Use ChangeGraph
Read-only MCP tools, auth, and Investigation Agent boundaries.
MCP server
ChangeGraph exposes a read-only MCP server so external agents can inspect incidents without mutating production.
Start locally
From the repo root:
pnpm mcp
The server speaks stdio (MCP TypeScript SDK). Auth: set CHANGEGRAPH_MCP_TOKEN (alias MCP_AUTH_TOKEN) when exposing beyond localhost. If unset, tools still run for local fixture smoke (documented in README).
Tools (MVP)
| Tool | Purpose |
|---|---|
list_incidents | List fixture scenarios + optional ingest-store incidents for the tenant |
get_incident | Full incident: candidates, evidence, timeline, LKG, window expansion fields |
get_evidence_package | Sanitized LLM-safe evidence package (no secrets) |
Tool names are locked in MCP_TOOL_NAMES / tests. Handlers live under src/mcp/tools.ts.
Design rules
- Domain model stays independent of MCP
- Tools are read-oriented for MVP: no arbitrary SQL, no prod mutations
- Mutations (if added later) require explicit human approval
- Auth token checked before tool execution when configured
Investigation Agent boundaries
The Investigation Agent is the in-repo Mastra-compatible workflow investigate_incident (src/lib/agents/mastra-runtime), not a free-form prod mutator:
- On by default. Set
INVESTIGATION_AGENT_ENABLED=0to opt out. - Read-only tool loop over deterministic evidence
- Does not rewrite scores or candidate ranks
- Requires an LLM provider for the explain step
The MCP server (stdio, read-only) is separate from the MCP client. The client is a gated read adapter (FEATURE_MCP_CLIENT, default off). It fails closed as not_configured without a registry. Scoring remains MCP-agnostic.
MCP client
FEATURE_MCP_CLIENT (default off) fetches allowlisted read tools as capped, redacted evidence (src/lib/mcp-client/). With the gate on and no registry, the fetch fails closed as not_configured. Those tools are evidence adapters, not core domain types. The full multi-server registry is deferred. The Mastra mcp-hook in src/lib/agents/mcp-hook.ts stays a stub.