Interface contract
MCP, with a ceiling
Care about the permission and the log. The logo on the protocol is the least interesting part.
MCP, the Model Context Protocol, is a contract for how a language model calls tools: what it may see, what it may change, and how each call is logged. A founder should treat an MCP server like an API with production credentials. Without a ceiling you do not have integration. You have a hole in the repository. The refuse-list is the override doctrine: spend, speak as the company, change production, close a judgment you still own.
Override doctrine
What the agent may never do
The charter says what the agent does. The doctrine says what it must refuse. Write it before the first tool that can send, spend, or delete. A named human in the loop is not a substitute if the irreversible act already happened.
- 01
Spend
No spend above a written ceiling. A tool that can pay without a cap is a junior hire with root.
- 02
Speak
Do not speak as the company. Outbound mail, posts, and customer replies stay behind a named person.
- 03
Change production
Do not change production data, deploy, or delete without a gate. Educational MCP servers are not a production catalogue.
- 04
Close judgment
Do not close a judgment the founder still owns. HITL without a refuse-list arrives after the spend.
Connector checklist
Three reads on every server
Auth is optional in the protocol. Least privilege is not. A clean server with no charter is still a hole with nicer plumbing.
- 01
Visibility
What may the model see? Files, mail, money, customer records. If you cannot name it, it is not a contract.
- 02
Mutation
What may it change? Undocumented write paths are the failure. No anonymous tools.
- 03
The log
How is each call recorded? If the log cannot be read on Monday, the weekend already spent.