Skip to main content

MCP Supply-Chain Security

Pavri includes an MCP review workspace for teams that want to inventory, inspect, and triage Model Context Protocol servers and their associated risk signals.

Support status

AreaStatusNotes
MCP inventory and server detailAvailableReview tenant-scoped MCP assets and their evidence.
Review actions (approve / reject / defer)AvailableAvailable to Admins and Security Analysts.
Baseline and drift reviewAvailableReview the recorded baseline and drift context.
Automatic risk-policy enforcementNot availableReview decisions require an operator action.

What the page is for

Use the MCP workspace to:

  • inventory discovered MCP servers
  • inspect server-level findings and metadata
  • review baseline context and drift indicators
  • approve, reject, or defer servers that need operator review

Current role model

RoleMCP behavior
AdminFull review access
Security AnalystFull review access
ViewerRead-only inspection with explicit non-mutating states

Current product boundaries

The MCP workspace supports manual review and triage. Its operating boundaries are:

  • richer baseline and drift explanation
  • stronger evidence/rationale capture during review
  • automatic restriction based on risk score or findings severity
  • tighter linkage between MCP review state and broader governance policy

Use the MCP workflow for manual review and triage. Do not assume it automatically changes runtime policy or restricts a server based only on a risk score.