ai.geodesiclabs/governance-platform
REMOTE · APP.GEODESICLABS.AI · SCANNED SEP 21
Pre-execution governance for AI agents. Deterministic PASS/FAIL/REVIEW verdicts, replayable proof.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (delete_blueprint). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability81
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 5678 tokens (~149/item across 38 items; 37 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 39 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the ai.geodesiclabs/governance-platform MCP server?
ai.geodesiclabs/governance-platform is a hosted endpoint at https://app.geodesiclabs.ai/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · app.geodesiclabs.ai
claude mcp add --transport http ai-geodesiclabs-governance-platform 'https://app.geodesiclabs.ai/mcp'
{
"mcpServers": {
"ai-geodesiclabs-governance-platform": {
"url": "https://app.geodesiclabs.ai/mcp"
}
}
} {
"servers": {
"ai-geodesiclabs-governance-platform": {
"type": "http",
"url": "https://app.geodesiclabs.ai/mcp"
}
}
} [mcp_servers.ai-geodesiclabs-governance-platform] url = "https://app.geodesiclabs.ai/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ai-geodesiclabs-governance-platform": {
"type": "remote",
"url": "https://app.geodesiclabs.ai/mcp",
"enabled": true
}
}
} openclaw mcp add ai-geodesiclabs-governance-platform --url 'https://app.geodesiclabs.ai/mcp' --transport streamable-http
mcp_servers:
ai-geodesiclabs-governance-platform:
url: "https://app.geodesiclabs.ai/mcp" {
"McpServers": {
"ai-geodesiclabs-governance-platform": {
"Transport": "http",
"Url": "https://app.geodesiclabs.ai/mcp"
}
}
} assistant mcp add ai-geodesiclabs-governance-platform -t streamable-http -u 'https://app.geodesiclabs.ai/mcp'
{
"mcpServers": {
"ai-geodesiclabs-governance-platform": {
"type": "http",
"url": "https://app.geodesiclabs.ai/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 14 Sept 26 0
- Tool “compare_semantic_equivalence” rewrote its description, which is the text the model reads security
- Tool “govern_inference” rewrote its description, which is the text the model reads security
- Tool “recent_inference_decisions” rewrote its description, which is the text the model reads security
- Tool “verify_replay” rewrote its description, which is the text the model reads security
- “analyze_anomaly” added an optional parameter “blueprint” cosmetic
- “compare_semantic_equivalence” added an optional parameter “constraints_a” cosmetic
- “compare_semantic_equivalence” added an optional parameter “constraints_b” cosmetic
- “compare_semantic_equivalence” added an optional parameter “field_mapping” cosmetic
- “compare_semantic_equivalence” added an optional parameter “rules_a” cosmetic
- “compare_semantic_equivalence” added an optional parameter “rules_b” cosmetic
- “get_inference_trace” added an optional parameter “blueprint” cosmetic
- “get_inference_trace” added an optional parameter “blueprint_version” cosmetic
- “govern_inference” added an optional parameter “blueprint” cosmetic
- “recent_inference_decisions” added an optional parameter “blueprint” cosmetic
- “recent_inference_decisions” added an optional parameter “blueprint_version” cosmetic
- “verify_certificate” added an optional parameter “formal_constraints” cosmetic
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
- Stability: 0.97 → pass security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 7 Aug 26 0
- The server no longer declares the “experimental” capability functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Stability: unverified → 0.03 ▲ functional
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Probed https://app.geodesiclabs.ai/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=geodesiclabs.ai | CN=WE1,O=Google Trust Services,C=US | 30 Aug 2026 | 28 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 3be684a110c2b03713aee25d9179d6a1 |
| SANs: geodesiclabs.ai, *.geodesiclabs.ai | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of app.geodesiclabs.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| geodesiclabs.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=15552000 |
| x-content-type-options | nosniff |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://app.geodesiclabs.ai/mcp | Verified | 200 | |
| http (plaintext) | http://app.geodesiclabs.ai/mcp | HTTPS enforced | 301 | https://app.geodesiclabs.ai/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
account_status ~53
This account's plan, key usage, Blueprint counts, and the deployed platform build fingerprint (version, build, deployed).
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
No output schema declared.
No examples provided.
analyze_anomaly ~97
Explain whether a record fits the usual pattern for records like it, and which fields stand out. No Blueprint required.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Discovery namespace used by discover_patterns |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
approve_rule ~71
Promote a rule discovered by discover_patterns into Blueprint-ready form.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| rule_id | string | yes | Discovered rule ID from discover_patterns |
No output schema declared.
No examples provided.
authorize_execution ~141
Go/no-go for a real-world action (payment, filing, API write): runs full validation, then the Blueprint's execution gate. authorized=true only on PASS; REVIEW means do not proceed automatically. Different from validate: validate asks is this data correct, authorize_execution asks should this action happen.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | yes | Blueprint name (workflow_name) to use |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
check_blueprint_health ~123
Static pre-deploy analysis of a Blueprint's rule set. Returns a health verdict - healthy, acceptable, fragile, rigid, split, brittle_islands, or unsatisfiable - with advice, including joint conflicts pairwise checks miss.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| config | object | – | Raw blueprint config with derivation_rules and formal_constraints (used when 'blueprint' is not given) |
No output schema declared.
No examples provided.
check_drift ~98
Check whether recent submissions still match the established pattern for this Blueprint. Returns a stability verdict and observation count.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
check_realization ~122
Structural realization analysis of a payload against the Blueprint's reference configuration (requires a 'realization' block; otherwise status=skipped). Diagnostics-tier tool; prefer validate or analyze_anomaly for standard checks.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
compare_semantic_equivalence ~196
Compare two payloads under the dual-hash design: content_hash is content_hash normalizes field order and numeric formatting. Semantic comparison preserves field roles; renaming requires an explicit bijection. With supplied rules, scalar types and whitespace remain significant. Structural similarity alone does not establish decision equivalence.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| constraints_a | array | – | Formal constraints for A |
| constraints_b | array | – | Formal constraints for B |
| field_mapping | object | – | Explicit one-to-one field renaming from A to B |
| payload_a | object | yes | First structured payload (arbitrary JSON object) |
| payload_b | object | yes | Second structured payload to compare against payload_a |
| rules_a | array | – | Derivation rules for A |
| rules_b | array | – | Derivation rules for B |
No output schema declared.
No examples provided.
counterfactual ~130
Run the same data under two rule sets and compare which future states remain valid - what-if analysis for rule changes.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| constraints_b | array | – | Alternative constraints (rule set B) |
| rules_b | array | – | Alternative derivation rules (rule set B) |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
create_blueprint ~474
Create a Blueprint - the governance contract validation runs against. A Blueprint defines what correct means for your data: fields, the math that must hold between them, and acceptable ranges. Start from load_rule_pack or discover_patterns if you have no rules yet; invoke the blueprint_guide prompt for the full rule/constraint reference. Returns the new Blueprint's API key.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| customer_name | string | yes | Organization or project name (also used for storage folder naming) |
| derivation_rules | array | – | Math rules as objects. Types: add, subtract, multiply, divide, round, copy, sum (multi-operand), items_multiply, items_sum. Each needs 'type' plus its fields; see the blueprint_guide prompt |
| derived_fields | array | – | Field names the platform computes from other fields, e.g. ['subtotal','total'] |
| enable_anomaly_detection | boolean | – | Flag records that break no rules but do not fit the reference pattern |
| enable_drift_tracking | boolean | – | Track pattern stability across batches |
| extracted_fields | array | – | Field names the agent extracts from source data, e.g. ['vendor','qty','unit_cost'] |
| formal_constraints | array | – | Constraint objects. Types incl. magnitude_anchor {field,min,max}, relative_anchor {field,reference_field,ratio_min,ratio_max}, max_action_threshold {field,threshold,on_violation}, required_fields {fi… |
| mode | string | – | observe: platform checks the agent's work; enforce: platform computes derived fields itself |
| require_coherence | boolean | – | Check cross-field plausibility |
| require_consistency | boolean | – | Check internal field consistency |
| require_high_assurance | boolean | – | Strictest mode: every check must pass |
| require_math | boolean | – | Validate mathematical relationships |
| require_provenance | boolean | – | Require extraction source locations for fields |
| semantic_checks | array | – | Domain-specific semantic check objects |
| workflow_name | string | yes | Unique Blueprint identifier; the value passed as 'blueprint' in validate |
No output schema declared.
No examples provided.
create_chain ~140
Create a multi-agent sequential chain: stages validate in order against one Blueprint, repairs propagate forward, TTL bounds the run. Siblings: submit_chain_stage advances the chain; handoff_audit verifies a transition between stages. Returns chain_id.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | yes | Blueprint governing all stages of the chain |
| stages | array | yes | Stage definitions, e.g. [{'stage_name':'extract','agent_name':'PDF Agent'}]; minimum 2 |
| ttl | integer | – | Chain timeout in seconds; stages cannot advance after expiry |
No output schema declared.
No examples provided.
decompose_failure ~270
Split the error between original and corrected values into direct rule violations, boundary violations, and systemic structural error, with per-field contributions. Use with a known-correct version to diff against; use analyze_anomaly when you only have the suspicious payload. Diagnostics-tier tool.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Load rules from this Blueprint instead of passing them inline |
| corrected_values | object | yes | Corrected/expected numeric field values as {field: number} |
| derivation_rules | array | – | Math rules as objects. Types: add, subtract, multiply, divide, round, copy, sum (multi-operand), items_multiply, items_sum. Each needs 'type' plus its fields; see the blueprint_guide prompt |
| formal_constraints | array | – | Constraint objects. Types incl. magnitude_anchor {field,min,max}, relative_anchor {field,reference_field,ratio_min,ratio_max}, max_action_threshold {field,threshold,on_violation}, required_fields {fi… |
| original_values | object | yes | Original numeric field values as {field: number} |
No output schema declared.
No examples provided.
delete_api_key ~165
Permanently delete one of the caller's API keys. DESTRUCTIVE — agents using the deleted key will receive auth errors immediately. The Blueprint a key was tied to (if any) is NOT affected; only the credential is revoked. To delete a Blueprint and all its keys, use delete_blueprint. The target key can be specified two ways: - As the full key string (gai_...). - As a key_id (SHA-256 hash from list_api_keys).
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| confirm | boolean | – | Must be true to confirm this irreversible action |
| key_to_delete | string | yes | The gai_ key to delete |
No output schema declared.
No examples provided.
delete_blueprint ~86
Permanently delete a Blueprint and revoke its API keys. Irreversible; requires confirm=true. Account-level keys are unaffected.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| confirm | boolean | – | Must be true to confirm this irreversible action |
| workflow_name | string | yes | Blueprint to delete; its API keys are revoked |
No output schema declared.
No examples provided.
discover_patterns ~95
Learn candidate validation rules and structural document types from a batch of your records, deterministically - no Blueprint required. Promote results with approve_rule. Source data is not stored.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| documents | array | yes | List of structured records (objects) to analyze |
No output schema declared.
No examples provided.
forecast ~147
Deterministic forward reasoning: from the current data state, generate and rank the valid next states reachable under the Blueprint's rules.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| max_branches | integer | – | Branches per step, 1-10 |
| max_depth | integer | – | Search depth, 1-10 |
| rank_by | string | – | Ranking criterion for returned paths |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
geometric_confidence ~96
Summarize an already-computed state_vector into a confidence level (high/medium/low) with a recommendation. Post-hoc digest - use analyze_anomaly or check_drift for fresh analysis of raw data.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| state_vector | object | yes | state_vector object from a prior validate or get_execution_trace result |
No output schema declared.
No examples provided.
get_execution_trace ~119
Run validation and return the per-node execution trace (node names, deterministic flags, timing) plus the verdict and determinism hash. Use validate for normal operation; this is for debugging and audit preparation.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
get_inference_trace ~98
Retrieve the durable audit trail for a governed generation: every recorded decision and its reasons.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint namespace used when recording the trace |
| blueprint_version | string | – | Optional historical blueprint_version hash returned by govern_inference |
| inference_id | string | yes | Caller-chosen ID grouping the steps of one generation |
No output schema declared.
No examples provided.
govern_inference ~234
Quality-govern an in-progress AI generation step BEFORE its output is used (complements validate, which checks finished documents). Returns an action - STOP, CONTINUE, REPAIR_REGION, REUSE_MOTIF, REVIEW, ESCALATE - with a plain-language explanation. Structural scores do not establish task correctness. Check safe_to_finalize and acceptance coverage. Persistence success is reported; read traces in the same Blueprint namespace.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Owned Blueprint namespace for the trace |
| constraints | object | – | Optional governance constraint config object |
| inference_id | string | yes | Caller-chosen ID grouping the steps of one generation |
| payload | object | yes | Task-type payload: generative_text {text,...}; retrieval {query,candidates}; generic {features} |
| source | string | – | Free-form caller label recorded for audit |
| step_index | integer | – | Step number within this generation (0-based) |
| task_type | string | yes | Kind of generation step being governed |
No output schema declared.
No examples provided.
handoff_audit ~149
Audit a handoff between two chain stages: a context capsule of verified facts from the prior stage, and (if proposed_data is given) a compatibility verdict that catches fields mutated in transit. Siblings: create_chain, submit_chain_stage.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| chain_id | string | yes | Chain identifier returned by create_chain |
| from_stage | string | yes | Completed stage name (agent A) |
| proposed_data | object | – | Data agent B intends to submit; checked for mutation against agent A's verified fields |
| to_stage | string | yes | Stage about to start (agent B) |
No output schema declared.
No examples provided.
list_api_keys ~42
List this account's API keys (masked) with their Blueprint bindings.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
No output schema declared.
No examples provided.
list_blueprints ~60
List the Blueprints on this account with field/rule/constraint counts and mode. Use the returned workflow_name as 'blueprint' in validate.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
No output schema declared.
No examples provided.
load_rule_pack ~86
Load a prebuilt Blueprint template (invoices, timecards, legal, POs, claims). Call without pack_id to list packs; then create_blueprint to save a customized copy.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| pack_id | string | – | Rule pack ID; omit to list available packs |
No output schema declared.
No examples provided.
profile_blueprint_robustness ~105
Sweep the Blueprint's numeric constraint bounds and report verdict stability: the stable band, the scales where the verdict first flips, and advice. Use before deploying bound changes.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| config | object | – | Raw blueprint config to profile (used when 'blueprint' is not given) |
No output schema declared.
No examples provided.
recent_inference_decisions ~103
Recent generation-governance decisions in this owner's Blueprint version.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | – | Optional action filter (STOP, CONTINUE, REVIEW, ...) |
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint namespace used when recording the trace |
| blueprint_version | string | – | Optional historical blueprint_version hash returned by govern_inference |
| limit | integer | – | Maximum rows to return |
No output schema declared.
No examples provided.
reject_rule ~82
Reject a discovered candidate rule so it will not be promoted into a Blueprint. Pair with approve_rule after discover_patterns.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| rule_id | string | yes | Discovered rule ID from discover_patterns |
No output schema declared.
No examples provided.
repair ~229
One-shot repair: return corrected values that would make failing data valid under the Blueprint. Use repair_path to see the steps instead.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| derivation_rules | array | – | Math rules as objects. Types: add, subtract, multiply, divide, round, copy, sum (multi-operand), items_multiply, items_sum. Each needs 'type' plus its fields; see the blueprint_guide prompt |
| formal_constraints | array | – | Constraint objects. Types incl. magnitude_anchor {field,min,max}, relative_anchor {field,reference_field,ratio_min,ratio_max}, max_action_threshold {field,threshold,on_violation}, required_fields {fi… |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
repair_path ~155
Find the shortest sequence of field changes taking invalid data to a valid state, as an ordered path of intermediate states. Different from repair (one-shot nearest fix): use repair_path to explain or audit the fix, or compare alternative repairs.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| max_depth | integer | – | Search depth, 1-10 |
| rank_by | string | – | Ranking criterion for returned paths |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
rotate_api_key ~73
Replace an API key with a fresh one. The old key stops working immediately; the new key inherits its bindings.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| key_to_rotate | string | yes | The gai_ key to rotate; it stops working immediately |
No output schema declared.
No examples provided.
structural_types ~80
Retrieve the document categories a discover_patterns session identified (counts, distinguishing fields, domain hints). Read-only; returns status=no_session if discovery has not run for this namespace.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
No output schema declared.
No examples provided.
submit_chain_stage ~128
Submit data for the chain's current stage; the platform validates it and advances the chain if it passes. Response includes next-stage info and accumulated repairs.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| chain_id | string | yes | Chain identifier returned by create_chain |
| stage | string | yes | Stage name to submit for (must be the chain's current stage) |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
update_blueprint ~442
Update an existing Blueprint in place. Only passed fields change; pass [] to clear a list. workflow_name cannot be renamed and existing API keys keep working. Different from create_blueprint: modifies an existing Blueprint, mints no new key.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| customer_name | string | – | Organization or project name (also used for storage folder naming) |
| derivation_rules | array | – | Math rules as objects. Types: add, subtract, multiply, divide, round, copy, sum (multi-operand), items_multiply, items_sum. Each needs 'type' plus its fields; see the blueprint_guide prompt |
| derived_fields | array | – | Field names the platform computes from other fields, e.g. ['subtotal','total'] |
| enable_anomaly_detection | boolean | – | Flag records that break no rules but do not fit the reference pattern |
| enable_drift_tracking | boolean | – | Track pattern stability across batches |
| extracted_fields | array | – | Field names the agent extracts from source data, e.g. ['vendor','qty','unit_cost'] |
| formal_constraints | array | – | Constraint objects. Types incl. magnitude_anchor {field,min,max}, relative_anchor {field,reference_field,ratio_min,ratio_max}, max_action_threshold {field,threshold,on_violation}, required_fields {fi… |
| mode | string | – | New mode: observe or enforce; omit to keep current |
| require_coherence | boolean | – | Check cross-field plausibility |
| require_consistency | boolean | – | Check internal field consistency |
| require_high_assurance | boolean | – | Strictest mode: every check must pass |
| require_math | boolean | – | Validate mathematical relationships |
| require_provenance | boolean | – | Require extraction source locations for fields |
| semantic_checks | array | – | Domain-specific semantic check objects |
| workflow_name | string | yes | Unique Blueprint identifier; the value passed as 'blueprint' in validate |
No output schema declared.
No examples provided.
validate ~131
Validate structured data against a Blueprint's rules BEFORE the result is used. Returns PASS, FAIL, or REVIEW with plain-language findings, repair suggestions, a determinism hash, and a re-verifiable certificate. Same input + same rules = same verdict, every time.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
validate_repair ~131
Validate structured data against a Blueprint and, when it fails, include repair suggestions (corrected values with the rule each fix is based on) in the same call. Same verdicts as validate: PASS, FAIL, or REVIEW, with reasons and proof.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| blueprint | string | – | Blueprint name (workflow_name) to use |
| structured_data | object | yes | The document's extracted fields as key/value pairs. Keys are open by design - your Blueprint's rules define what is checked |
No output schema declared.
No examples provided.
verify_certificate ~142
Independently re-verify a validation certificate. Integrity mode checks the hash chain; full mode (certificate + original data) recomputes every attested rule from scratch - trust nothing, recheck everything.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| certificate | object | yes | The certificate object from a prior validation response |
| data | object | – | Original payload for full re-verification; omit for integrity-only mode |
| derivation_rules | array | – | Rule list for independent attestation recomputation (optional) |
| formal_constraints | array | – | Optional constraints to match against the committed bundle |
No output schema declared.
No examples provided.
verify_replay ~111
Check replay commitment integrity and compare recorded execution components. Version 4 includes reference context and the final result/status. A match compares commitments; this tool does not rerun the workflow or reconstruct historical reference populations, and does not prove factual correctness.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | GeodesicAI API key (gai_...) |
| contract_a | object | yes | replay_contract object from one execution |
| contract_b | object | yes | replay_contract object to compare against contract_a |
No output schema declared.
No examples provided.
What is the ai.geodesiclabs/governance-platform MCP server?
ai.geodesiclabs/governance-platform is an MCP server listed in the public MCP registry as ai.geodesiclabs/governance-platform. Pre-execution governance for AI agents. Deterministic PASS/FAIL/REVIEW verdicts, replayable proof. This page covers its hosted endpoint (https://app.geodesiclabs.ai/mcp).
Is the ai.geodesiclabs/governance-platform MCP server safe to use?
ai.geodesiclabs/governance-platform scores 82 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the ai.geodesiclabs/governance-platform MCP server expose?
ai.geodesiclabs/governance-platform exposes 37 tools: validate, validate_repair, create_blueprint, list_blueprints, repair, and 32 more. Their descriptions and schemas cost roughly 5,204 tokens of context every time the server is loaded.
Does the ai.geodesiclabs/governance-platform MCP server require authentication?
No. We connected to ai.geodesiclabs/governance-platform without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the ai.geodesiclabs/governance-platform MCP server still maintained?
ai.geodesiclabs/governance-platform is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.