# Catalyst Governance (remote · catalyst.stratogenic.ai)

Governance middleware for AI agents: permission gates, approvals, compliance scanning, audit ledger.

- Trust score: 70/100 (medium)
- Change this week: +7
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `catalyst.stratogenic.ai`: 70/100 (this document), [markdown](https://verifymcp.io/servers/stratogenic-ai-catalyst/catalyst.md), [page](https://verifymcp.io/servers/stratogenic-ai-catalyst/catalyst)
- remote · `catalyst.stratogenic.ai`: 23/100, [markdown](https://verifymcp.io/servers/stratogenic-ai-catalyst/catalyst-2.md), [page](https://verifymcp.io/servers/stratogenic-ai-catalyst/catalyst-2)

## Channel facts

- Endpoint: `https://catalyst.stratogenic.ai/mcp`
- Transports: `streamable-http`
- Auth: `required`
- Version: `1.0.1`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 74/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 71/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 3304 tokens (~106/item across 31 items; 31 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 71/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 0% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http stratogenic-ai-catalyst https://catalyst.stratogenic.ai/mcp
```

### Codex

```toml
[mcp_servers.stratogenic-ai-catalyst]
url = "https://catalyst.stratogenic.ai/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "stratogenic-ai-catalyst": {
      "type": "remote",
      "url": "https://catalyst.stratogenic.ai/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add stratogenic-ai-catalyst --url https://catalyst.stratogenic.ai/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  stratogenic-ai-catalyst:
    url: "https://catalyst.stratogenic.ai/mcp"
```

### Other

```json
{
  "mcpServers": {
    "stratogenic-ai-catalyst": {
      "type": "http",
      "url": "https://catalyst.stratogenic.ai/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-01 (score 69, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-31 (score 68, +3)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 65, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-29 (score 64, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-27 (score 63, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 62)

First indexed and scored.

## MCP tools (31)

### `catalyst_ingest_task` (~84 tokens)

Ingest one or more tasks into Catalyst governance pipeline.

        Items should include at minimum a 'title'. Optional fields: details, owner,
        priority (Low/Medium/High/Critical), stage, domain, due_at, tags, group_id.
        Returns ingested count and proposal IDs created.

Input parameters:

- `domain`
- `items` (array, required)

### `catalyst_search_tasks` (~80 tokens)

Search normalised tasks in the tenant flow cycle.

        Performs case-insensitive substring match on title/details.
        Filter by canonical domain (e.g. security, product, operations) or priority.

Input parameters:

- `domain`
- `limit` (integer)
- `offset` (integer)
- `priority`
- `q` (string)

### `catalyst_update_task` (~71 tokens)

Update a single task in the governance flow. Ledger-recorded.

        Patch may include: title, details, owner, priority, stage, domain,
        due_at, status, tags, done. Normalisation is applied automatically.

Input parameters:

- `patch` (object, required)
- `task_id` (string, required)

### `catalyst_bulk_update_tasks` (~81 tokens)

Bulk update all tasks matching a filter. Growth/Enterprise plans only.

        filter keys: domain, priority, stage, owner, tag, group_id.
        updates keys: owner, priority, domain, stage, tags_add, tags_remove.
        Returns matched and updated counts.

Input parameters:

- `filter` (object, required)
- `updates` (object, required)

### `catalyst_list_proposals` (~117 tokens)

List all pending governance proposals awaiting acceptance or decline.

        Proposals are work items that have been ingested but not yet committed
        to the live flow cycle. They require human (or agent) review.

        Each proposal contains an `idempotency_key` field — this is the canonical
        proposal identifier. Always use `idempotency_key` (not `task_id` or `id`)
        when passing proposal IDs to catalyst_accept_proposals,
        catalyst_decline_proposals, or catalyst_review_proposal.

### `catalyst_accept_proposals` (~116 tokens)

Accept one or more proposals, committing them to the flow cycle.

        ids: list of proposal `idempotency_key` values from catalyst_list_proposals.
        Do not pass `task_id` or `id` — the backend looks up proposals by
        `idempotency_key` and will silently match nothing if the wrong field is used.

        Acceptance is the governance commit step: items move from review state
        into live execution state and are recorded in the immutable ledger.

Input parameters:

- `ids` (array, required)

### `catalyst_decline_proposals` (~109 tokens)

Decline one or more proposals without committing them.

        ids: list of proposal `idempotency_key` values from catalyst_list_proposals.
        Do not pass `task_id` or `id` — the backend looks up proposals by
        `idempotency_key` and will silently match nothing if the wrong field is used.

        Declined proposals are recorded for audit and learning but are not
        added to the live flow cycle.

Input parameters:

- `ids` (array, required)

### `catalyst_review_proposal` (~131 tokens)

Approve or reject a review-required proposal (AI governance hold).

        proposal_id: the `idempotency_key` field from catalyst_list_proposals.
        Do not pass `task_id` or `id` — the backend looks up by `idempotency_key`.
        decision must be 'approve' or 'reject'. Approved proposals can then
        be accepted via catalyst_accept_proposals. Rejected proposals are
        marked review-rejected in the ledger.

Input parameters:

- `decision` (string, required)
- `proposal_id` (string, required)
- `reason`
- `reviewer_id`

### `catalyst_get_graph_views` (~66 tokens)

Get all 7 governance graph views for the tenant.

        Views: org_snapshot, execution_flow, ownership_map, compliance_web,
        risk_heatmap, client_influence, catalyst_metrics. Read-only, derived
        from flow_cycle on demand. Requires governance_dashboard entitlement.

### `catalyst_get_dashboard` (~53 tokens)

Get the governance dashboard snapshot including all views.

        Returns tenant metadata, execution metrics, and all 5 governance views
        (execution_flow, ownership_map, compliance_web, risk_heatmap, client_influence).

### `catalyst_get_org_summary` (~94 tokens)

Get an AI-generated narrative summary of the org's execution state.

        time_window: 'last_7_days' or 'last_30_days'.
        extra_query: optional focus bias (e.g. 'compliance', 'delivery risk').
        Returns a MASC-L3 compliant narrative — no individual evaluations.
        Requires governance_dashboard entitlement.

Input parameters:

- `extra_query`
- `time_window` (string)

### `catalyst_run_compliance_scan` (~53 tokens)

Run a compliance scan against all loaded compliance documents.

        Detects compliance gaps, conflicts, and policy violations across
        the current flow cycle. Requires can_scan entitlement.
        Returns findings grouped by severity.

### `catalyst_get_compliance_findings` (~67 tokens)

Get the latest compliance findings from the most recent scan.

        Returns findings flattened by category: conflicts, gaps, ok.
        Each finding includes category, severity, status, and task linkage.
        Does not trigger a new scan — use catalyst_run_compliance_scan first.

### `catalyst_create_tasks_from_findings` (~68 tokens)

Materialise compliance findings as actionable flow tasks.

        classes: list of finding classes to convert, e.g.
        ['MISSING_CONTROL', 'PROHIBITED_ACTION']. Defaults to both.
        Created tasks enter the governance pipeline like any other ingest.

Input parameters:

- `classes`

### `catalyst_list_compliance_frameworks` (~92 tokens)

List all available pre-built compliance framework packs.

        Returns each pack (GDPR, SOC 2, ISO 27001, HIPAA, PCI-DSS, EU AI Act,
        Bribery Act, AML/KYC) with its name, description, rule count, and
        whether it is currently active for this organisation.
        Activate a pack with catalyst_activate_compliance_framework.

### `catalyst_activate_compliance_framework` (~104 tokens)

Activate a pre-built compliance framework pack for this organisation.

        framework: one of gdpr, soc2, iso27001, hipaa, pci_dss, eu_ai_act,
        bribery_act, aml_kyc.
        Once activated, the pack's DENY/REQUIRE/ADVISE rules are merged into
        every subsequent compliance scan — no document upload required.
        Requires can_scan entitlement.

Input parameters:

- `framework` (string, required)

### `catalyst_list_compliance_rules` (~104 tokens)

List all compliance rules currently in effect for the organisation.

        Returns rules from three sources combined and deduplicated:
        - Rules extracted from uploaded policy documents
        - Custom org-level rules (PATCH /compliance/rules)
        - Rules from any activated framework packs

        Each rule includes: id, type (DENY/REQUIRE/ADVISE), trigger sentence,
        severity, scope, remediation guidance, confidence score, and authority citation.

### `catalyst_register_machine_actor` (~141 tokens)

Register a machine actor (agent, automation) with Catalyst governance.

        runtime_type: zapier_zap | n8n_workflow | openai_assistant | make_scenario |
                      claude_agent | custom_agent | internal_worker.
        governance_mode: observe | advisory | proposal | strict.
        risk_class: low | standard | high.
        Requires can_configure_ai_workflows entitlement (Enterprise+).

Input parameters:

- `capabilities`
- `display_name` (string, required)
- `governance_mode` (string)
- `notes`
- `risk_class` (string)
- `runtime_type` (string, required)
- `scopes`

### `catalyst_evaluate_agent_action` (~86 tokens)

Evaluate whether an agent action is permitted by the governance gate.

        Returns decision: 'allow' | 'proposal_required' | 'deny'.
        High-risk actors with allow decisions are escalated to proposal_required.
        The actor must be registered and active for this tenant.

Input parameters:

- `actor_id` (string, required)
- `capability` (string, required)
- `context`

### `catalyst_register_workflow` (~121 tokens)

Register an AI workflow for EU AI Act compliance governance.

        risk_level: unacceptable (rejected) | high | limited | minimal.
        mode: observe | advisory | proposal. High-risk workflows are forced to proposal.
        Sets ai_standards=True to opt into the Built to AI Standards evidence trail.
        Requires can_configure_ai_workflows (Enterprise+).

Input parameters:

- `ai_standards` (boolean)
- `mode`
- `notes`
- `risk_level` (string)
- `workflow_id` (string, required)

### `catalyst_send_lite_event` (~92 tokens)

Send a lifecycle event for a registered AI workflow.

        event_type examples: run.started, action.executed, approval.requested,
        run.completed, run.failed. Idempotent via request_id (UUID recommended).
        Payload is scrubbed of credentials before storage.

Input parameters:

- `event_type` (string, required)
- `payload`
- `request_id`
- `workflow_id` (string, required)

### `catalyst_get_workflow_trust` (~101 tokens)

Get the four-component trust score for a registered AI workflow.

        Score = 0.25×ai_declared + 0.25×risk_eval + 0.25×override + 0.25×(1−failure).
        Range 0.0–1.0. window_days controls the lookback period (1–365).

Input parameters:

- `window_days` (integer)
- `workflow_id` (string, required)

### `catalyst_export_workflow_audit` (~86 tokens)

Export audit events for an AI workflow as JSON.

        since: ISO timestamp filter (inclusive). ai_standards_only: limit to
        events from workflows opted into Built to AI Standards.
        Suitable for regulatory submissions and investor due diligence.

Input parameters:

- `ai_standards_only` (boolean)
- `since`
- `workflow_id` (string, required)

### `catalyst_weekly_summary` (~49 tokens)

Get a 7-day activity rollup: ingested, accepted, declined proposals,
        domain breakdown, priority breakdown, and average risk score.
        Fully deterministic — no LLM calls.

### `catalyst_export_ledger` (~85 tokens)

Export the immutable SHA-256 chained audit ledger.

        since: ISO timestamp to filter entries (inclusive).
        format: 'json' returns full entries; 'csv' sets entries to null (use REST API for CSV).
        The ledger is tamper-evident — any modification breaks the hash chain.

Input parameters:

- `format` (string)
- `since`

### `catalyst_my_governance` (~124 tokens)

Show your governance profile, actor registration, and plan capabilities.

        Returns governance_mode (observe/advisory/proposal/strict), risk_class,
        declared capabilities, and actor_id. Auto-registers you in observe mode
        on first connection — the lightest governance touch.

        Also returns plan_capabilities showing which features are active and
        which require an upgrade — relay any upgrade_required fields to the user
        so they can unlock compliance scanning or AI workflow governance.

        Call this first to understand what you are and are not permitted to do.

### `catalyst_check_action` (~151 tokens)

Check if a capability/action is permitted by your governance policy.

        Returns decision: 'allow' | 'proposal_required' | 'deny' with guidance.
        Call BEFORE any consequential action (API call, data write, send, deploy).

        If title is provided and decision is 'proposal_required', the intent is
        logged automatically and proposal_id is returned — no second call needed.
        If 'proposal_required' without a title, call catalyst_log_task separately.

        capability examples: 'send_email', 'write_file', 'deploy_code',
        'update_record', 'delete_record', 'external_api_call'.

Input parameters:

- `capability` (string, required)
- `context`
- `title`

### `catalyst_log_task` (~103 tokens)

Log a task or action into the Catalyst governance pipeline.

        Records work, decisions, and actions for audit and governance.
        priority: Low | Medium | High | Critical.
        domain: security | product | operations | compliance | finance | legal | other.
        Returns ingested count and any proposal_ids created (if a governance hold applies).

Input parameters:

- `details`
- `domain`
- `priority` (string)
- `title` (string, required)

### `catalyst_pending_approvals` (~67 tokens)

List proposals currently awaiting governance approval.

        Shows proposals with status pending or in review. Use this to check whether
        an action you submitted is still waiting for human sign-off before you proceed.
        Returns count and full proposal objects with IDs for catalyst_await_approval.

### `catalyst_await_approval` (~129 tokens)

Check approval status for a specific proposal.

        Returns approved: true/false and clear guidance on whether to proceed.
        Call this after catalyst_check_action returns 'proposal_required'.
        Do NOT proceed with the gated action until approved: true is returned.

        POLLING vs EVENT-DRIVEN: For interactive sessions, poll this tool.
        For autonomous long-running workflows, prefer registering a webhook via
        catalyst_register_approval_webhook(callback_url) so your orchestrator is
        notified the moment a human acts — no polling loop required.

Input parameters:

- `proposal_id` (string, required)

### `catalyst_register_approval_webhook` (~166 tokens)

Register a callback URL to receive proposal approval notifications.

        Subscribes callback_url to proposal.accepted and proposal.declined events.
        When a human approves or declines any proposal, Catalyst POSTs the event
        to your URL with the resolved proposal IDs in data.ids.

        Use this instead of polling catalyst_await_approval for autonomous workflows:
        register once, let your orchestrator (Temporal, job queue, webhook relay) wake
        the agent when the relevant proposal_id arrives. Then call catalyst_await_approval
        once to confirm and proceed.

        Returns subscription IDs, the expected payload shape, and usage guidance.
        Returns upgrade_required: true if outbound webhooks are not on your plan.

Input parameters:

- `callback_url` (string, required)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/stratogenic-ai-catalyst/catalyst#diagnostics

## Score history

- 2026-08-03: 70
- 2026-08-02: 69
- 2026-08-01: 69
- 2026-07-31: 68
- 2026-07-30: 65
- 2026-07-29: 64
- 2026-07-28: 63
- 2026-07-27: 63
- 2026-07-26: 62

## Links

- Remote endpoint: https://catalyst.stratogenic.ai/mcp
- Authorisation metadata: https://catalyst.stratogenic.ai/.well-known/oauth-protected-resource/mcp
- Repository: https://github.com/Stratogenic-AI/catalyst-mcp
- Changelog RSS feed: https://verifymcp.io/servers/stratogenic-ai-catalyst/catalyst/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/stratogenic-ai-catalyst/catalyst/changelog.json
- HTML version of this page: https://verifymcp.io/servers/stratogenic-ai-catalyst/catalyst
