MCP Supply-Chain Security
Pavri includes an MCP review workspace for teams that want to inventory, inspect, and triage Model Context Protocol servers and their associated risk signals.
Support status
| Area | Status | Notes |
|---|---|---|
| MCP inventory and server detail | Available | Review tenant-scoped MCP assets and their evidence. |
| Review actions (approve / reject / defer) | Available | Available to Admins and Security Analysts. |
| Baseline and drift review | Available | Review the recorded baseline and drift context. |
| Automatic risk-policy enforcement | Not available | Review decisions require an operator action. |
What the page is for
Use the MCP workspace to:
- inventory discovered MCP servers
- inspect server-level findings and metadata
- review baseline context and drift indicators
- approve, reject, or defer servers that need operator review
Current role model
| Role | MCP behavior |
|---|---|
| Admin | Full review access |
| Security Analyst | Full review access |
| Viewer | Read-only inspection with explicit non-mutating states |
Current product boundaries
The MCP workspace supports manual review and triage. Its operating boundaries are:
- richer baseline and drift explanation
- stronger evidence/rationale capture during review
- automatic restriction based on risk score or findings severity
- tighter linkage between MCP review state and broader governance policy
Use the MCP workflow for manual review and triage. Do not assume it automatically changes runtime policy or restricts a server based only on a risk score.