Skip to content

[MCP-01] Define tenant, authorization, consent, and audit threat model for MCP tools #2

Description

@jaavid

Background

CoreLink is one product across multiple implementation repositories. This work is owned by mcp-server under EPIC-02.

Goal

Define and accept the tenant, authorization, consent and audit threat model that gates every supported MCP tool surface.

Parent

  • Primary Product Epic: EPIC-02
  • Backlog ID: MCP-01

Scope

  • Define actor/tenant identity and least-privilege authorization semantics for MCP clients and tools.
  • Define explicit consent requirements for sensitive or state-changing operations.
  • Define audit-event requirements, token/secret handling and tenant-isolation failure behavior.
  • Map MCP boundaries to version-identifiable public API/contracts rather than internal runtime access.
  • Provide threat/abuse cases and retained security review evidence.

Out of Scope

  • Implementing the read-only tool surface (MCP-02).
  • Implementing state-changing tools (MCP-03).
  • Treating generic EPIC-02 wording as sufficient evidence without an MCP-specific accepted boundary.

Acceptance Criteria

  • MCP actors, credentials, tenant context and trust boundaries are documented.
  • Least-privilege scope model and denied/cross-tenant behavior are explicit and fail closed.
  • Consent rules distinguish read-only and state-changing/sensitive operations.
  • Audit requirements identify actor, tenant, tool, action, outcome and correlation data without leaking secrets.
  • Token/secret handling, replay, confused-deputy and prompt/tool-abuse cases are addressed.
  • Public API/contract boundaries are identified; unsupported internal-runtime shortcuts are prohibited.
  • Security review/sign-off evidence is linked and EPIC-02 exit criteria are measurably advanced.

Dependencies and acceptance state

  • Product/security input: EPIC-02 actor/authentication/tenancy contract and accepted public API security semantics.
  • Blocks: MCP-02 supported read-only tools; MCP-03 state-changing tools; MCP-04 package/release acceptance; DOCS-04 MCP security guidance; and EPIC-02 MCP security acceptance.
  • Current dependency state: See the CoreLink Product organization Project.

Planning Metadata

  • Type: Technical Task
  • Priority snapshot: P0
  • Product milestone snapshot: Developer Platform
  • Domain snapshots: security, devex
  • Area snapshot: backend
  • Complexity: M
  • Created in status: Triage
  • Current status and DRI: See the CoreLink Product organization Project.
  • Intended repository labels: type:technical-task

Definition of Done

  • Acceptance criteria demonstrated.
  • Threat model and security decision evidence are retained.
  • MCP-02/03/04 dependency semantics are reconciled.
  • Tenant/auth/consent/audit boundaries are reflected in documentation/examples.
  • Any required contract/security changes are linked.
  • Pull request(s) or decision records and review evidence are linked.

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:technical-taskImplementation or engineering enablement work

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions