Integration directory

MCP scope review

Review the MCP contract before connecting an AI client

MCP remains a named, scope-gated integration direction in the Queast v2 plan. Current product evidence does not establish a customer-facing Queast MCP gateway, approved tool catalog, commercial availability, or supported client list.

Evidence state

Treat the route as approved—not the access

The canonical site plan names MCP as a scope-gated direction. Every customer-product contract behind that name still requires current evidence and approval.

VerifiedCanonical route
Verified in the authoritative v2 sitemap and structure plan.
UnverifiedCustomer availability
No approved plan, tenant, market, or release state.
UnverifiedGateway and hosting
No customer-facing server, hosting, or transport contract is established by current product evidence.
UnverifiedAccess model
Authentication, tenant binding, roles, scopes, credential lifecycle, and client support are unverified.
Not approvedTools and audit
The read/write catalog, fields, side effects, approval, audit, privacy, and operating behavior are unapproved.

Evidence boundary

Do not use internal developer tooling as product proof

The repository contains an MCP bridge for a separate Headless PM coordination system. It has a different purpose and tool catalog and cannot support Queast customer-product claims.

01

Different system

Headless PM coordinates internal project and agent work; it is not the Queast customer platform.

02

Different tools

Its task, document, agent, and service-management tools do not establish Queast company, Workbench, Messaging, SPICED, or Signal access.

03

Different authority

Developer access and internal administration cannot be generalized into tenant-user permissions.

04

No compatibility inference

An internal client bridge does not prove supported customer clients, hosting, connection method, or commercial availability.

Required access contract

Approve the boundary before approving tools

These are requirements for a future customer-facing MCP surface, not claims that a current gateway implements them.

Required

Identity and tenant

Define authentication, represented tenant and user, credential issuance and revocation, and impersonation controls.

Required

Closed tool catalog

Publish only named tools with declared inputs, outputs, fields, authority, side effects, and availability.

Required

Live authorization

Define the permission and approval check for each read, draft, write, or external side effect.

Required

Data and audit boundary

Specify allowed fields, evidence references, redaction, recorded call context, retention, export, and review.

Tool catalog gate

Keep every tool class unapproved until named

No customer-facing tool class is approved in the available product evidence. Each class needs an explicit field, permission, side-effect, and availability contract.

  1. 01Not approved

    Retrieve context

    Company, person, evidence, Workbench, SPICED, or Actionable Signal reads require a named tool and field contract.

  2. 02Not approved

    Prepare output

    Research summaries, SPICED preparation, and message drafts require source and authority boundaries plus human review.

  3. 03Not approved

    Change Queast state

    Saved items, task status, drafts, and other writes require a named action, confirmation policy, and audit contract.

  4. 04Not approved

    Act outside Queast

    CRM changes, notifications, email, LinkedIn, calls, and generic requests require separate connector and human-control approval.

  5. 05Not approved

    Administrative access

    Tenant or super-admin operations cannot be inferred from internal developer tooling or exposed without explicit approval.

Artifact authority

Keep the same authority across the client boundary

MCP access cannot make missing evidence true, activate a Composite Intent, satisfy eligibility, or raise the authority of any artifact it retrieves or formats.

  1. 01

    Source evidence

    The observation keeps its source, date, and provenance.

  2. 02

    Analysis

    Interpretation remains separate and may connect supported inputs across time.

  3. 03

    Composite Intent

    The company-level hypothesis keeps its lifecycle, conflicts, and provenance.

  4. 04

    Actionable Signal

    Only a recommendation that passed the applicable eligibility contract carries strict Signal authority.

  5. 05

    Approved tool result

    A future named tool may expose only approved fields at the artifact’s existing authority.

  6. 06

    Client response

    The client may explain or format approved context without inventing evidence or removing uncertainty.

  7. 07

    Human action

    Action remains a separate decision unless a narrowly approved write tool and confirmation policy explicitly state otherwise.

Readiness checklist

Confirm the complete MCP contract

Do not configure or publish customer-facing access until each decision has current product evidence and human approval.

Read Tech and Security
  1. 1

    Availability

    Which plan, tenant, market, and release state can use MCP?

  2. 2

    Hosting and transport

    Where is the server hosted and which connection method is supported?

  3. 3

    Clients

    Which AI clients and versions are approved?

  4. 4

    Authentication

    Which credential, tenant binding, role, scope, expiry, rotation, and revocation rules apply?

  5. 5

    Tools and fields

    What is the exact read and write catalog, with fields and side effects per tool?

  6. 6

    Approval

    Which calls require preview, confirmation, or a separate human action?

  7. 7

    Audit and privacy

    What is logged, redacted, retained, exportable, and reviewable?

  8. 8

    Operations

    What limits, errors, timeouts, support, incident response, and SLA apply?

Next step

Verify MCP availability with Queast

Confirm the gateway, hosting, client, authentication, tool, permission, audit, privacy, and operating contracts against current product evidence.