Session

Beyond CRUD: Designing MCP Tools Around Trust and Consent

Exposing data through MCP is straightforward. Deciding what an agent should be allowed to discover, infer, and act on is much harder.

While building DevGlobe, a developer-discovery platform, I chose not to expose a general database interface. Instead, I designed four domain-specific MCP tools across two trust levels: anonymous tools for public discovery and authenticated tools for consent-controlled introductions.

In this implementation deep dive, I will demonstrate an agent finding developers using structured public evidence while being unable to initiate contact silently. We will examine typed tool contracts, bounded results, authentication, structured errors, data freshness, rate limits, and the consent state machine behind introduction requests. I will also explain how a stateless MCP server coordinates a stateful workflow without leaking private contact information.

Attendees will leave with a practical framework for deciding when to expose database, platform, or domain-level tools, and how to make human approval a real system boundary rather than just another instruction in a prompt.

Key Takeaways

Choose MCP tools based on trust boundaries, not API convenience.
Separate read-only discovery from consequential actions.
Model consent as durable application state.
Return evidence and freshness instead of unsupported agent conclusions.
Use authentication, least privilege, and bounded contracts together.

Sajeetharan Sinnathurai

Program Manager (Cosmos DB) | Google Dev Expert | Top Stackoverflow Contributor

Sri Jayewardenepura Kotte, Sri Lanka

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top