A
system (100) for the secure MCP-mediated use of tools by AI agents and generative AI / LLM services in cloud-native distributed applications, wherein the
system (100) comprises: a KL agent interface (1) configured to receive
natural language commands and application events from a variety of
client applications and to generate appropriate tool call commands for one or more generative KL or Large
Language Model (LLM) services; an MCP
mediator service (2) that is configured to: (a) to convert the tool request requests into messages compatible with a model context protocol (MCP); and (b) to maintain the conversation context, including at least one of the following: user identity, tenant identity and application identity; a tool register (3) that stores a plurality of tool descriptions, each tool description defining at least a tool identifier, an input and output scheme, an endpoint location and allowed functions, wherein the tool register (3) is accessible to the MCP
mediator service (2); a policy and security manager (4) configured to evaluate each MCP tool call against one or more security and access policies based on the conversation context and the corresponding tool description, and to issue a decision to allow, modify or block the tool call; a tool connector layer (5) comprising a plurality of tool adapters, each tool adapter being configured to communicate securely with a corresponding external tool, service or
data source using credentials and permissions restricted according to the decision of the policy and security manager (4); an observation and audit manager (6) configured to
record, for each tool call, at least a
timestamp, the calling KL agent, the tool identifier, the
policy decision, and a summary of the tool response, and to provide audit logs and
metrics for monitoring and compliance purposes; and a cloud-native deployment controller (7) configured to provide the MCP
mediator service (2), policy and security manager (4), tool connector layer (5) and observation and audit manager (6) as distributed
microservices with
network isolation between tenants in a cloud-native environment.