Overview
Formal governs how people and AI agents use MCP servers, skills, and LLM providers. The AI Tools section of the groups these pages:
Insights adds AI-generated security findings about LLM traffic.
How the Pieces Fit
- Capture AI traffic. Formal sees AI activity that flows through the Formal Endpoint or a .
- Discover. Shadow AI and the usage pages show which MCP servers, skills, models, and AI clients people use.
- Decide. Add approved items to the Catalog with access controls. Set Guardrails for everything else.
- Handle exceptions. Employees request access from the employee Catalog. Admins decide in Access Requests.
- Investigate. Review Insights, Logs, and the usage pages for risky activity.
Capture AI Traffic
Each page reads logs, so it only shows traffic that Formal proxies:
This network rule intercepts LLM and MCP traffic from known AI agents on macOS:
resource.technology:llm.
The Catalog
The Catalog lists the MCP servers and skills your organization approves. Click Add MCP to add a server from a template or a custom endpoint. See MCP Gateway for the steps. Click Add Skill to add a skill from itsSKILL.md.
Adding items requires the Resource permission. Changing access requires the Policies permission.
Access Controls
Open an MCP server or a skill and go to Access Controls. Under Who can use this MCP? or Who can use this skill?, choose:- Everyone: Every user can use it.
- Specific Users: Only the selected users and groups can use it.
- No One: Nobody can use it. Formal keeps the item in the Catalog as blocked.
reason, which appears in Logs. Blocked users currently see Formal’s standard block message instead. An item open to Everyone, with All Tools for an MCP server, needs no policy, so Formal deletes it. You can find these policies on the Policies page, tagged as described in Policy Tags. Edit access from the Catalog rather than in the policy code.
The Employee Catalog
Employees use the employee Catalog at catalog.formal.ai. There they can:- Browse the MCP servers and skills available to them
- Follow setup steps for their MCP clients
- Link upstream accounts and approve MCP clients during sign-in
- Request access to MCP servers, or exceptions to policies that blocked them
- Review their governed AI activity and their requests
Next Steps
Shadow AI
Review unmanaged MCP servers and skills
Guardrails
Block MCP servers and skills outside the Catalog
Access Requests
Approve employee requests
AI Usage
See which AI tools people use