haver-governance-mcp
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| HAVER_GOV_DIR | No | Override the default data directory (~/.haver-governance). If not set, defaults to ~/.haver-governance. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| register_agentA | Register an AI agent with a stable identity, owner, role, and permission scopes. Scopes use the form 'action:resource' (e.g. 'read:labs'), and '*' wildcards are allowed. |
| check_permissionA | Decide whether a registered agent may perform an action on a resource, based on its scopes and status. Recalled or unknown agents are always denied. The decision is written to the audit log. |
| record_actionB | Append a tamper-evident audit record for something an agent did. Entries are hash-chained, so any later modification is detectable. |
| get_audit_trailC | Return recent audit entries, optionally filtered by agent or resource. |
| verify_audit_integrityA | Recompute the audit hash chain and report whether the log is intact or has been tampered with. |
| recall_agentA | Revoke an agent so all future permission checks deny it. Use when an agent misbehaves or is decommissioned. The recall is audited. |
| scan_phiA | Heuristically scan text for common protected health information (SSN, MRN, email, phone, dates) and return findings plus a redacted copy. A guardrail, not a certified de-identification tool. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 7 tools
Each tool has a unique purpose: permission checking, audit trail retrieval, agent recall, action recording, agent registration, PHI scanning, and integrity verification. No two tools overlap or could be confused.
All tools follow a consistent verb_noun pattern (e.g., check_permission, register_agent, scan_phi) with imperative verbs and descriptive nouns. No mixing of styles or vague names.
Seven tools is well-scoped for a governance server covering agent lifecycle, permissions, audit, and integrity. Each tool earns its place without being excessive or insufficient.
The tool surface covers core CRUD-like operations for agents (register, recall), permissions (check), audit (record, get, verify integrity), and adds a guardrail (scan_phi). No obvious gaps for the domain.