What is Agent?
An agent is a software loop that uses model output and context to select steps or tools toward a goal. Model Context Protocol can supply tools and context to an AI application, but it does not define an agent primitive or a planning method.
Why it matters
An agent can turn inferred intent into external effects. Its identity, tools, permissions, and approval rules must be clear before it acts.
How it works
- A host gives the model instructions, context, and available tools.
- The model or host selects the next action and supplies tool arguments.
- The system validates and executes the action, returns the result, and continues or stops.
Example
An operations agent reads an incident, queries current service health, and creates a draft response for a person to approve.
Pomerium boundary
Pomerium can protect the Streamable HTTP request path from an agent application or another Model Context Protocol client to an internal server. Pomerium authenticates the user or service account that the request represents and applies configured route and tool policy. Operators can add Model Context Protocol authorization log fields to record the method, tool name, and parameters.
Limits and non-claims
- Model Context Protocol does not define agent reasoning, memory, or autonomy.
- The word agent does not identify the originating user or prove delegated authority.
- A model decision is not an authorization decision.
- Pomerium protects Model Context Protocol servers that use Streamable HTTP through a Pomerium route. It does not secure local stdio connections, the model runtime, tool code, or traffic that bypasses the route.
Evaluation checklist
- Can you separate the model, agent loop, host application, client, server, and tool?
- Which component grants authority, holds credentials, and validates each proposed action?
- Can goal hijack, untrusted context, or a tool result expand the agent's allowed work?
Sources and further reading
- Model Context Protocol architectureDocumentation
- Model Context Protocol toolsStandard
- OWASP excessive agency guidancePrimary source
- OWASP GenAI LLM Top 10 2026Primary source
- OWASP Top 10 for Agentic Applications 2026Primary source
- Pomerium Model Context Protocol supportPomerium documentation
- Delegate MCP access to an LLMPomerium documentation
- Pomerium MCP observabilityPomerium documentation
- Pomerium MCP referencePomerium documentation
