JournalDAY 104 / X

FIELD NOTE / X

MCP exposes tools. It does not run the job.

The short film, the complete written thought, and the evidence behind it.

Journal September 28, 2026 · X target January 9, 2027
Open the approved MP4 ↗

The X conversation link will follow its public release.

MCP exposes tools. It does not run the job.

Day 104 - 2027-01-09 PT target - X

Video caption

MCP exposes tools. It does not run the job. Start, continue, cancel, and collect artifacts are not MCP. Do not invent permissions MCP does not make. Review tools as tools. Narration uses Eric's authorized AI voice clone. #EricFieldNotes

Full written post / accessibility read

MCP contracts for how a host exposes tools and resources to a model session. That is the tools and data plane. Hosts, gateways, and policy still decide what is allowed, who may call it, and what gets logged. MCP does not become a permissions system by existing.

What MCP does not define is how a product starts a harness job, continues across turns, cancels mid flight, or collects artifacts when the job ends. Treating MCP as the whole agent stack is how a tools review gets mistaken for a product integration review.

This framing matches public MCP's role. Any claim that MCP alone solves permissions is untested synthesis and should stay out of a security signoff. Enforcement remains host side.

When someone asks whether the agent protocol is safe, answer with the layer. If they mean tool exposure, review MCP and host policy. If they mean cancel and collect, look at the job surface. If they mean isolation, look at the substrate.

Narration uses Eric's authorized AI voice clone.

#EricFieldNotes

Four-beat scene transcript

1. MCP exposes tools. It does not run the job.

MCP contracts for how a host exposes tools and resources to a model session. That is the tools and data plane. Hosts, gateways, and policy still decide what is allowed, who may call it, and what gets logged. MCP does not become a permissions system by existing.

Visual: Hosts still decide allow, deny, and log.

2. Job lifecycle lives elsewhere.

What MCP does not define is how a product starts a harness job, continues across turns, cancels mid flight, or collects artifacts when the job ends. Treating MCP as the whole agent stack is how a tools review gets mistaken for a product integration review.

Visual: Start, continue, cancel, and collect artifacts are not MCP.

3. Keep governance claims bounded.

This framing matches public MCP's role. Any claim that MCP alone solves permissions is untested synthesis and should stay out of a security signoff. Enforcement remains host side.

Visual: Do not invent permissions MCP does not make.

4. Review tools as tools.

When someone asks whether the agent protocol is safe, answer with the layer. If they mean tool exposure, review MCP and host policy. If they mean cancel and collect, look at the job surface. If they mean isolation, look at the substrate.

Visual: Leave job and substrate reviews their own queues.

More notes from the work ↗