MCP Ready

Security & trust

The AI gets a controlled path—not a master key.

A trustworthy connection respects the customer’s existing access, limits what each action can do, and asks before important changes.

Your product stays in charge

MCP is a connection standard, not a security guarantee. The implementation must still identify the user, apply your product’s permission rules, protect credentials, and record important actions. Strata designs those controls as part of the product—not as a final checklist.

Five questions we answer before launch

What can the AI see?

Only the systems, records, and fields needed for the chosen customer job.

Whose access is used?

Normally the signed-in customer’s account, so your existing roles and tenant boundaries continue to matter.

What can it change?

Reading, preparing, and acting are separated so broad access is not hidden inside one command.

What needs approval?

Sending, deleting, publishing, paying, or making an important update can show the exact effect before it runs.

What is recorded?

The service keeps an appropriate trail of the user, request, decision, and outcome without putting secrets in logs.

Approval should be specific

Too vague

Allow this tool?

Clear and useful

Send this reminder to Maya for invoice #1842?

State is explicit

Each MCP request carries what it needs and is authorized on its own. When a workflow continues later, a draft, task, subscription, or other explicit reference identifies that work. The reference can be tied to the right user, checked again, expired, and included in the audit trail.

Our launch baseline

  • Start with the smallest useful data and action scope.
  • Use the customer’s existing identity and permissions wherever possible.
  • Keep credentials and unnecessary personal data out of AI-visible results.
  • Test wrong-account access, misleading instructions, retries, failures, and duplicate actions.
  • Provide a clear way to disable access and respond to an incident.

Build trust into the first version

Customers should know what the AI can see and what it can change.

Strata turns that promise into working permissions, approval steps, tests, and operating controls.

Discuss a secure implementation →