege scopes, allow-listed servers and tools, logging and defenses against prompt injection and tool poisoning.

Can we use MCP with Microsoft Entra ID?

Yes. Remote MCP servers can use Entra ID as the authorization server, so tool calls run with the signed-in user's identity and permissions.

Where should we start?

Pick one well-understood API with clear ownership, wrap a few read-only tools in an MCP server, register it, log every call and evaluate the results before adding write actions.

Want to talk it through?

Tell us where you are today. We'll tell you what it takes to get to production.

Start a conversation