Palm92 Governed Agent MCP
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Palm92 Governed Agent MCPevaluate this proposed action for policy compliance and risk"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Palm92 Governed Agent MCP
Human-in-the-loop Agentic AI and MCP governance prototype for risk, compliance, evidence verification, policy checks, human approval and audit trails.
AI investigates. Humans decide.
Why this project exists
AI agents can search, reason and use tools, but consequential actions need governance. This project demonstrates a practical control layer around an agentic workflow so that evidence is traceable, policy is checked, sensitive actions can be stopped for human approval, and decisions can be audited.
Related MCP server: enterprise-agent-lab
Core workflow
Request → Evidence → Agent investigation → Policy check → Risk classification → Human approval (when required) → Action → Audit trail
The prototype is designed around five questions:
What is the agent being asked to do?
What evidence supports its proposed action?
Which policy or control applies?
Does a human need to approve the action?
Can the final decision be reconstructed later?
Governance controls
Evidence provenance — record the source and context used by the agent.
Least privilege — tools should expose only the access required for the task.
Policy checks — evaluate proposed actions against explicit rules.
Human-in-the-loop approval — consequential actions pause for review.
Audit logging — preserve request, evidence, checks, approvals and outcomes.
Data minimisation — avoid collecting unnecessary sensitive information.
Fail-safe behaviour — uncertainty or missing evidence can trigger escalation rather than silent execution.
MCP and agentic AI
The project explores how Model Context Protocol (MCP)-style tool access can be governed rather than treated as unrestricted automation. The intended pattern is:
User / System Request
|
v
Governed Agent
|
+--> Evidence tools
+--> MCP / external tools
|
v
Policy & Risk Gate
|
+----+----+
| |
Low risk Approval required
| |
v v
Action Human reviewer
|
v
Action
|
v
Audit recordExample use cases
GRC evidence collection and verification
Third-party risk review
Access-control evidence review
Fraud and verified-request workflows
AI governance approval gates
Compliance case preparation
Project status
Status: Early prototype / portfolio build
This repository documents an evolving prototype. It is not presented as a production compliance platform and does not replace legal, regulatory, financial or security advice.
Planned repository structure
docs/
architecture.md
governance-controls.md
risk-register.md
testing-plan.md
examples/
sample-evidence.json
sample-audit-record.json
src/
agent/
policy/
approval/
audit/Roadmap
Define the governed-agent problem and control objectives
Document the human-in-the-loop workflow
Add sample policy and evidence handling
Implement policy/risk gate
Implement human approval state
Implement structured audit event model
Add MCP tool demonstration
Add test scenarios for allowed, denied and escalated actions
Add a visual reviewer demo interface
Persist append-only audit events in a production-grade store
Add a fuller threat model and abuse-case test suite
Host a public visual demo
Record a short end-to-end demonstration
Recruiter / reviewer walkthrough
A reviewer should be able to use this repository to assess practical thinking across:
AI Governance · GRC · Risk & Compliance · Agentic AI · MCP · Human-in-the-Loop Controls · Evidence Traceability · Auditability · Responsible AI
Palm92 Intelligence
Palm92 Intelligence builds practical, human-governed AI concepts around real-world risk, compliance, trust and operational problems.
Principle: AI investigates. Humans decide.
Project owner: Faith Wright
Portfolio: Palm92 Intelligence
Working MCP demonstration
The repository now includes mcp_server.py, an MCP-compatible server exposing governed tools for policy evaluation, governance-record creation and explicit human decisions. It intentionally does not expose unrestricted consequential execution.
Visual demo interface
A Streamlit reviewer interface is available in demo/app.py. It shows the policy decision, final state, approval gate and structured audit record for synthetic requests.
pip install -r requirements.txt
streamlit run demo/app.pyCurrent maturity
Working local reference prototype. The repository contains executable governance logic, automated tests, a real MCP-compatible FastMCP server with three governed tools, and a Streamlit visual demo. External consequential actions remain simulated by design.
Truthful portfolio boundary: this is not claimed as a continuously hosted MCP service, production compliance platform, or live integration with payment, identity, access-control or employer systems. The MCP server is a runnable local reference implementation; the visual interface is a runnable local reviewer demo.
Public deployment
The repository is deployment-ready as a single ASGI application in app.py.
Public routes:
/— reviewer-friendly visual governance demo/api/evaluate— synthetic governance evaluation endpoint/mcp— Streamable HTTP MCP endpoint/health— deployment health check
Deployment status
Code is deployment-ready. Public Vercel deployment is the next step.
The deployed portfolio version will continue to simulate consequential external actions by design. It must not be described as a production compliance platform or live payment/access-control integration.
This server cannot be deployed
Maintenance
Related MCP Connectors
Human-in-the-loop review and approval for AI agents. Audit trail, approval policies, native MCP.
Runtime permission, approval, and audit layer for AI agent tool execution.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Deterministic allow/require_approval/deny verdicts for agent actions, before they happen.
Related MCP Servers
- FlicenseNot gradedqualityBmaintenanceEnables AI coding agents to evaluate actions against team-defined policies, record decisions, and obtain human approvals for potentially risky operations.57 npm1-
- FlicenseNot gradedqualityCmaintenanceEnables controlled AI-agent access to enterprise-shaped tools with a deny-by-default gated write path, human approval, dry-run execution, and append-only audit logging.1-
- AlicenseBqualityBmaintenanceProvides AI governance and action-assurance primitives, enabling trust scoring, policy-based allow/deny decisions, risk assessment, EU AI Act compliance checks, and an emergency kill-switch for autonomous agents.639 npmMIT

@quirna/mcpofficial
AlicenseNot gradedqualityBmaintenanceEnables AI agents to request human approval before consequential actions, with policy-based routing, phone-based approver decisions, and signed audit evidence.351 npmMIT