<aside> 🔌
This guide explains the value of MCP in CM, how to connect an approved AI assistant, and how access, actions and audit are controlled. It is written for platform administrators and security reviewers.
MCP is in beta and off by default. Nothing described here is active on your instance until Corlytics enables it and your platform administrator turns it on.
</aside>
MCP (Model Context Protocol) is a standard way for an AI assistant to connect to a system and work inside it. CM exposes an MCP endpoint inside your own instance, so an assistant your organization already approved can work with your policies on your behalf.
That covers general assistants such as Microsoft Copilot, ChatGPT, Claude, and Amazon Q; domain assistants such as Harvey; workspace tools such as Notion; and developer tools such as Cursor. Any client that speaks MCP can connect, so this is not a vendor allowlist.
For MCP connections, your approved AI assistant provides the model and generates the answer. CM controls what it can see and do, enforces existing workflow rules, and records tool activity.
| CM stands behind | You stand behind |
|---|---|
| Permission scoped content, source version, citations, permitted actions, workflow enforcement, and the audit record | Choice and approval of the AI assistant, model behavior, generated wording, and how the output is used |
One connection works with any MCP compatible assistant, so you do not need a separate integration per AI vendor.
MCP can help with three levels of work, from finding policy evidence to carrying out policy and platform tasks.
| Level | Who it is for | Value it can deliver |
|---|---|---|
| Knowledge Access | People who need to follow policy | Bring policy evidence into your approved assistant, with paragraph citations and links to CM, so staff can find guidance where they already work. |
| Policy Workflows | Policy authors, owners and reviewers | Support faster policy drafting, review and updates, with help spotting contradictions, duplication and inconsistent changes within CM workflows. |
| Platform Operations | Platform administrators and delivery teams | Reduce manual configuration, metadata rework and migration effort by letting an assistant carry out permitted administrative tasks. |
Identity, permissions and audit apply across all three levels. See section 8 for current write safeguards.
Endpoint: https://{your-instance}/api/v1/mcp
The MCP server runs inside your CM instance. It is not a separate service, not a separate deployment, and not a shared multi-tenant gateway.