Skip to content

[MCP-01] Define tenant, authorization, consent, and audit threat model for MCP tools #2

Description

@jaavid

Background

CoreLink is one product across multiple implementation repositories. This work is owned by mcp-server under EPIC-02.

Goal

Define and accept the tenant, authorization, consent and audit threat model that gates every supported MCP tool surface.

Parent

  • Primary Product Epic: EPIC-02
  • Backlog ID: MCP-01

Scope

  • Define actor/tenant identity and least-privilege authorization semantics for MCP clients and tools.
  • Define explicit consent requirements for sensitive or state-changing operations.
  • Define audit-event requirements, token/secret handling and tenant-isolation failure behavior.
  • Map MCP boundaries to version-identifiable public API/contracts rather than internal runtime access.
  • Provide threat/abuse cases and retained security review evidence.

Out of Scope

  • Implementing the read-only tool surface (MCP-02).
  • Implementing state-changing tools (MCP-03).
  • Treating generic EPIC-02 wording as sufficient evidence without an MCP-specific accepted boundary.

Acceptance Criteria

  • MCP actors, credentials, tenant context and trust boundaries are documented.
  • Least-privilege scope model and denied/cross-tenant behavior are explicit and fail closed.
  • Consent rules distinguish read-only and state-changing/sensitive operations.
  • Audit requirements identify actor, tenant, tool, action, outcome and correlation data without leaking secrets.
  • Token/secret handling, replay, confused-deputy and prompt/tool-abuse cases are addressed.
  • Public API/contract boundaries are identified; unsupported internal-runtime shortcuts are prohibited.
  • Security review/sign-off evidence is linked and EPIC-02 exit criteria are measurably advanced.

Dependencies and acceptance state

  • Product/security input: EPIC-02 actor/authentication/tenancy contract and accepted public API security semantics.
  • Blocks: MCP-02 supported read-only tools; MCP-03 state-changing tools; MCP-04 package/release acceptance; DOCS-04 MCP security guidance; and EPIC-02 MCP security acceptance.
  • Current dependency state: See the CoreLink Product organization Project.

Planning Metadata

  • Type: Technical Task
  • Priority snapshot: P0
  • Product milestone snapshot: Developer Platform
  • Domain snapshots: security, devex
  • Area snapshot: backend
  • Complexity: M
  • Created in status: Triage
  • Current status and DRI: See the CoreLink Product organization Project.
  • Intended repository labels: type:technical-task

Definition of Done

  • Acceptance criteria demonstrated.
  • Threat model and security decision evidence are retained.
  • MCP-02/03/04 dependency semantics are reconciled.
  • Tenant/auth/consent/audit boundaries are reflected in documentation/examples.
  • Any required contract/security changes are linked.
  • Pull request(s) or decision records and review evidence are linked.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:technical-taskImplementation or engineering enablement work

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions