MBeyond CRUD — Designing MCP Tools Around Trust and Consent

Beyond CRUD

Designing MCP tools around trust and consent

Sajeetharan Sinnathurai
Sajeetharan Sinnathurai

Contributions
Azure MCP Server · Azure Cosmos DB MCP Toolkit

Principal Product Manager
Azure Cosmos DB
sajeetharan.dev
01 / 16
One product. Two trust levels.

What is DevGlobe?

An open-source talent graph where humans and AI agents discover developers through public contribution evidence—not popularity alone.

Public signals Real developer evidence Profiles, repositories, languages, locations, and contribution activity.
Powered by Azure Cosmos DB Data + search + workflow Stores profiles and activity, powers vector and hybrid search, and persists introduction state.
MCP experience Bounded agent actions Find evidence publicly. Request an introduction only through consent controls.
Anonymous · public discovery
Authenticated · consent-controlled introductions
Real-time live coding presenceOpt in from VS Code → heartbeat every 30 seconds → appear on the live globe. Shares presence and active language—not source code, paths, repositories, branches, or keystrokes.
02 / 16
One prompt. Two trust decisions.
“Find top developers in Bangalore—and contact the audience’s choice.”
✓ Discovery returns public evidence
✕ Silent contact is blocked

Let’s run the system before explaining it.

DevGlobe’s profiles, evidence, and consent workflow are powered by Azure Cosmos DB.
03 / 16
Treat every request like a fresh order
SPEC 2026-07-28

Every request brings its context.

Like a restaurant order slip: do not depend on what someone remembers.

01No session trust

Do not trust this request only because an earlier request was trusted.

No initialize handshake or Mcp-Session-Id; protocol context travels with each request.
02Explicit metadata

The request says which version and capabilities the client supports.

Protocol version and client capabilities travel in request _meta.
03Discover first

The client can first ask who the server is and what it can do.

server/discover exposes server identity and supported primitives.
04Explicit interaction

If something is missing, ask a clear follow-up. Send only requested updates.

MRTR handles follow-ups; filtered subscriptions deliver requested change notifications.
04 / 16
Toolkit lesson · local convenience ≠ production identity

Azure MCP’s production baseline

Protect the server, its identity, and every tool call it brokers.

01
Audience-bound OAuth 2.1Use PKCE and resource in the OAuth flow; validate token issuer, audience, expiry, and scopes on protected requests.
02
Least-privilege identityUse workload identity and narrow RBAC to only the enabled tools.
03
Origin and endpoint checksValidate Origin; bind local servers to localhost; fail closed on TLS errors.
04
APIM enforcement gatewayCentralize token validation, rate limits, allowed paths, and auditing.
05
Pin tool definitionsTreat descriptions, annotations, schemas, and results as untrusted context.
06
OpenTelemetry evidenceInventory servers and retain traces; protocol Logging is now deprecated.
05 / 16
A secure tool can still hold too much authority

A secure tool can still be the wrong tool.

Azure MCP baseline

How do we execute safely?

Identity, least privilege, gateways, context protection, and evidence.

+

Would you allow this tool?

An authenticated agent can contact this developer immediately. Should this capability exist?

Product design decides the capability.
06 / 16
Four core tools

Public discovery

search_developers get_developer_profile

Anonymous. Read-only. Bounded.

Public evidence, explicit freshness, no private contact data.

TRUST BOUNDARY

Consequential action

request_introduction get_introduction_status

Authenticated. Rate-limited. Audited.

A request starts a consent workflow. It does not reveal contact details.

07 / 16
Toolkit lesson · validate before execution
search_developers Tool contract
inputSchema: SearchInput
outputSchema: DeveloperSearchResult

structuredContent: {
  results, resultCount, freshness
}

// UX hints — not security claims
readOnlyHint: true
idempotentHint: true
Clients MUST treat annotations as untrusted unless the server itself is trusted.

Validate shape. Re-evaluate trust.

Input contractBounds cost, scope, and unsafe degrees of freedom.
Output contractServer MUST conform; client SHOULD validate structured content.
Trust contractPublisher, authorization, provenance, and intent remain independent.
08 / 16
Search returns evidence—not a verdict

Evidence,
not a verdict.

The tool explains the match. It does not invent suitability.

0 results ≠ permission to hallucinate
Selected developer · Public profile result TypeScript
Why matched Public intent
Result count ≤ 20
Public commits 13,986
Agent requests No
Freshness: unknown — surfaced, not hidden
09 / 16
Missing context triggers elicitation—not consent
InputRequiredResult
“Which event, and why Sajeetharan?”
HUMAN
IN LOOP
A Project → MCP Connect Bangalore
B Reason → speaking invitation
C Elicitation → I complete the request
D Consent → Sajeetharan decides
10 / 16
A complete request still crosses four permission boundaries

Agent permission

1 · valid DevGlobe credential
2 · confirm request_introduction
Bearer token
↓ SHA-256 + timing-safe compare
{ id, name, owner }

My yes creates the request.

≠

Human permission

3 · approve authentication navigation
4 · developer accepts
pending
↓ Sajeetharan decides
accepted | declined | expired

His yes accepts the introduction.

11 / 16
The developer’s answer becomes durable consent state
pending
accepted
declined
expired
pending — no contact information
accepted — public GitHub route only
declined — no contact route
expired — no contact route

The chat may close. DevGlobe still remembers his decision.

12 / 16
Durable consent outlives progress and tasks

Seconds, long-running work, or days?

notifications/progressReact search · seconds

Progress ends when the search response completes.

close SSE responseCancelled search

Close the request, stop useful work, and ignore late results.

io.modelcontextprotocol/tasksRe-indexing · longer

A durable job gets an ID and can be checked later.

Human approval may take days. Keep consent in DevGlobe—not in request progress or a task handle.

13 / 16
Expose the narrowest consent-aware capability

Database

Raw access gives the agent far more authority than this demo needs.

query(sql)

Platform

Bounded public discovery is enough to find React profiles.

search_developers(...)

Domain

Identity, reason, limits, history, and consent travel together.

request_introduction(...)
14 / 16
Design every agent action around its consequence

One demo. Three rules.

Evidence before conclusions

Discovery before action

Consent before consequence

Discover Return bounded public evidence and uncertainty.
Request Use a protected capability with identity and intent.
Decide Persist the affected person’s answer in the product.
15 / 16
Q&A
server online 01 / 16