What does the agent actually call?
A tool. The hosted MCP server at protocol.decionis.com/mcp exposes decionis.evaluate_decision over streamable HTTP with an org API key; the @decionis/mcp npm package exposes the same check over stdio for local hosts. The agent describes the action it wants to take; the verdict — ALLOW, ESCALATE, or BLOCK — comes back before the consequential tool runs.
MCP surfaces and setup