Implementation plan
Phase 7: MCP and AI-native workflow
Deliverables and exit criteria for MCP and AI-native workflow.
Status: planned; completion evidence not yet recorded in this documentation.
Implement:
- OAuth authorization server/client flow
- MCP streamable HTTP endpoint
- Organization/app/scopes grant UI
- Core tools
- Operation search/execute catalog
- Client allowlist policy
- Agent identity/audit
- Change-set AI workflow
- Build/preview tools
- Deployment-request tool
- Secret-reference behavior
- Revocation and expiration
- Tool-call metrics/rate limits
Exit criteria:
- Approved AI client creates an app under a human grant.
- AI cannot see another app or organization.
- AI cannot approve deployment.
- Revoked grant stops working immediately or within documented cache bounds.
- Tool calls identify both human and client.
- Source changes are reviewable as diffs.
- Personal/unapproved client can be denied by organization policy.
Evidence to record
Record implementation revisions, test reports, relevant ADRs, unresolved findings, the accepting owner, and acceptance date. Leave this phase planned until its exit criteria are demonstrated.

