Skip to content

[MCP-03] Add explicit, auditable, policy-gated state-changing tools #4

Description

@jaavid

Background

CoreLink is one product across multiple implementation repositories. This work is owned by mcp-server under EPIC-02.

Problem

The repository does not yet provide a supported, reproducible and acceptance-tested way to add explicit, auditable, policy-gated state-changing tools.

Goal

Add explicit, auditable, policy-gated state-changing tools, aligned with tagged contracts and the shared CoreLink release train.

Parent

  • Primary Product Epic: EPIC-02
  • Backlog ID: MCP-03

Scope

  • Deliver the title outcome inside mcp-server.
  • Reconcile contract version, authentication, tenancy, error, compatibility, packaging and documentation behavior where applicable.
  • Retain evidence for the Post-Beta gate.

Out of Scope

  • Hand-written divergence from the normative contracts.
  • Unsupported production claims before an artifact and conformance evidence exist.
  • A separate repository roadmap.

Acceptance Criteria

  • The outcome is reproducible from documented inputs and tagged dependencies.
  • Expected, error, retry/recovery and compatibility behavior is verified.
  • Authentication, tenant context and sensitive-data handling are safe where applicable.
  • Installable artifacts or explicit scaffold status are documented accurately.
  • Examples and documentation are versioned and runnable.
  • Conformance evidence is linked to the parent Epic.

Technical Notes

Generated artifacts must identify immutable contract provenance. Security-sensitive tools use least privilege, explicit consent, audit and safe token handling. Package channels must distinguish prerelease from stable.

Dependencies

  • Blocked by: MCP-01, MCP-02 and customer evidence
  • Blocks: Resolved during refinement.
  • Cross-repository: Link concrete contract, mock, documentation and release Issues.

Planning Metadata

  • Type: Feature
  • Priority: P2
  • Product milestone: Post-Beta
  • Domains: security, devex
  • Area: backend
  • Complexity: L
  • Initial status: Triage
  • DRI: Unassigned
  • Intended labels: type:feature, priority:p2, domain:security, domain:devex, area:backend

Definition of Done

  • Acceptance criteria demonstrated.
  • Tests/conformance and required evidence pass.
  • Contracts are updated or confirmed unaffected.
  • Security and tenancy boundaries are reviewed.
  • Packaging, provenance and rollback are verified.
  • Documentation and release notes are updated.
  • Pull request(s) are merged and linked.

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:featureUser-visible product capability or outcome

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions