What is MCP, and why do businesses need a safe gateway?
July 6, 2026 · 5 min read
MCP is a shared standard that lets AI tools plug into services the way USB-C lets any device plug into one port. A business needs a controlled gateway so that connection stays scoped, approved, and recorded.
The short answer
MCP is an open standard that lets AI tools connect to services in one common language. Think of it like USB-C for AI. Before a single standard, every connection was its own custom job. With one shared plug, any compatible tool can connect the same way.
That convenience is powerful, and it is exactly why a business needs a controlled gateway in front of it. Riley is that gateway. It gives your AI tools a way in that is scoped to what you allow, gated by your approval, and recorded so you always know what happened.
The USB-C idea, in plain words
For years, connecting an AI tool to a service meant a bespoke integration each time. MCP replaces that with one standard shape. A tool that speaks MCP can connect to any service that speaks MCP, without a custom build for each pairing.
The upside is obvious: your Claude, your Cursor, your ChatGPT where supported, and other clients can all reach the same service through one standard. The catch is just as obvious: a standard plug is only as safe as what sits behind the socket.
Why an open plug needs a controlled gateway
A connection that any tool can make is a connection you have to govern. Without a gateway, an AI client could reach further into your business than you intended, act without a checkpoint, and leave no trail. That is not a hypothetical risk. It is the default if nothing sits in the middle.
A safe gateway does three jobs. It scopes access so a client only gets the specific tools you grant. It gates action so anything that changes the outside world waits for a human. And it records everything so there is always an answer to what happened.
How Riley is the gateway
Riley exposes a documented MCP endpoint, but access runs through per-workspace keys you mint yourself, that are shown once, and that you can revoke at any time. Whatever client you connect gets Riley's specific tools and nothing beyond them.
Every request that arrives through a connected AI client passes through the same approval gate as everything else. No surface gets a side door around your approvals. And each action is written to the ledger with the surface it came from, so a connection through MCP is as accountable as work you did by hand in the dashboard.
- Scoped keys: each client gets only the tools you allow, with a key you can revoke.
- Approval gates: external writes wait for a human, whoever asked for them.
- Receipts: every action is recorded and provable after the fact.
Frequently asked questions
- Is MCP something I have to understand to use Riley?
- No. If you work in the dashboard, you never touch MCP directly. It only matters when you want to connect Riley into another AI tool, and even then the setup is a short guided step.
- Can a connected AI tool bypass my approvals?
- No. Requests from any connected AI client pass through the same approval gate as everything else. External writes wait for a human, no matter which surface asked.
- What happens if a key is exposed?
- Keys are scoped to your workspace and revocable. You mint a new one and revoke the old one from Settings, and the old key stops working immediately. Scheduled automatic rotation is not built yet, so today rotation is a manual step you control.