Skip to main content
Glama
mo7-s3d690

Iron Bridge Construction MCP Equipment Safety Server

by mo7-s3d690

Iron Bridge Construction — MCP Equipment Safety Server

Company & Problem

Iron Bridge Construction manages heavy equipment (cranes, excavators, scaffolding) across multiple job sites.
Before this system, site workers used paper checklists. Nothing stopped an uncertified operator from taking a crane, and nothing forced a human supervisor sign-off when the work was near power lines.

The fix: an MCP server that gives an LLM scoped, safe access to equipment data. The model never talks to the database directly. Every write that carries real risk is gated by capability checks, role changes, elicitation, and sampling.

Related MCP server: MCP Airlock

Protocol Concerns Mapping

#

Concern

How it appears in this system

1

Capability negotiation

Server checks ctx.session.check_client_capability(...) for elicitation+sampling before attempting either, inside request_equipment's high-risk branch — not just via try/except after the fact. The demo client only gets this far because it registers real sampling_callback + elicitation_callback on ClientSession.

2

Notifications

Worker starts with read-only tools; approve_equipment_request is not registered at all. After authenticate_supervisor, the server calls mcp.add_tool(...) to register it for the first time, then pushes tools/list_changed. The tool set genuinely changes, not just the notification.

3

Elicitation

request_equipment for high-risk items (crane / near power lines) pauses mid-call and asks a human supervisor for explicit confirmation.

4

Resources

Safety policies (lifting-safety, electrical-proximity) are exposed as resources, not tools.

5

Prompts

Reusable template prepare-equipment-receipt that takes {request_id}.

6

Sampling

Before final approval of a high-risk request the server asks the client's model to draft a short risk summary; result is stored in audit log.

7

Progress tracking

generate_site_compliance_report walks every request and reports 25/50/75/100 %.

8

Defensive tool design

Strict JSON Schema (additionalProperties: false), server-side jsonschema validation, parameterized SQL, and handler-level authorization.

Transport

  • Development: stdio (default).

  • Demo / multi-site: Streamable HTTP (MCP_TRANSPORT=streamable-http).

Commit history shows the transition from stdio-only to HTTP support.

Quick Start

python -m venv .venv
source .venv/bin/activate   # or .venv\Scripts\Activate.ps1 on Windows
pip install -r requirements.txt
cp .env.example .env        # set SUPERVISOR_PIN; ANTHROPIC_API_KEY is optional
python db/init_db.py
python agent/client.py      # starts stdio server automatically

mcp is pinned to 1.29.0 in requirements.txt — mcp>=1.1.0 would let a fresh install pull mcp==2.0.0, which removed the fastmcp module this server is built on.

HTTP mode:

export MCP_TRANSPORT=streamable-http
export MCP_HOST=127.0.0.1
export MCP_PORT=8000
python -m mcp_server.server
# endpoint: http://127.0.0.1:8000/mcp

Tool Comparison

Tool

Read/Write

Needs elicitation?

Needs sampling?

Notes

check_worker_certification

read

no

no

always available

get_equipment_status

read

no

no

always available

request_equipment

write

yes if high-risk

yes if high-risk

creates PENDING request

authenticate_supervisor

write (session)

no

no

triggers tools/list_changed

approve_equipment_request

write

no

no

only after supervisor auth

generate_site_compliance_report

read (report)

no

no

progress updates

If a client connects without elicitation or sampling capability, high-risk requests return NOT_SUBMITTED and nothing is written to the database.

Folder Layout

db/                 schema, seed, ERD, init script
mcp_server/         server, schemas, service layer, database helpers
agent/              demo client that performs the full handshake
docs/               progressive code parts for team commits
issues/             ready-to-paste GitHub Issue bodies (one per concern)

Team Workflow (4 sequential parts per concern)

See docs/ and issues/. Each concern is an independent GitHub Issue.
Code for each concern is delivered in 4 progressive commits so every teammate has a visible contribution.

F
license - not found
-
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    C
    maintenance
    Policy enforcement gateway for MCP tool calls, evaluating every tool invocation against declarative YAML policies (allow/deny/escalate-to-human), generating cryptographic hash-chained audit receipts, and including built-in content safety scanning.
    Last updated
    2
    MIT
  • A
    license
    C
    quality
    D
    maintenance
    Enables secure, zero-trust access to MCP tools through short-lived, signed capability leases that bind tool execution to specific sessions, intents, and constraints. Prevents prompt injection attacks and privilege escalation with dynamic risk scoring, policy enforcement, and tamper-evident audit logging.
    Last updated
    4
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Security-enforcing MCP proxy that sits between an AI agent and any number of downstream MCP servers, intercepting every tool call through a capability-token policy gateway that can allow, deny, or escalate to human approval before the call reaches any real tool. It also exposes built-in operator tools for approval workflows, audit trail queries, token management, voice/HUD output, and hierarchical
    Last updated
    21
    11
    Apache 2.0
  • A
    license
    -
    quality
    A
    maintenance
    Security gateway for MCP tool calls. Sits between your LLM client and MCP servers, enforcing per-tool policies (allow/block/approve/read-only), logging every call, and pausing dangerous operations for human approval in terminal or Slack.
    Last updated
    1
    MIT

View all related MCP servers

Related MCP Connectors

  • Runtime permission, approval, and audit layer for AI agent tool execution.

  • Operate your Linux servers from your LLM. Every action runs through an auditable allowlist.

  • Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/mo7-s3d690/ironbridge-mcp-project'

If you have feedback or need assistance with the MCP directory API, please join our Discord server