Back to standardsAI Tool Exposure Standard
Minimum controls for exposing APIs, workflows, functions, and MCP tools to AI runtimes.
Minimum controls
- Tool registered with owner and source-system owner
- Allowed callers and operations defined
- Read/write/action risk classification required
- Input/output schema versioned
- Audit logging and correlation IDs enabled
Related records and procedures
Records: Tool, Tool Operation, Tool Risk, Tool Entitlement.
Procedures: Register tool, classify risk, approve/revoke tool access.