// Governance in front of every tool call

Every MCP tool call, governed and receipted.

The MCP Registry has thousands of servers and no trust layer. Agentics puts governance in front of every server your agents reach: a policy check and a proof-anchored receipt on every tool call — with a Bureau score where the cross-tenant data earns one.

This is the public catalog of servers Agentics governs. Governance posture (allow-listed / default-deny-writes) is shown for each; a Bureau score appears only where 5+ independent tenants have contributed outcome data — never an invented number.

Phase 0, stated plainly. Receipts on governed tool calls are live — each call writes a verifiable child receipt to the ledger. What grows over time is the catalog's breadth: only servers that are registered and approved appear, and scores stay locked behind the k ≥ 5 floor until the data earns them. We never fabricate a server or a score.

A governed tool call
1

Policy + allow-list check

The Tool Mesh gate decides allow/deny per call — writes are default-deny until a tool is explicitly allow-listed, with an SSRF host gate and a tool-poisoning scan.

2

Proof-anchored receipt

Each call writes a child receipt (request_kind=tool, billable=false) chained to the parent LLM receipt — hash-only by default, verifiable on the ledger.

3

Bureau score (where earned)

Cross-tenant outcomes roll up into a k-anonymized Bureau score for a server's category — shown only at k ≥ 5, never estimated.

Steps 1 & 2 are live today for every governed tool call. Step 3 fills in as the cross-org corpus grows.

// The catalog

Governed MCP servers

Each server shows its governance posture, declared tools, and Bureau score where the cross-org data earns one. Rated servers sort by composite score; the rest are listed honestly as unrated.

// What "Agentics-governed MCP" means

A check and a receipt on every tool call

Extending the same discipline we put in front of every model to every tool call — so an agent can only do what you granted, and every move it makes is provable after the fact.

1 · policy check Default-deny, allow-listed Writes are denied until a tool is explicitly allow-listed. Per-tool RBAC, an SSRF host-allowlist gate, and a tool-poisoning scan decide allow vs. deny on every call.
2 · proof receipt A receipt per tool call Each governed call writes a child receipt chained to the parent LLM request — hash-only by default, independently verifiable on the ledger. Not a claim: it ships today.
3 · bureau score Scored by outcomes Cross-tenant outcomes roll into a k-anonymized (k ≥ 5), differentially-private Bureau score for a server's category. Shown only where the data earns it — never estimated.
// The Bureau formula

composite = reliability + cost_efficiency − incident_rate

Every input is a cross-customer aggregate over k ≥ 5 contributing tenants with differential-privacy noise. The Bureau table carries no tenant or partner identifier by design — the score ranks the supply chain, never a customer. A server with no scored category or below the floor is shown unrated.

policy check · every call receipt · every call · live k ≥ 5 · differential privacy public · aggregate-only

Governing MCP for your own agents happens in the console; this page is the public read-only view. Bureau scoring reuses the same aggregate that powers the marketplace.

// Put a trust layer on MCP

Govern every tool call. Prove every one.

Point your agents at the Tool Mesh and every MCP tool call is policy-checked, allow-listed, and receipted — with a Bureau score on the servers as the corpus grows.