[{"data":1,"prerenderedAt":708},["ShallowReactive",2],{"navigation":3,"\u002Fdevelopment\u002Fai-mcp":250,"\u002Fdevelopment\u002Fai-mcp-surround":703},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":98,"body":252,"description":696,"extension":697,"links":698,"meta":699,"navigation":700,"path":99,"seo":701,"stem":100,"__hash__":702},"docs\u002F4.development\u002F1.ai-mcp.md",{"type":253,"value":254,"toc":680},"minimark",[255,271,276,279,282,293,296,299,327,330,345,349,352,358,361,367,370,374,377,383,386,392,395,401,407,411,414,419,425,428,431,435,438,444,447,450,456,459,465,468,473,476,480,483,506,509,535,539,542,549,552,584,592,596,599,602,608,611,631,634,654,657,661,669],[256,257,258],"note",{},[259,260,261,265,266,270],"p",{},[262,263,264],"strong",{},"v1 design baseline."," This page specifies intended behavior. Delivery and validation are tracked in the ",[267,268,269],"a",{"href":171},"implementation plan","; it is not a claim that the platform is already implemented.",[272,273,275],"h2",{"id":274},"primary-model","Primary model",[259,277,278],{},"Users use their approved Claude, ChatGPT, or Codex account.",[259,280,281],{},"The AI client connects to:",[283,284,290],"pre",{"className":285,"code":287,"language":288,"meta":289},[286],"language-text","https:\u002F\u002Fmcp.intrnl.cloud\u002Fmcp\n","text","",[291,292,287],"code",{"__ignoreMap":289},[259,294,295],{},"The inference cost remains with the user’s or the organization’s AI subscription\u002Fcontract.",[259,297,298],{},"intrnl charges for:",[300,301,302,306,309,312,315,318,321,324],"ul",{},[303,304,305],"li",{},"Application hosting",[303,307,308],{},"Builds",[303,310,311],{},"Databases",[303,313,314],{},"KV",[303,316,317],{},"Governance",[303,319,320],{},"Security",[303,322,323],{},"Runtime capacity",[303,325,326],{},"Support",[259,328,329],{},"It does not need to absorb every code-generation token.",[259,331,332,333,339,340],{},"Both OpenAI and Anthropic support remote MCP-style tool access with authenticated endpoints. OpenAI’s guidance explicitly says authorization must be enforced by the MCP server on every request rather than delegated to the model; Anthropic’s connector supports remote HTTPS servers and OAuth bearer tokens. ",[267,334,338],{"href":335,"rel":336},"https:\u002F\u002Fdevelopers.openai.com\u002Fplugins\u002Fbuild\u002Fmcp-server",[337],"nofollow","OpenAI MCP server authorization",", ",[267,341,344],{"href":342,"rel":343},"https:\u002F\u002Fplatform.claude.com\u002Fdocs\u002Fen\u002Fagents-and-tools\u002Fmcp-connector",[337],"Anthropic MCP connector",[272,346,348],{"id":347},"no-subscription-token-proxying","No subscription-token proxying",[259,350,351],{},"Do not implement:",[283,353,356],{"className":354,"code":355,"language":288,"meta":289},[286],"Paste your Claude session cookie\nLogin to Claude inside intrnl\nGive intrnl your ChatGPT subscription token\nRun Claude Code using a user’s consumer session from our servers\n",[291,357,355],{"__ignoreMap":289},[259,359,360],{},"The valid architecture is:",[283,362,365],{"className":363,"code":364,"language":288,"meta":289},[286],"User’s AI client\n        ↓\nauthenticated MCP call\n        ↓\nintrnl tool\n",[291,366,364],{"__ignoreMap":289},[259,368,369],{},"A future native intrnl assistant may use API billing and become a separate paid offering.",[272,371,373],{"id":372},"oauth-grant-model","OAuth grant model",[259,375,376],{},"An MCP grant is bound to:",[283,378,381],{"className":379,"code":380,"language":288,"meta":289},[286],"human user\norganization\nAI client\nallowed applications\nscopes\nissued time\nexpiration\nrevocation state\n",[291,382,380],{"__ignoreMap":289},[259,384,385],{},"Example scopes:",[283,387,390],{"className":388,"code":389,"language":288,"meta":289},[286],"profile:read\napps:read\napps:create\nsource:read\nsource:write\nbuilds:read\nbuilds:create\npreviews:create\ndeployments:request\ndeployments:approve\nsecurity:read\nsecurity:admin\nsecrets:reference\n",[291,391,389],{"__ignoreMap":289},[259,393,394],{},"Normal AI-client grants must not include:",[283,396,399],{"className":397,"code":398,"language":288,"meta":289},[286],"deployments:approve\nsecurity:admin\nidentity:admin\nsecrets:read\n",[291,400,398],{"__ignoreMap":289},[259,402,403,406],{},[291,404,405],{},"secrets:reference"," allows an AI to configure code around a named capability without obtaining the underlying secret value.",[272,408,410],{"id":409},"tool-surface","Tool surface",[259,412,413],{},"Use a small set of obvious core tools plus a searchable operation catalog.",[415,416,418],"h3",{"id":417},"core-tools","Core tools",[283,420,423],{"className":421,"code":422,"language":288,"meta":289},[286],"profile.get\norganizations.get_current\n\napps.list\napps.get\napps.create\n\nsource.list_files\nsource.read_file\nsource.apply_patch\nsource.get_diff\n\nbuilds.create\nbuilds.get\nbuilds.get_logs\n\npreviews.create\npreviews.get\n\ndeployments.request\ndeployments.get\n\noperations.search\noperations.execute\n",[291,424,422],{"__ignoreMap":289},[259,426,427],{},"The search\u002Fexecute pattern keeps the default tool list manageable while supporting future capabilities.",[259,429,430],{},"Every operation schema is versioned and generated from the same command definitions used by REST and Filament.",[272,432,434],{"id":433},"ai-change-set-model","AI change-set model",[259,436,437],{},"AI does not directly mutate production.",[283,439,442],{"className":440,"code":441,"language":288,"meta":289},[286],"Human prompt\n    ↓\nAI requests source change\n    ↓\nintrnl creates or updates a change set\n    ↓\npatch applied against expected base revision\n    ↓\ncommit\u002Fcheckpoint\n    ↓\nbuild\n    ↓\npreview\n    ↓\nhuman review\n    ↓\ndeployment request\n",[291,443,441],{"__ignoreMap":289},[259,445,446],{},"Optimistic concurrency prevents the AI from silently overwriting changes made after it read the source.",[259,448,449],{},"Each change records:",[283,451,454],{"className":452,"code":453,"language":288,"meta":289},[286],"Human actor: Jane Smith\nAgent\u002Fclient: Claude\nOAuth grant: grant_...\nOrganization: Example Organization\nApplication: Equipment Requests\nBase revision: abc123\nResult revision: def456\n",[291,455,453],{"__ignoreMap":289},[259,457,458],{},"The audit text should read:",[460,461,462],"blockquote",{},[259,463,464],{},"Jane Smith, via Claude, modified Equipment Requests.",[259,466,467],{},"Not:",[460,469,470],{},[259,471,472],{},"Claude modified Equipment Requests.",[259,474,475],{},"The human grant is the authority.",[272,477,479],{"id":478},"no-ai-approvals","No AI approvals",[259,481,482],{},"An AI may:",[300,484,485,488,491,494,497,500,503],{},[303,486,487],{},"Create an app",[303,489,490],{},"Read and edit permitted source",[303,492,493],{},"Run a build",[303,495,496],{},"Create a preview",[303,498,499],{},"Explain a diff",[303,501,502],{},"Request deployment",[303,504,505],{},"Request a capability",[259,507,508],{},"An AI may not:",[300,510,511,514,517,520,523,526,529,532],{},[303,512,513],{},"Approve its own deployment",[303,515,516],{},"Approve a destructive migration",[303,518,519],{},"Grant itself network access",[303,521,522],{},"Grant itself a secret",[303,524,525],{},"Change mandatory organization policy",[303,527,528],{},"Add itself to another application",[303,530,531],{},"Change its OAuth scopes",[303,533,534],{},"Approve regulated status",[272,536,538],{"id":537},"public-mcp-endpoint-and-organization-networking","Public MCP endpoint and organization networking",[259,540,541],{},"Cloud-hosted AI clients connect from the AI provider’s infrastructure, which has different IP addresses from the user’s office network.",[259,543,544,545,548],{},"Therefore, ",[291,546,547],{},"mcp.intrnl.cloud"," cannot be limited solely to organization office IP addresses if the organization wants cloud-hosted AI clients to use it.",[259,550,551],{},"The endpoint should be publicly reachable but protected by:",[300,553,554,557,560,563,566,569,572,575,578,581],{},[303,555,556],{},"OAuth",[303,558,559],{},"Client registration",[303,561,562],{},"User and org authorization",[303,564,565],{},"Short token lifetimes",[303,567,568],{},"Scope enforcement",[303,570,571],{},"Rate limiting",[303,573,574],{},"mTLS where supported",[303,576,577],{},"Revocation",[303,579,580],{},"Audit",[303,582,583],{},"Optional provider IP checks as supplemental protection",[259,585,586,587],{},"An IP allowlist is not a substitute for authentication and authorization. OpenAI’s own MCP guidance makes that distinction. ",[267,588,591],{"href":589,"rel":590},"https:\u002F\u002Fdevelopers.openai.com\u002Fplugins\u002Fbuild\u002Fauth",[337],"OpenAI MCP authentication",[272,593,595],{"id":594},"data-classification-controls","Data-classification controls",[259,597,598],{},"The organization configures approved AI clients and account types.",[259,600,601],{},"Example:",[283,603,606],{"className":604,"code":605,"language":288,"meta":289},[286],"Organization allows:\n- approved ChatGPT Enterprise workspace\n- approved Claude Enterprise workspace\n\nOrganization denies:\n- personal AI accounts for organization source\n- all AI clients for regulated apps\n",[291,607,605],{"__ignoreMap":289},[259,609,610],{},"For the pilot:",[300,612,613,616,619,622,625,628],{},[303,614,615],{},"No regulated data in prompts",[303,617,618],{},"No regulated data in source",[303,620,621],{},"No sensitive production data in previews",[303,623,624],{},"No enterprise system integrations",[303,626,627],{},"Synthetic data only",[303,629,630],{},"Explicit “No regulated data” classification and user acknowledgement",[259,632,633],{},"Do not log full AI prompts by default. Log:",[300,635,636,639,642,645,648,651],{},[303,637,638],{},"Tool name",[303,640,641],{},"Authenticated actor",[303,643,644],{},"Inputs necessary for audit",[303,646,647],{},"Source patch\u002Fdiff",[303,649,650],{},"Result and error metadata",[303,652,653],{},"Correlation ID",[259,655,656],{},"Avoid storing unrelated conversational text that may contain sensitive data.",[272,658,660],{"id":659},"compatibility-validation","Compatibility validation",[259,662,663,664,668],{},"Remote MCP support does not establish that every client, account tier, transport, or workspace policy works with intrnl. The ",[267,665,667],{"href":666},"\u002Froadmap\u002Fphase-0#mcp-spike","Phase 0 MCP spike"," must verify representative OpenAI and Anthropic clients, OAuth discovery, grants, revocation, and audit.",[259,670,671,672,674,675,679],{},"The read-only MCP tools exposed by this documentation site are a separate service. They do not implement the planned authenticated platform endpoint at ",[291,673,547],{},". See ",[267,676,678],{"href":677},"\u002Freference\u002Fcontributing#machine-readable-documentation","documentation access",".",{"title":289,"searchDepth":681,"depth":682,"links":683},1,2,[684,685,686,687,691,692,693,694,695],{"id":274,"depth":682,"text":275},{"id":347,"depth":682,"text":348},{"id":372,"depth":682,"text":373},{"id":409,"depth":682,"text":410,"children":688},[689],{"id":417,"depth":690,"text":418},3,{"id":433,"depth":682,"text":434},{"id":478,"depth":682,"text":479},{"id":537,"depth":682,"text":538},{"id":594,"depth":682,"text":595},{"id":659,"depth":682,"text":660},"Scoped human grants, approved AI clients, reviewable change sets, and server-enforced authorization.","md",null,{},true,{"title":98,"description":696},"Jwh8tT8ejSSfqYOBILt-vd6GEr_hJ6VWY5w44DfQB-Q",[704,706],{"title":87,"path":88,"stem":89,"description":705,"children":-1},"Threats and controls for tenant isolation, untrusted code, AI access, identity, and recovery.",{"title":102,"path":103,"stem":104,"description":707,"children":-1},"Managed Forgejo repositories, change sets, GitHub canonical mode, and full-history transfer.",1790019414382]