MCP Supply-Chain Security
Pavri includes an MCP review workspace for teams that want to inventory, inspect, and triage Model Context Protocol servers and their associated risk signals.
Current readiness
| Area | Status | Notes |
|---|---|---|
| MCP inventory and server detail | Preview | The dashboard supports meaningful triage and review flows. |
| Review actions (approve / reject / defer) | Preview | Available to Admins and Security Analysts. |
| Baseline and drift review | Preview | Present in the UI, but still lighter than the full roadmap workflow. |
| Automatic risk-policy enforcement | Planned | Threshold-based restriction and policy-driven MCP gating are not yet first-class workflows. |
What the page is for
Use the MCP workspace to:
- inventory discovered MCP servers
- inspect server-level findings and metadata
- review baseline context and drift indicators
- approve, reject, or defer servers that need operator review
Current role model
| Role | MCP behavior |
|---|---|
| Admin | Full review access |
| Security Analyst | Full review access |
| Viewer | Read-only inspection with explicit non-mutating states |
Current product boundaries
The MCP review surface is now more honest and easier to operate than it was before P4-S4, but it is still not the entire Phase 2/4 vision. The main missing pieces are:
- richer baseline and drift explanation
- stronger evidence/rationale capture during review
- automatic restriction based on risk score or findings severity
- tighter linkage between MCP review state and broader governance policy
Use the current MCP workflow for manual review and triage. Treat automatic risk-policy enforcement and full supply-chain automation as planned roadmap capabilities rather than current product behavior.