Agent Execution & MCP Control
Operators and approved MCP clients share one action plane. Read-only checks may auto-run; mutating work against acme-wks-01 still waits for human approval.
This guide is the Cohort 01 operator view of MCP and agent control: not a private protocol dump. Prefer least privilege, keep humans in the loop for consequential work, and use Actions as the review surface.
Prerequisites
- An enrolled Acme Corp endpoint online under the Acme operator tenant (see Get Started).
- A portal operator identity (or API key) with only the scopes you need.
- Clear HITL defaults: four-eyes unless Governance intentionally allows self-elevate for a client environment.
Connect an MCP client
Typical options:
- OAuth login: preferred for interactive clients such as Cursor.
- API key headers: for scripts and automation; mint keys in Settings and store them outside chat logs.
- Other clients (ChatGPT Apps, Claude Desktop, custom) follow the same rule: mutating tools must remain accountable to Actions.
Session behavior should mirror portal permissions. If a tool would change an endpoint, expect a pending Action unless policy explicitly auto-approves a low-impact kind.
What operators usually do with MCP
- Fleet visibility: list endpoints, check vitals, find software (for example Chrome on Acme Corp devices).
- Read-only verification: PowerShell/shell checks that do not change state.
- Mutating commands: queue uninstalls, scripts, or package work for Approve & run.
- Optional visual check: screenshot/verification tools when your cohort environment enables them.
Example path (same story as the marketing walkthrough): MCP queues a winget uninstall for an Acme Windows endpoint → a human Approves & runs on Actions → the agent executes → the timeline keeps the handoff.
Policy tiers (operator mental model)
- Read-only / low-impact work may auto-execute when Governance allows it.
- Medium and high-risk work should land on Actions for a person.
- Endpoint agent enforcement is defense in depth: portal approval is still the Cohort 01 accountability story.
Details for the approval UX live in Operator Actions & Human Approval. Remote session mechanics live in Remote Control & Interactive Console.
Troubleshooting (operator level)
- Tool denied / missing scope: mint a key or role with the needed permission; do not widen to admin by default.
- Pending forever: someone needs to Approve & run or Reject on Actions.
- Endpoint offline: confirm check-in under Endpoints before retrying.
Internal smoke scripts and private PROTOCOL references stay out of this public guide.
Related guides
- Operator Actions & Human Approval
- Remote Control & Interactive Console
- Get Started with FlowRMM Remote Console
Want hands-on help evaluating Cohort 01? Book a demo or apply for Cohort 01.