Read
Search tickets, open a wiki page
Runs without asking once the connection is approved. Every call is logged.
Over the Model Context Protocol (MCP), chat and agents call tools in Jira, Notion or Microsoft 365. Before every call, a policy checks whether it is allowed. Reading runs straight away. Anything that creates or changes something waits for your approval of that exact content.
Request in chat
Open a Jira ticket for the complaint about batch 24-117.
Look for similar tickets
Readjira.search
Create the ticket
Writejira.create_issue
Write the record
Logaudit.log
Approval for this exact content
Log entry
Example with made-up data.
How a call runs
The AI never calls a tool directly. Every call passes a policy check that knows the risk class, the workspace and your settings.
Risk classes
The class is set when the tool is registered, not by the AI mid-conversation. Reading is less risky than changing, so different rules apply.
Search tickets, open a wiki page
Runs without asking once the connection is approved. Every call is logged.
Create a ticket, update a record
Waits for an approval of the exact content. An expired approval is never reused.
Send a message to a third party
Has an effect outside your organisation, so it needs an approval too.
Analyse a table, draw a chart
Runs in a sealed sandbox with no network access.
When a workflow writes to internal systems or triggers something irreversible, the classes internal_write and irreversible apply. You decide whether one or two people approve.
Guided catalogue
In On Demand you choose from a fixed set of vendor MCP servers. You sign in with the vendor over HTTPS and OAuth; credentials live in a separate store and never in the tool description. A connection starts out visible only to you, and you can share it with a workspace afterwards.
Names and marks belong to their vendors. They stand for the servers in the guided catalogue and imply no partnership or certification. The catalogue does not accept addresses in private networks.
Per operating route
In the cloud route you talk to services on the internet. Private Spark keeps a management connection to souveraen.ai by default; Air-Gap Enterprise has no outside connection.
Run by us
Device on your premises
No network link
Which servers are packaged for your local setup is agreed in the project. Not every remote server in the catalogue has a counterpart that runs without the internet.
Compare operating routesThe other direction
The same sourced search that works in chat can be offered to other MCP-capable applications, such as a developer tool or a desktop assistant.
souveraen-search
MCP server · read-only
At most 8 passages per call
The answers describe how MCP tools work in souveraen.ai. What each operating route includes is on the pricing page.
Send us the list. We will tell you which of them are in the catalogue and which risk class their tools would have. Phone +49 3744 365 2202.