Skip to content

Content Security Providers govern the Model Context Protocol: A standard protocol for AI agent and server interactions that defines how AI assistants communicate with external tools and data sources.Learn more(opens in new tab) tool traffic that flows through Aembit’s MCP Identity Gateway: A component that brokers MCP traffic between MCP clients and target MCP servers, validating authorization and presenting Aembit-managed credentials on each request.Learn more to your MCP servers. You add a provider to an Access Policy: Access Policies define, enforce, and audit access between Client and Server Workloads by cryptographically verifying workload identity and contextual factors rather than relying on static secrets.Learn more through its Content Security component. Each provider evaluates the MCP tool messages the MCP Identity Gateway proxies, and Aembit applies the provider’s decision before the message continues.

In the Access Policy Builder, Content Security is an optional component positioned between Access Conditions and Credential Providers. See Create an Access Policy for every component an Access Policy can include.

An Access Policy evaluates each Content Security Provider it carries on both the request and response paths of the MCP tool traffic it governs. Evaluation adds a step without changing how the Access Policy’s other components authorize access.

An Access Policy can carry one of each at the same time. MCP Tool Access Control matches tool names first, so CrowdStrike AIDR inspects only the MCP tools and calls that MCP Tool Access Control allowed.

When an Access Policy includes CrowdStrike AIDR, Aembit sends the inspected MCP content to CrowdStrike AIDR, along with request metadata that identifies the request. Review CrowdStrike’s data handling before you add CrowdStrike AIDR to Access Policies that carry sensitive content. For exactly what Aembit sends, see Data shared for inspection.

Where Aembit records a provider’s decisions

Section titled “Where Aembit records a provider’s decisions”

Aembit records every decision a Content Security Provider makes, so you can confirm what a provider decided:

  • MCP workload events record the decision for each MCP message under application.mcp.contentSecurity.
  • Access Authorization Events name the provider that Aembit identified for the Access Policy.
  • Audit Logs record when you create, update, or delete a provider, under the ContentSecurity category. An entry names who made the change, not which settings or MCP tool rules changed.

Each provider writes to its own field inside the contentSecurity element, so the field name identifies which provider acted: crowdStrikeAidr for CrowdStrike AIDR, and aembitMcpToolsAcl for MCP Tool Access Control.

To report on provider decisions in your own system, send workload events to a log stream.