Bastion One — The Deterministic Control Plane for AI Agents

The MCP Audit Layer: SCITT-Compliant Receipts for Every Tool Call

A technical brief for engineering, security, and trust & safety leads at frontier model providers and platform vendors building on the Model Context Protocol.

The Standard Was Half the Problem

The Model Context Protocol (MCP) has rapidly become the de facto standard for how autonomous agents call tools — file systems, databases, SaaS APIs, the enterprise’s full system of record. The protocol elegantly solves semantic standardization: any compliant client can invoke any compliant server. What MCP deliberately leaves out is the part that the enterprise security buyer asks about first: auditability and enforcement.

MCP tells you what the agent can call. It does not tell you, in court-admissible form, who acted, with what authority, against what target, with what outcome, and whether the action was authorized at the moment it executed.

For regulated industries — financial services, healthcare, government, defense — that gap is the difference between a deployable agent and a non-starter.

The MCP Audit Layer

Bastion One’s AICS (Agent Control Engine) sits as an interceptor between the MCP client and the MCP server. Every tool call is evaluated, in-band, against the customer’s compiled regulatory policy (the Sovereign Treaty). Authorized calls pass. Unauthorized calls receive a deterministic Hard Stop before they reach the system of record. Every decision — allow or deny — generates a cryptographically signed receipt.

Agent → MCP Client → AICS Interceptor → MCP Server → System of Record
↓
DUT Receipt → AITS Ledger → Customer SIEM

What’s in the Receipt

The receipt is a Data Unit of Traceability (DUT) — a SCITT-compliant signed envelope that binds three artifacts to the tool-call event:

  • UAI (Unique Agent Identifier) — cryptographic workload identity of the calling agent, including model/version and provenance.
  • LT (Lineage Tag) — process-level wrapper capturing the originating prompt, the workflow context, and data lineage upstream of the call.
  • The action envelope — the exact MCP tool name, arguments hash, target system, and the AICS decision (allow / deny / quarantine) with the matching policy clause from the Sovereign Treaty.

The DUT is signed by the AICS instance’s KMS key and streamed to the customer’s AITS ledger — which is hosted in their environment (Splunk, Datadog, AWS GovCloud SIEM), not ours. Bring Your Own Storage.

For Trust & Safety and Solutions Engineering teams at frontier labs: this is the layer your regulated enterprise customers are asking for when they say “we love Claude, but we can’t deploy it against SAP / Epic / our treasury system without provable enforcement.” Constitutional shaping handles intent. AICS handles outcome.

Standards Alignment

The MCP audit layer is designed to slot directly into the standards landscape enterprise compliance officers already recognize:

  • IETF SCITT — Supply Chain Integrity, Transparency & Trust. DUT receipts are SCITT-compliant envelopes.
  • ISO/IEC 42001:2023 — AI Management System. The receipt stream is the evidence layer auditors ask for.
  • NIST AI RMF — Govern / Map / Measure / Manage. AICS enforces Govern + Manage at runtime; AITS provides Measure.
  • EU AI Act — Article 12 logging requirements satisfied by the DUT stream.

What This Solves for the Platform Provider

If you ship MCP servers, agents, or an agentic platform, you inherit three buyer objections the moment a regulated enterprise picks up a sales call:

  • “How do I prove the agent did what it was authorized to do?” — The DUT stream is mathematical proof, defensible to a Big 4 auditor.
  • “How do I block hallucinated transactions before they hit my SAP?” — The AICS Hard Stop is deterministic, not probabilistic.
  • “How do I keep classified audit telemetry off a third-party vendor’s cloud?” — BYOS streams the ledger to the customer’s own SIEM or GovCloud.

Bastion One sits as the independent governance partner in the agentic stack — model-agnostic, MCP-ready, and protected by foundational IP in deterministic agent enforcement and cryptographic agent identity.

Similar Posts