/companies/:companyId/mcp. Agents, Commander, the board UI, and external MCP clients can call it to read and write company data.
Authentication
Three actor types are accepted:
Requests with neither →
401 in authenticated deployments. In local_trusted mode, no-token loopback requests are treated as trusted board context, and requests carrying a valid run id may be treated as the running agent.
Tool Call Format
Read Tools
Write Tools
Protocol Workflow Tools
Document Tools
Approval Tools
Resources
MCP resources are read viaresources/list and resources/read. They are separate from tools and are not counted in the tool total.
Actor Gate
Most tools are open to all authenticated protocol actors unless listed in the server’stoolAllowedActors map. Actor gates are enforced before the tool handler runs; handlers still perform company, scope, and RBAC checks.
Key Behaviors
debrief-pushvscreate-task: Usedebrief-pushfor unstructured content that needs extraction into tasks + memory. Usecreate-taskwhen the task title/fields are already known. Revised Decision #14 allows authenticated direct task writes because RBAC is the quality gate; anonymous MCP traffic is rejected outsidelocal_trusted.- Task ownership fields:
assigneeAgentIdandassigneeUserIdidentify the executor doing the work.responsibleUserIdidentifies the accountable human for outcome and escalation; it does not dispatch execution or change the single-assignee checkout model.reviewerUserIdidentifies the human expected to review output when review is needed. - Task assignment permission: Explicitly setting
responsibleUserIdor clearing it withresponsibleUserId: nullincreate-taskorupdate-taskrequirestasks:assign. OmittingresponsibleUserIddoes not require that permission. - Memory write gate: Agents cannot write memory directly to approved status except into their own personal scope via
memory.retain+scopeToSelf: true. All other memory writes land inpendingstatus awaiting founder review (Critical Rule #6). - Artifact immutability:
attach-artifact-versionandupsert-task-documentalways create new versions. Existing versions are never modified (Decisions #43, #45). - RBAC enforcement: All tools enforce company isolation.
team_memberactors see only their project-scoped data. Cross-company access returns404.
server/src/mcp/tools/index.ts is authoritative. Avoid
copying its total into prose: the catalog changes as tools are generated and
registered.