Knowledge · MCP

    The MCP and agent infrastructure checklist

    A practical checklist for evaluating any vendor's MCP or AI-agent claims: connection, discovery, permission, confirmation, execution and evidence.

    How do you evaluate an AI agent integration?

    Test six layers in order on your own account: transport, discovery, authorization, confirmation, execution and evidence. Stop at the first one that fails. Most integrations pass the first two and are described as if they passed all six.

    Key takeaways

    • Test on your own tenant with a low-privilege account, not a demo.
    • Ask for a tool list, then ask which entries have live handlers.
    • Run one destructive-category action and confirm a preview appears.
    • Read the resulting record back through the normal interface.
    • Ask how a duplicate is prevented when the assistant retries.

    The six checks

    • Connection: can you connect as yourself, with consent recorded and revocable.
    • Discovery: what exactly is advertised, and how is that list kept honest.
    • Authorization: does a low-privilege account get refused on a restricted action.
    • Confirmation: does a destructive or outbound action return a preview first.
    • Execution: does the action leave a record you can open in the normal interface.
    • Evidence: does an audit entry name the actor and the authorizing person.

    Questions that produce specific answers

    • Which advertised tools have deployed handlers today?
    • How is the organization determined for a tool call?
    • Which action categories require a second confirmed call?
    • What happens when the same mutation is sent twice?
    • Where do I read the audit record without asking support?

    Red flags

    • A live endpoint offered as proof of capability.
    • A single shared credential for the whole company.
    • Confirmation described as a setting rather than a protocol step.
    • Verification that requires the vendor to look at logs for you.
    • Claims of full parity with a human operator.

    Where URBLD fits

    URBLD publishes a reviewed action catalog rather than an aspirational one, enforces organization derivation and capability mapping server-side, requires a signed confirmation token for destructive, financial, override, bulk and external-send actions, and records agent work in an auditable history an owner can read directly.

    Principles reinforced

    This page rests on the following foundational ideas.

    FAQ

    Frequently Asked Questions

    Straight answers about how URBLD runs the business end-to-end.

    More in MCP

    The protocol that lets AI do work instead of describing it.

    Browse MCP
    Share this page