Explainer

What Is MCP? A Business Guide to Model Context Protocol and AI Agent Tools

Model Context Protocol gives AI applications a standard way to discover tools and resources. It can simplify agent integrations, but it does not replace permissions, workflow design or transaction controls.

MCP is a connection standard

Model Context Protocol, usually shortened to MCP, defines how an AI application can discover and use capabilities exposed by an MCP server. A server may offer tools that perform actions, resources that supply information and prompts that package a recurring interaction. The client could be an agent application, an assistant or a development environment.

The practical attraction is reuse. A team can expose a suitable capability once and connect more than one compatible client. The protocol reduces repeated connector work, but the business still decides what the capability should do and who may use it.

An MCP server is not the business system

An MCP server normally sits between the agent client and an existing application, data source or service. It translates a standard MCP call into the underlying operation. The system of record remains responsible for authoritative data and transaction rules.

For example, an MCP tool may let an agent create a work item in Jira or search a customer record in Salesforce. The server does not automatically know whether creating the work item is appropriate for the current process, whether the customer record may be disclosed or whether a proposed transaction needs approval.

Common MCP server families

Knowledge and search servers expose documentation, policies, repositories or enterprise search. Work-management servers connect tasks, tickets and collaboration systems. Developer servers expose source control, issues, deployment or technical documentation. Customer and commercial servers connect CRM, service or commerce information. Data servers expose governed query or analytical capabilities. Internal servers wrap organisation-specific services, calculations or policy checks.

Representative official offerings include GitHub's MCP server, Atlassian's server for products including Jira and Confluence, Salesforce hosted MCP servers and the Microsoft Learn MCP server. Microsoft Foundry Toolbox and Amazon Bedrock AgentCore Gateway provide managed ways to organise or govern tool access. These examples show the breadth of the ecosystem; they are not endorsements or evidence that every available server is suitable for production.

Local, remote and gateway patterns

A local server runs close to the client and may access local files or development tools. A remote server is hosted behind a network endpoint and is easier to share, update and govern centrally. An MCP gateway can provide a controlled entry point for several servers or convert existing services into MCP-compatible tools.

The choice changes the security and operating model. Local execution can expose a user's machine and credentials. Remote execution requires strong authentication, network controls, service availability and data-location review. A gateway can centralise identity, policy, logging and versioning, but also becomes a critical shared dependency.

MCP does not remove the need for narrow tools

A server with hundreds of broad tools can make the agent less predictable and fill its context with irrelevant definitions. Start with the smallest set needed for the approved workflow. Separate reading from writing and low-consequence updates from material transactions. Use the underlying system to validate limits and current state.

For a customer-service agent, searching policy and reading an order may fit one governed server. Issuing money should remain a narrow action with an amount limit, current-order check, idempotency key and approval condition. Safe tool design still applies when the tool uses MCP.

Authorisation follows the user and the task

Current MCP specifications include an authorisation framework for HTTP-based connections, and commercial servers commonly use OAuth. Authentication proves an identity. The implementation must still decide which user or agent identity acts, which scopes are permitted and whether the tool should act on behalf of a person or as a service.

Treat server trust separately from user trust. Review who operates the server, what it logs, where the server sends data, how tool definitions change and how access can be revoked. Require confirmation or independent approval for material side effects.

MCP and A2A solve different problems

MCP connects an AI client to tools and resources. Agent2Agent, or A2A, addresses communication between independent agents that advertise capabilities and manage tasks together. An organisation does not need A2A merely because one agent calls several tools. The protocol selection guide compares ordinary APIs, MCP and A2A against the actual integration need.

A worked pattern for service recovery

Imagine a service-recovery agent that reads current policy, checks a customer case and creates follow-up work. A knowledge MCP server supplies the approved policy. An official work-management server creates and updates tasks. A CRM server returns only fields the service role may see. The payment adjustment remains behind an internal service with deterministic limits.

The agent receives a scoped identity, and every tool call is traced. A request above the remedy limit pauses for approval. If the task system confirms creation but the response is lost, the workflow checks the authoritative task identifier before retrying. MCP simplifies the connection surface, while ordinary control design makes the workflow safe.

How Marketways supports MCP decisions

Marketways maps the workflow, identifies reusable tool families, compares direct API and MCP routes, defines permissions and side effects, and tests the complete operating sequence. The output is an integration and control design that shows where MCP creates useful reuse and where a narrower conventional interface is more appropriate.

Continue through the implementation practice

References

  1. Model Context Protocol 2026 specification update
  2. OpenAI, MCP servers
  3. GitHub, extending Copilot with MCP
  4. GitHub MCP Server
  5. Atlassian MCP Server
  6. Salesforce hosted MCP servers
  7. Microsoft Learn MCP Server