Use RiskVault through MCP

You do not need to memorize tool names. Ask a clear question, state the intended scope, and tell the AI client how you want the result presented.

Search risks

Good prompts include both a subject and useful output fields:

Search RiskVault for accessible risks mentioning “single sign-on.” Show RR number, title, status, owner, and rating. Do not infer missing values.

Find risks with the exact workflow status “Under Review.” Return one page and tell me whether another page exists.

Risk search matches free text across title, RR number, and description. Search text is limited to 200 characters, and results are paged to prevent an unbounded data dump.

Read one risk

Start with a search if you do not know the record identifier. Then ask the client to read the selected risk:

Using the RiskVault result for RR-1234, retrieve the risk details and summarize the description, owner, workflow state, and rating. Separate facts from recommendations.

The details tool uses the risk's internal identifier returned by search. If the risk does not exist or you cannot access it, RiskVault deliberately returns the same general not-found-or-not-accessible message.

Request a portfolio summary

Users with portfolio scope and full-register access can ask:

Get the RiskVault portfolio summary. Present the returned metrics as a table and do not calculate values that RiskVault did not provide.

Portfolio summaries contain approved aggregate metrics, not record-level detail. If you lack full-register access, the tool returns an error instead of a partial portfolio result.

Check the assistant's work

  1. Ask the assistant to identify which RiskVault tool it used.
  2. Check RR numbers and important facts in the RiskVault application.
  3. Treat analysis and recommendations as generated suggestions, not authoritative records.
  4. Do not ask the assistant to reveal excluded or sensitive data.
  5. Do not paste sensitive data into the conversation to work around an MCP restriction.

Image needed: Example AI conversation showing a natural-language risk search, a visible tool call indicator, and a short table of fictional results.

Current limitations

RiskVault MCP currently reads data only. It cannot create a risk, edit fields, add comments, upload files, approve a transition, or perform another write action. Complete those tasks inside RiskVault.

It also does not provide raw database access or a complete unbounded export. Use Reports and exports for controlled portfolio reporting.

Common errors

Risk not found or not accessible
Confirm the RR number or repeat the search. The risk may be outside your permissions or excluded from MCP.
Portfolio summary requires full-register scope
The client registration or your account lacks the required access. Use risk search within your scope or contact an administrator.
RiskVault is temporarily rate-limiting requests
Wait briefly, reduce repeated requests, and try again.
Authorization or sign-in opens again
The session may have been inactive or reached its refresh lifetime. Review and approve the consent screen again.
The client connects but no RiskVault tools appear
Reconnect, confirm the server URL ends at the correct MCP endpoint, and ask an administrator to verify the client is enabled and has at least one MCP scope.