Skip to content
souveraen.ai
MCP tools

The AI works inside your business systems. It only changes things with approval.

Over the Model Context Protocol (MCP), chat and agents call tools in Jira, Notion or Microsoft 365. Before every call, a policy checks whether it is allowed. Reading runs straight away. Anything that creates or changes something waits for your approval of that exact content.

  • Checked before every call
  • Writes only with approval
  • Every call logged

Request in chat

Open a Jira ticket for the complaint about batch 24-117.

  1. 1

    Look for similar tickets

    Read

    jira.search

     

  2. 2

    Create the ticket

    Write

    jira.create_issue

     

  3. 3

    Write the record

    Log

    audit.log

     

Approval for this exact content

Project
QS
Type
Complaint
Title
Batch 24-117: hairline crack in housing
Priority
High
Linked
QS-402
ApproveIf the AI changes the content, the approval no longer applies.

Log entry

  • 09:41:12 jira.search read allowed
  • 09:41:37 jira.create_issue write approval A-2291
  • Result: QS-418

Example with made-up data.

How a call runs

There is a check between the AI and your systems.

The AI never calls a tool directly. Every call passes a policy check that knows the risk class, the workspace and your settings.

Checked before every call

A policy decides before the tool runs: allow it, wait for approval, or deny it.

Read call

Read, write, deny

Three paths a call can take. Each one ends in the log, the denied one included.

Tools per workspace

Sales sees Salesforce, Quality sees Jira. You decide which tools each workspace may use.

In chat only when you switch it on

A new connection starts out private. In chat you choose which tool the AI may use for this conversation. Without your choice it calls none.

Calls: 12

Active

Switching off is immediate

A tool that is switched off stays registered. Every further call is denied and logged.

Risk classes

Every tool has a risk class, and the check follows it.

The class is set when the tool is registered, not by the AI mid-conversation. Reading is less risky than changing, so different rules apply.

read

Read

Search tickets, open a wiki page

Runs without asking once the connection is approved. Every call is logged.

write

Write

Create a ticket, update a record

Waits for an approval of the exact content. An expired approval is never reused.

external

External

Send a message to a third party

Has an effect outside your organisation, so it needs an approval too.

compute

Compute

Analyse a table, draw a chart

Runs in a sealed sandbox with no network access.

In fixed workflows, additionally

When a workflow writes to internal systems or triggers something irreversible, the classes internal_write and irreversible apply. You decide whether one or two people approve.

Guided catalogue

20 remote servers you connect in a few clicks.

In On Demand you choose from a fixed set of vendor MCP servers. You sign in with the vendor over HTTPS and OAuth; credentials live in a separate store and never in the tool description. A connection starts out visible only to you, and you can share it with a workspace afterwards.

Atlassian

Jira and Confluence

Microsoft 365

Mail, calendar, files

Notion

Pages and databases

Salesforce

CRM

GitHub

Code and issues

Slack

Messages

HubSpot

CRM

Stripe

Payments

PayPal

Payments

Linear

Issues

Asana

Projects

Monday

Projects

Miro

Whiteboards

Sentry

Error reports

incident.io

Incidents

CircleCI

Build pipelines

Webflow

Websites

Close

Sales

Pulumi

Infrastructure

Cloudflare

Network and DNS

Atlassian

Jira and Confluence

Microsoft 365

Mail, calendar, files

Notion

Pages and databases

Salesforce

CRM

GitHub

Code and issues

Slack

Messages

HubSpot

CRM

Stripe

Payments

PayPal

Payments

Linear

Issues

Asana

Projects

Monday

Projects

Miro

Whiteboards

Sentry

Error reports

incident.io

Incidents

CircleCI

Build pipelines

Webflow

Websites

Close

Sales

Pulumi

Infrastructure

Cloudflare

Network and DNS

Atlassian

Jira and Confluence

Microsoft 365

Mail, calendar, files

Notion

Pages and databases

Salesforce

CRM

GitHub

Code and issues

Slack

Messages

HubSpot

CRM

Stripe

Payments

PayPal

Payments

Linear

Issues

Asana

Projects

Monday

Projects

Miro

Whiteboards

Sentry

Error reports

incident.io

Incidents

CircleCI

Build pipelines

Webflow

Websites

Close

Sales

Pulumi

Infrastructure

Cloudflare

Network and DNS

Atlassian

Jira and Confluence

Microsoft 365

Mail, calendar, files

Notion

Pages and databases

Salesforce

CRM

GitHub

Code and issues

Slack

Messages

HubSpot

CRM

Stripe

Payments

PayPal

Payments

Linear

Issues

Asana

Projects

Monday

Projects

Miro

Whiteboards

Sentry

Error reports

incident.io

Incidents

CircleCI

Build pipelines

Webflow

Websites

Close

Sales

Pulumi

Infrastructure

Cloudflare

Network and DNS

Names and marks belong to their vendors. They stand for the servers in the guided catalogue and imply no partnership or certification. The catalogue does not accept addresses in private networks.

Included

souveraen-search

Our own MCP server for your company knowledge. All its tools only read, respect access rights and return at most eight passages per call.

  • searchSourced search
  • graphRelations
  • mail_readRead mail
  • calendar_readRead calendar
  • table_readRead tables
  • computeCompute in a sandbox, no network

Per operating route

How far a tool reaches depends on where it runs.

In the cloud route you talk to services on the internet. Private Spark keeps a management connection to souveraen.ai by default; Air-Gap Enterprise has no outside connection.

On Demand

Run by us

Tools
Guided catalogue of 20 remote servers, plus souveraen-search and the sandbox
Network path
Outbound HTTPS from the gateway to the vendor
Where servers come from
Pinned vendor addresses, sign-in via OAuth

Private Spark

Device on your premises

Tools
Packaged servers; admins or, depending on permissions, users add more
Network path
No outbound traffic for tools; management connection to souveraen.ai
Where servers come from
Signed packages with pinned arm64 images, nothing fetched at runtime

Air-Gap Enterprise

No network link

Tools
Only servers brought onto the device as a package
Network path
No way out
Where servers come from
Signed packages, installed like any other update

Which servers are packaged for your local setup is agreed in the project. Not every remote server in the catalogue has a counterpart that runs without the internet.

Compare operating routes

The other direction

souveraen.ai as an MCP server for your other applications.

The same sourced search that works in chat can be offered to other MCP-capable applications, such as a developer tool or a desktop assistant.

  • Access per tenant and workspace, with the rights of the person asking
  • Answers come with passages, not as free text
  • Read-only tools; every call is logged

souveraen-search

MCP server · read-only

  • searchread
  • graphread
  • mail_readread
  • calendar_readread
  • table_readread

At most 8 passages per call

Questions

What IT and data protection ask before the first connection.

The answers describe how MCP tools work in souveraen.ai. What each operating route includes is on the pricing page.

Which systems does your team use?

Send us the list. We will tell you which of them are in the catalogue and which risk class their tools would have. Phone +49 3744 365 2202.

Book a call

The Model Context Protocol is an open standard through which an AI calls tools in other programs. Each program describes which tools it offers, what they expect and what they return.

Try it yourself

Start with a tool that only reads.

Connect Notion or Confluence, say, and let the AI search in it. The log then shows you every call before you allow any tool to write.

  1. Create an account1
  2. Connect a tool2
  3. Ask the first question3