| New server or first enterprise route | A previously unapproved MCP endpoint, supplier, package or internal server is proposed. | Ownership, provenance, protocol support, transport, authentication, capability inventory, data classes, schema fingerprints, downstream permissions, failure tests, telemetry and retirement path. | Approved registry record, architecture and threat model, conformance and acceptance results, runbook and route-as-code change. |
|---|
| Additive capability or schema change | A tool, resource or prompt is added, or an optional field or enum value expands the contract. | New privilege, model-selection effect, name collision, compatibility, data exposure, rate impact, client caching and updated tests. | New fingerprint, contract diff, classification decision, acceptance tests and approved release record. |
|---|
| Breaking contract change | A capability is removed or renamed, a required field changes, constraints narrow, output shape changes or behaviour is no longer compatible. | Affected consumers, parallel versioning, migration window, route or name strategy, rollback and retirement of the former contract. | Consumer inventory, migration plan, dual-run or compatibility test, effective date and deprecation notice. |
|---|
| Privilege or impact increase | Read becomes write, write becomes destructive, accessible records expand, approval is removed or a broader downstream identity is introduced. | Business necessity, least privilege, scopes, human approval, separation of duties, rollback, transaction controls and incident containment. | Fresh security and business approval, negative tests, exact permission diff and updated risk record. |
|---|
| Authorisation or identity change | Issuer, audience, client registration, scopes, token handling or downstream credential flow changes. | Protected-resource metadata, issuer and audience validation, step-up behaviour, token separation, revocation and affected clients. | Authorisation-flow test, configuration review, secret-rotation evidence and rollback plan. |
|---|
| Endpoint, transport or gateway route change | Canonical URI, environment endpoint, transport, gateway, region or route policy changes. | Resource indicator, TLS, DNS and redirect behaviour, allowlists, latency, availability, cancellation, header/body validation and telemetry continuity. | Route diff, connectivity and failure tests, updated registry record and post-change verification. |
|---|
| Protocol baseline or extension change | The server adds or removes a supported MCP revision or optional extension. | Client compatibility, fallback behaviour, deprecated features, schema and error changes, conformance suite and operational rollback. | Compatibility matrix, conformance results, client validation and approved release notes. |
|---|
| Deprecation and retirement | A server, release or capability is no longer strategic, supported, compliant or safe. | Consumer inventory, successor, migration deadline, route closure, credential revocation, endpoint shutdown and evidence retention. | Deprecation decision, consumer acknowledgements, completed migration, disabled route and retained retirement record. |
|---|
| Emergency restriction | An incident, vulnerability, ownership loss or unexplained schema difference creates immediate risk. | Minimum safe capability set, affected principals, containment route, communication, evidence preservation and restoration criteria. | Incident decision, temporary policy, active restriction verification and time-bound remediation owner. |
|---|