The MCP Audit Layer: SCITT-Compliant Receipts for Every Tool Call
A technical brief for engineering, security, and trust & safety leads at frontier model providers and platform vendors building on the Model Context Protocol.
The Standard Was Half the Problem
The Model Context Protocol (MCP) has rapidly become the de facto standard for how autonomous agents call tools — file systems, databases, SaaS APIs, the enterprise’s full system of record. The protocol elegantly solves semantic standardization: any compliant client can invoke any compliant server. What MCP deliberately leaves out is the part that the enterprise security buyer asks about first: auditability and enforcement.
MCP tells you what the agent can call. It does not tell you, in court-admissible form, who acted, with what authority, against what target, with what outcome, and whether the action was authorized at the moment it executed.
For regulated industries — financial services, healthcare, government, defense — that gap is the difference between a deployable agent and a non-starter.
The MCP Audit Layer
Bastion One’s AICS (Agent Control Engine) sits as an interceptor between the MCP client and the MCP server. Every tool call is evaluated, in-band, against the customer’s compiled regulatory policy (the Sovereign Treaty). Authorized calls pass. Unauthorized calls receive a deterministic Hard Stop before they reach the system of record. Every decision — allow or deny — generates a cryptographically signed receipt.
↓
DUT Receipt → AITS Ledger → Customer SIEM
What’s in the Receipt
The receipt is a Data Unit of Traceability (DUT) — a SCITT-compliant signed envelope that binds three artifacts to the tool-call event:
- UAI (Unique Agent Identifier) — cryptographic workload identity of the calling agent, including model/version and provenance.
- LT (Lineage Tag) — process-level wrapper capturing the originating prompt, the workflow context, and data lineage upstream of the call.
- The action envelope — the exact MCP tool name, arguments hash, target system, and the AICS decision (allow / deny / quarantine) with the matching policy clause from the Sovereign Treaty.
The DUT is signed by the AICS instance’s KMS key and streamed to the customer’s AITS ledger — which is hosted in their environment (Splunk, Datadog, AWS GovCloud SIEM), not ours. Bring Your Own Storage.
Standards Alignment
The MCP audit layer is designed to slot directly into the standards landscape enterprise compliance officers already recognize:
- IETF SCITT — Supply Chain Integrity, Transparency & Trust. DUT receipts are SCITT-compliant envelopes.
- ISO/IEC 42001:2023 — AI Management System. The receipt stream is the evidence layer auditors ask for.
- NIST AI RMF — Govern / Map / Measure / Manage. AICS enforces Govern + Manage at runtime; AITS provides Measure.
- EU AI Act — Article 12 logging requirements satisfied by the DUT stream.
What This Solves for the Platform Provider
If you ship MCP servers, agents, or an agentic platform, you inherit three buyer objections the moment a regulated enterprise picks up a sales call:
- “How do I prove the agent did what it was authorized to do?” — The DUT stream is mathematical proof, defensible to a Big 4 auditor.
- “How do I block hallucinated transactions before they hit my SAP?” — The AICS Hard Stop is deterministic, not probabilistic.
- “How do I keep classified audit telemetry off a third-party vendor’s cloud?” — BYOS streams the ledger to the customer’s own SIEM or GovCloud.
Bastion One sits as the independent governance partner in the agentic stack — model-agnostic, MCP-ready, and protected by foundational IP in deterministic agent enforcement and cryptographic agent identity.
