Skip to main content

Overview

Formal governs how people and AI agents use MCP servers, skills, and LLM providers. The AI Tools section of the groups these pages: Insights adds AI-generated security findings about LLM traffic.

How the Pieces Fit

  1. Capture AI traffic. Formal sees AI activity that flows through the Formal Endpoint or a .
  2. Discover. Shadow AI and the usage pages show which MCP servers, skills, models, and AI clients people use.
  3. Decide. Add approved items to the Catalog with access controls. Set Guardrails for everything else.
  4. Handle exceptions. Employees request access from the employee Catalog. Admins decide in Access Requests.
  5. Investigate. Review Insights, Logs, and the usage pages for risky activity.

Capture AI Traffic

Each page reads logs, so it only shows traffic that Formal proxies: This network rule intercepts LLM and MCP traffic from known AI agents on macOS:
Verify: Use an AI agent on a device that runs the Endpoint. Then open Logs, select the Endpoint source, and filter on resource.technology:llm.

The Catalog

The Catalog lists the MCP servers and skills your organization approves. Click Add MCP to add a server from a template or a custom endpoint. See MCP Gateway for the steps. Click Add Skill to add a skill from its SKILL.md. Adding items requires the Resource permission. Changing access requires the Policies permission.

Access Controls

Open an MCP server or a skill and go to Access Controls. Under Who can use this MCP? or Who can use this skill?, choose:
  • Everyone: Every user can use it.
  • Specific Users: Only the selected users and groups can use it.
  • No One: Nobody can use it. Formal keeps the item in the Catalog as blocked.
For an MCP server, you can also answer Which tools can they use? with All Tools or Specific Tools. Formal enforces restrictions with a generated . It stores Message shown when access is denied as the policy’s reason, which appears in Logs. Blocked users currently see Formal’s standard block message instead. An item open to Everyone, with All Tools for an MCP server, needs no policy, so Formal deletes it. You can find these policies on the Policies page, tagged as described in Policy Tags. Edit access from the Catalog rather than in the policy code.

The Employee Catalog

Employees use the employee Catalog at catalog.formal.ai. There they can:
  • Browse the MCP servers and skills available to them
  • Follow setup steps for their MCP clients
  • Link upstream accounts and approve MCP clients during sign-in
  • Request access to MCP servers, or exceptions to policies that blocked them
  • Review their governed AI activity and their requests
Control who can use the employee Catalog with the Catalog application in Permissions. See Grant access to the Catalog.

Next Steps

Shadow AI

Review unmanaged MCP servers and skills

Guardrails

Block MCP servers and skills outside the Catalog

Access Requests

Approve employee requests

AI Usage

See which AI tools people use