Use case · By risk
Review an MCP server before relying on it
For teams deciding which agent integrations to use.
A new server adds tools and another place that can receive data. Its name alone does not establish what it can read or change. Create a Work task for the server review. Assign an owner, describe the required tools and data access, and link the server documentation and review evidence.
MCP servers off the org list
Review the proposed MCP integration
- 1
Next action
Check its tools and data access
- 2
Context
Server and documentation
- 3
Evidence
Tools needed for the task
What to put in the task
- Assign the task to the person responsible for the next action.
- Add evidence links and explain what they show in a comment.
- Update the task when the work changes so the next reader has the current state.
Before you rely on it
Command interception depends on your client's hooks or proxy; see the setup guide for Claude Code, Codex, Cursor and other MCP clients.
- A review task does not intercept MCP calls or detect prompt injection. Governed proxy coverage requires separate setup; do not treat a listed server as automatically safe.
- Work must be enabled for the selected account, and you need permission to read or change the task. Security access and device setup are separate.
Related use cases and clients
By riskNetwork off the allowlistThe access decision stays attached to the work that required it.By riskDevice reports and bypassYou can distinguish a reported policy state from a missing receipt and assign the follow-up.By clientAny MCP clientSetup requirements for any MCP client.
All use cases →