Investigate a session
Follow what happened in an AI session. The timeline, policy results, and supporting records give an investigation its context.
Model Context Protocol · Generally available
Your agents can investigate a decision, draft a policy, or check a business rule before they act, using the same records and access limits your people already have. Nothing an agent does through MCP escapes the identity it was given.
An agent can do the gathering and the first draft. It sees exactly what the signed-in person can see, and the person still makes the call.
Follow what happened in an AI session. The timeline, policy results, and supporting records give an investigation its context.
Reviews and follow-up work can be scattered across a busy day. An agent can gather the items assigned to you into a focused view.
Summaries stay within the assigned audit engagement and point to the available evidence behind the findings.
Trace a dashboard total back to its records using matching filters and dates.
See how policy outcomes and compliance measures change over time. Agents can combine summaries with the records available to their role.
Bring the relevant alert or review case into the conversation. The authorized person confirms any review decision or alert acknowledgement.
The agents your business builds in Copilot Studio never touch your repo, and they still need the same rules as the ones your developers wrote. Connect the maker studio, or any compatible MCP client, and those workflows check business rules before they act.
A connected workflow asks VeriProof before it commits a protected change, and the answer arrives while there is still time to act on it.
A Copilot Studio workflow gets a policy check against current business facts. The outcome lands in the same decision history as everything else your agents do.
One set of rules, applied wherever your agents happen to work.
When an agent acts through a browser, a reviewer needs to see what the agent saw. MCP tools tie the policy check, the outcome, and the screen that explains the moment into one session.
Start a governed session and evaluate the business action before execution. Application requirements determine the policy and evidence needed.
Link selected, masked browser captures to the action: before a protected change, during review, after execution, or when work cannot continue.
Record the action result with its retained capture references. Reviewers can follow the relevant step in Flow View and inspect the visual context.
Key screens give reviewers visual context. A connected execution service adds independent action evidence alongside the agent's report.
Let an agent do the first draft. It can compose a rule, validate it, run the test cases, and show what the rule would have decided on real traffic. A confirmed draft goes to VeriProof for review.
Turning a rule on stays with your policy team.
A signed-in person can use the same applications, features, and audit records they can access in the portal.
A registered agent receives limited, short-lived access instead of using a customer’s identity or approval rights.
MCP credentials cannot submit application evidence. Applications continue to use their own scoped ingestion connection.
Approval remains a human responsibility
Agents can help prepare a decision. The signed-in person confirms the specific action before a review decision or alert acknowledgement is recorded.
Reach for MCP when an agent needs governance tools or an action check. Reach for an SDK integration when you are putting policy evaluation directly into application code. Most estates end up with both.
Computer-use sessions use MCP action tools. Capture files travel through the application's evidence connection, and MCP links the retained references to the action.
Connect through Streamable HTTP using a supported MCP client. The MCP guide lists the supported protocol version and connection requirements.
Records arrive with consistent fields and clear filters, so an agent has the context to interpret the result.
Supported writes use confirmation and a unique retry key. Repeating the same request does not create another outcome.
Start with an included investigation workflow. It helps the agent gather relevant records and identify gaps for your review.