Different system
Headless PM coordinates internal project and agent work; it is not the Queast customer platform.
MCP scope review
MCP remains a named, scope-gated integration direction in the Queast v2 plan. Current product evidence does not establish a customer-facing Queast MCP gateway, approved tool catalog, commercial availability, or supported client list.
Evidence state
The canonical site plan names MCP as a scope-gated direction. Every customer-product contract behind that name still requires current evidence and approval.
Evidence boundary
The repository contains an MCP bridge for a separate Headless PM coordination system. It has a different purpose and tool catalog and cannot support Queast customer-product claims.
Headless PM coordinates internal project and agent work; it is not the Queast customer platform.
Its task, document, agent, and service-management tools do not establish Queast company, Workbench, Messaging, SPICED, or Signal access.
Developer access and internal administration cannot be generalized into tenant-user permissions.
An internal client bridge does not prove supported customer clients, hosting, connection method, or commercial availability.
Required access contract
These are requirements for a future customer-facing MCP surface, not claims that a current gateway implements them.
Define authentication, represented tenant and user, credential issuance and revocation, and impersonation controls.
Publish only named tools with declared inputs, outputs, fields, authority, side effects, and availability.
Define the permission and approval check for each read, draft, write, or external side effect.
Specify allowed fields, evidence references, redaction, recorded call context, retention, export, and review.
Tool catalog gate
No customer-facing tool class is approved in the available product evidence. Each class needs an explicit field, permission, side-effect, and availability contract.
Company, person, evidence, Workbench, SPICED, or Actionable Signal reads require a named tool and field contract.
Research summaries, SPICED preparation, and message drafts require source and authority boundaries plus human review.
Saved items, task status, drafts, and other writes require a named action, confirmation policy, and audit contract.
CRM changes, notifications, email, LinkedIn, calls, and generic requests require separate connector and human-control approval.
Tenant or super-admin operations cannot be inferred from internal developer tooling or exposed without explicit approval.
Readiness checklist
Do not configure or publish customer-facing access until each decision has current product evidence and human approval.
Read Tech and SecurityWhich plan, tenant, market, and release state can use MCP?
Where is the server hosted and which connection method is supported?
Which AI clients and versions are approved?
Which credential, tenant binding, role, scope, expiry, rotation, and revocation rules apply?
What is the exact read and write catalog, with fields and side effects per tool?
Which calls require preview, confirmation, or a separate human action?
What is logged, redacted, retained, exportable, and reviewable?
What limits, errors, timeouts, support, incident response, and SLA apply?
Next step
Confirm the gateway, hosting, client, authentication, tool, permission, audit, privacy, and operating contracts against current product evidence.