Skip to main content

Model Context Protocol (MCP)

Exploring Framework

Model Context Protocol (MCP) is an open standard from Anthropic that lets AI assistants access systems such as Jira, GitHub, Confluence, Azure DevOps and SonarQube in a controlled way.

Warning Talk to the AI Capability and Enablement team before you use MCP. We are trialling it, so it is not approved for general use.

Only designated projects use MCP at the moment, and only with the team's agreement. If you think it could help your project, email the AI Capability and Enablement team before you start.

An MCP server exposes those systems to the model. For projects trialling MCP, remote vendor-hosted servers are preferred, because they give consistent governance, stronger security controls and built-in audit logging.

What data you can use with it

What you can expose through MCP depends on your data's classification. Check Using data with AI before you connect anything.

Exclude sensitive, personal or confidential data from prompts and MCP context, and redact secrets and credentials.

Why we are trialling it

The AI Capability and Enablement team is trialling MCP to learn where it adds value and how to run it safely. It is not approved for general use.

Any use needs written approval from the relevant Project Architect and the AI Capability and Enablement team.

Using MCP safely

If your project is trialling MCP, follow these rules:

  • connect only to the vendor-provided MCP servers the team is trialling, not community or self-built servers
  • use OAuth-based authentication with least-privilege scopes, not Personal Access Tokens
  • never auto-approve actions: keep a human in the loop and review tool calls before they run
  • restrict access to only the repositories, projects and workspaces you need

MCP servers we are trialling

These are the servers the AI Capability and Enablement team is currently trialling. They are not approved for general use.

Talk to the team before you connect to any of them. Do not use community or self-built servers.

More information

For how Defra handles AI security and data, see Security and Keeping data safe.

Get help with Model Context Protocol

The AI Capability and Enablement team is trialling MCP. Talk to us before you use it.