Choose a content evaluator
Understand the optional TypeSafe AI request and response checks.
Built-in or TypeSafe
The built-in evaluator is the default. Where TypeSafe is configured on the server, an administrator can select TypeSafe AI in the MCP policy evaluation setting. Changing the evaluator invalidates outstanding approvals.
Review the data flow
TypeSafe receives server-verified consumer permissions and relevant tool arguments or response content. Review that external data flow before enabling it. It can restrict access but cannot override a baseline denial or required independent approval.
Troubleshooting
Evaluation fails or returns an uncertain answer
Access is blocked. Check the evaluator configuration and service state, then verify a reviewed read after resolving the failure.
The TypeSafe option is unavailable
The server must be configured for TypeSafe before the organization can opt in. Ask the deployment administrator to check availability.
Frequently asked questions
Can TypeSafe grant access the built-in checks denied?
No. Mandatory identity, resource, membership, credential, and approval checks remain authoritative.