Model Context Protocol
Open connections. Controlled execution.
OYYO is designed to act as an MCP client, an MCP server and an MCP gateway, with identity, policy, credential isolation and audit in the middle.
What this layer does
Designed around the job, not the prompt.
R0, Public read
Read a public page or public documentation.
R1, Private read
Read a connected file, search a CRM, inspect a private repository.
R2, Reversible create
Create a draft, an internal note or a proposed task.
R3, External or material change
Send email, publish, change CRM state, merge code. Approval required.
R4, Sensitive and high impact
Money movement, deletion, production deployment, credential or permission change.
Capability scope
The full surface, stated plainly.
Each item is described as designed. Status labels on this page show what is shipped and what is planned.
OYYO as MCP client
- Discover tools
- Use resources
- Use prompts and templates
- Read tool metadata
OYYO as MCP server
- OYYO Memory
- Project knowledge
- OYYO Language
- OYYO Growth
- OYYO Artifacts
- Benchmark data
- Approved local tools
- Runtime information
OYYO as MCP gateway
- Identity
- Allow and deny policy
- Capability scope
- Credential isolation
- Risk classification
- Approval
- Rate limits
- Audit
Security principles
- Discovery is not permission
- Tool identity matters
- Credentials stay isolated
- Parameters are inspected
- Tool output is untrusted content
- Every call is auditable
Agentic does not have to mean opaque.
This capability is part of the published OYYO roadmap. It is described here as designed and planned, not as shipped software.
Continue
Related parts of OYYO.
Every OYYO layer shares one context, one memory and one permission model.
Think. Create. Execute.
One intelligence. One workspace. One place for everything.
OYYO is being built in public against a versioned release line. Join the early access list and follow the roadmap.