Feature · Administration

Work in Zovos from the AI assistant your team already uses.

Claude, ChatGPT, Copilot and other MCP clients connect to Zovos under each person’s own role, and every tool call is audited.

SectionAdministration
UpdatedOctober 2026
MCP tools
36
10 write, dry run first
Skill packs
17
control families
Audit
1 row
per tool call
Recent tool calls · audit log
ToolPersonClientOutcome
query_controlsJ. RiveraClaudeRead
submit_control_test_resultJ. RiveraClaudePending review
get_my_workM. ChenCopilotRead
create_taskM. ChenCopilotDry run
query_findingsA. PatelChatGPTRead
Illustrative product preview. It does not show tenant data.
01 · AI assistants over MCP and ZEP control testing

An MCP server built into Zovos

Zovos runs a remote MCP server with 36 tools, 26 read and 10 write. Assistants sign in through OAuth 2.1 and register themselves, so there is no API key to paste or rotate (app/mcp).

  • 01Setup is documented for Claude, ChatGPT, Cursor, VS Code with GitHub Copilot, Copilot Studio, and Gemini CLI.
  • 02Read tools cover your work and approvals, controls, risks, obligations, findings, KRIs, vendors, regulatory updates, exam request lists, and policies.
  • 03Write tools create a task, comment on a record, import records from your old system, and submit a control test. Each one shows a dry run until the person confirms it.
02 · AI assistants over MCP and ZEP control testing

Your role, not a service account

The assistant acts as the person who signed in. The institution comes from the verified sign-in, and every tool runs through the same role-based access checks as the app (mcp runtime, mcp access).

  • 01An assistant never approves or signs anything, and it never changes a record’s status.
  • 02It cannot reach fraud cases, SAR decisions, or credit risk review.
  • 03An examiner’s assistant can read the help articles and nothing in your workspace.
03 · AI assistants over MCP and ZEP control testing

Every tool call on the audit trail

Each tool call writes its own row to the append-only audit log. The row records the tool, the person, their role, the assistant client, the outcome, and a hash of the arguments.

  • 01Owners see every connected assistant client and can revoke or restore each one.
  • 02Tool calls that use AI are also recorded as agent runs.
04 · AI assistants over MCP and ZEP control testing

Test controls with your own assistant through ZEP

The Zovos Evidence Protocol (ZEP) publishes the test procedure, the result schema, and the tools. Your assistant runs the procedure against your own systems with your own credentials, uploads the raw evidence, and submits the result. Zovos never receives those credentials.

  • 01Zovos recomputes the evidence hash on the server, scans the file, and refuses credentials, personal data, and SAR content before anything is stored.
  • 02The tester of record is the verified person who signed in. The assistant’s name and model are recorded as unverified.
  • 03Nothing changes a rating until a different person accepts the result. A failed test opens a draft finding, and 5% of submissions are re-tested at random by default.
  • 04Accepted results export as OSCAL Assessment Results or OCSF Compliance Finding records.
05 · AI assistants over MCP and ZEP control testing

Skill packs for 17 control families

Zovos publishes a skill pack for each of 17 control families, including privileged access MFA, access review, backup and restore, and vulnerability management. Each pack comes as a Claude skill, Copilot instructions, and a Cursor rule.

  • 01Each pack follows the published procedure for its family, so the assistant runs the same steps your reviewer checks against.
06 · AI assistants over MCP and ZEP control testing

Off until your owner turns it on

The MCP server and ZEP control testing are two separate settings in Settings → Integrations → AI assistants. Both are off by default, and only your institution’s owner can turn them on.

  • 01Turning on the MCP server does not turn on control testing. Each one is its own decision.
Proof points

Grounded in shipped behaviour.

  • The MCP server registers 36 tools, 26 read and 10 write.
  • Every tool call writes one audit row that carries a hash of its arguments.
  • ZEP results follow a published schema at zovos.ai/schemas/evidence/control-test-result/v1.json.
  • Skill packs cover 17 control families for Claude, Copilot, and Cursor.

Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.

FAQ

Questions, answered first.

Which assistants work with Zovos?
Any MCP client that supports OAuth sign-in can connect. Setup steps are documented for Claude, ChatGPT, Cursor, VS Code with GitHub Copilot, Copilot Studio, and Gemini CLI.
Does my assistant get more access than I have?
No. It acts as you, under your Zovos role, through the same access checks as the app.
Does Zovos see the credentials my assistant uses to test a control?
No. The assistant runs the test against your systems with your own credentials and sends Zovos only the result and the evidence.
Can an assistant approve or close something?
No. It can create a task, add a comment, and submit a test result. Approvals, sign-offs, and rating changes stay with people in Zovos.
Is this the same as the AI agents inside Zovos?
No. The agents inside Zovos run on AWS Bedrock. The MCP server lets each person use the assistant they already have, under their own role.

See AI assistants over MCP and ZEP control testing on your library.

Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.