MCP safety
Video MCP needs policy gates before tool calls become decisions.
A camera-facing tool interface can create real-world risk. Ayneye's MCP content uses a simple default: read evidence, cite evidence, expose uncertainty, and route risky outcomes to human review.
Safety policy matrix
| Risk area | Default MCP behavior | Required escalation |
|---|---|---|
| Identity | Do not identify people or infer protected attributes | Human-reviewed policy and lawful basis |
| Intent | Do not infer motive, threat, theft, or guilt | Evidence packet and reviewer decision |
| Physical access | No unlocking, locking, shutdown, dispatch, or device control | Separate governed system outside public beta |
| Emergency response | No automatic calls or emergency dispatch | Human operator review |
| Employment/discipline | No automated personnel decisions | Human policy review and audit |
| Low confidence | Return insufficient evidence | Reprocess, review, or escalate model path |
Blocked operations
Why this matters commercially
Safe boundaries make the product more credible to technical buyers. A buyer can trust a product that clearly separates evidence retrieval from action authority. A vague MCP promise may look exciting but creates procurement, legal, and operational blockers. The correct commercial message is not agents can do anything; it is agents can read evidence safely and hand risky outcomes to humans.
The purpose of this page is to make the MCP boundary concrete for builders, buyers, and reviewers. A useful MCP integration is not a promise that an agent can watch everything and decide everything. It is a disciplined interface over already-materialized evidence. Each tool call should be tenant-scoped, read-only by default, evidence-aware, cost-aware, and auditable. If the request asks for identity, intent, physical access, emergency response, employment action, or destructive change, the tool returns a review-required state instead of pretending that a video artifact is a final decision. This keeps the product useful for developers while making it credible for security, legal, and operations teams.