MCP workflow automation for governed agents
MCP lets an agent use tools without custom glue code for each one. In a business workflow, that makes access control the main question. This page covers the pattern, the vendors’ published support, and where Swfte stands.
Last reviewed 6 October 2026
What MCP does in a workflow
Before MCP, giving an agent a new tool meant writing a connector for that agent framework. MCP defines one way for a tool provider to describe what it offers and for an agent to call it, so a tool written once can be used by many agents.
In a workflow tool there are two directions. In the client direction, an agent or workflow step calls tools hosted on an MCP server, such as a CRM, a ticketing system or an internal API. In the server direction, the workflow tool publishes its own workflows or connectors as MCP tools, so that outside agents such as a desktop assistant can trigger them.
The difference matters when you buy. A product can be strong in one direction and absent in the other.
What automation vendors publish about MCP
We read each vendor’s own pages on 6 and 7 October 2026. The table records what the pages say, in our words. It does not say how well anything works.
| Vendor | What its pages describe |
|---|---|
| Zapier | Zapier MCP connects AI clients such as Claude, ChatGPT and Cursor to its apps and actions. |
| Make | A Make-hosted MCP server lets clients run scenarios. |
| n8n | An MCP Server Trigger node exposes n8n tools to MCP clients, and an MCP Client Tool node lets agents use MCP tools. |
| Windmill | Exposes an MCP server and can act as an MCP client. |
| Workato | MCP servers expose endpoints to AI agents as tools, built from project assets, an API collection or a proxy to external MCP servers. |
| Boomi | Documents an MCP server, labelled early access or tech preview, and agents that connect to MCP servers. |
Where MCP workflows go wrong
MCP makes tools easy to attach, which is exactly why it needs controls. The recurring problems are about authority, not protocol.
- Over-broad credentials. An agent that holds one key for every tool turns a single bad instruction into access to everything.
- No per-tool policy. If any agent can call any tool on a server, a research agent can reach the same functions as a finance agent.
- Untrusted tool output. Text returned by a tool can contain instructions. Treat it as data, and never as authority to act.
- Silent changes. A tool server can change what a tool does after you approved it. Pin and review.
- Thin audit. A log that records only that a call happened, not who made it or with what arguments, is of little use after an incident.
What Swfte offers, with the limits stated
Studio agents can call tools on external MCP servers over HTTP, server-sent events or streamable HTTP, with custom headers. Workflow tool steps use the same route. Connecting an external server is a Pro feature in Studio.
The MCP gateway endpoint checks that the caller has an API key with the right scope for that MCP server and that the workspace matches. Each call is logged with the workspace, the server, the method, the outcome and the time. It does not record the tool arguments or the calling person, so it is a thin audit record and not a full one.
What is not built: a per-tool allow or deny rule on the gateway, and exposing your own agents or workflows as an MCP server. Policy applied while an agent runs, through Nexus, can limit which tools an agent may use for runs that are enrolled in a policy, and each agent has its own tool allowlist. For the wider picture of how Swfte treats MCP, see the MCP gateway page and the MCP security guide.
A safe way to start
A pattern we would use for a first MCP workflow.
- Start with read-only tools. Let the agent search and summarise before it can change anything.
- Give each agent its own scoped credential, not a shared key, and name an owner.
- Put a person in the flow for any step that writes, sends or spends, and record the approval.
- Keep an allowlist of the tools each agent may use, and review it when a tool server changes.
- Log every call with the caller and the arguments, and test that you can reconstruct an incident from the log.
- Cap steps and spend per run so a loop cannot run away.
Which direction do you need?
If your aim is to let an outside assistant such as a desktop agent trigger your automations, you need the server direction, and the vendors in the table above publish it. If your aim is to let your own agents use tools hosted elsewhere, you need the client direction, which Swfte Studio offers. Many teams need both. In that case, check this against each vendor’s own documentation and ask for a demonstration with your tools.
MCP capabilities in Swfte, labelled
These labels come from a review of the product code on 7 October 2026. “Not offered” marks things a buyer may assume.
| Capability | State | Note |
|---|---|---|
| Agents and workflow steps call external MCP servers (client) | Available | HTTP, server-sent events and streamable HTTP, with custom headers. A Pro feature in Studio. |
| Gateway endpoint with API-key scope and workspace check | Available | Calls to a deployed MCP server go through it. |
| Audit of gateway calls | Available | Records workspace, server, method, outcome and latency. Not the arguments or the calling person. |
| Per-agent tool allowlist | Available | Set on the agent. |
| Policy on tool use while an agent runs (Nexus) | Available | Applies to runs enrolled in a policy. |
| Per-tool allow and deny rules on the MCP gateway | Designed for | Not built. |
| Expose your own agents or workflows as an MCP server | Not offered | Not available today. |
| Context-package API and MCP server on the Intelligence Platform | Designed for | On the roadmap. |
Sources for third-party facts
Facts about other vendors on this page were read on their own sites on 6 October 2026. Check the vendor’s page before you buy, because plans change.
- Zapier MCP (read 2026-10-06)
- Make MCP server (read 2026-10-06)
- n8n MCP Server Trigger node (read 2026-10-06)
- n8n MCP Client Tool node (read 2026-10-06)
- Windmill MCP (read 2026-10-06)
- Workato MCP servers (read 2026-10-06)
- Boomi MCP overview (read 2026-10-06)
Common questions
- What is MCP in workflow automation?
- The Model Context Protocol is an open standard for describing and calling tools. In workflows, it lets agents use tools from any MCP server, and lets a workflow tool offer its own steps to outside agents.
- What is the difference between an MCP client and an MCP server?
- A client calls tools hosted elsewhere. A server offers tools to clients. A workflow product can be one, the other or both, so ask which direction a vendor means.
- Does Swfte Studio support MCP?
- Studio agents can connect to external MCP servers, a Pro feature. A gateway endpoint checks an API key scope and logs calls. Swfte does not expose your own agents or workflows as an MCP server today.
- Can I control which tools an agent may call?
- Each agent has its own tool allowlist, and Nexus can apply policy to runs enrolled in a policy. The MCP gateway itself has no per-tool allow or deny rule yet.
- Is MCP secure?
- The protocol does not decide that. Security depends on credentials, per-tool policy, handling of untrusted tool output and the quality of the audit record. See the MCP security guide for a checklist.
- Which models work with MCP in Swfte?
- Any model reachable through the Connect gateway that supports tool calling. Connect lists 50+ providers.
- Where can I compare automation vendors’ MCP support?
- The table on this page lists what six vendors’ own pages say. The best automation platforms guide compares them on more criteria, with sources.
Related reading
- MCP gatewayThe control plane for tool calls
- MCP security best practicesA checklist
- MCP and tool securitySecOps view
- Swfte StudioAgents and workflows
- ConnectThe model gateway
- NexusPolicy and approvals
- Governed agentsLayer 04
- AI orchestration platformFour layers
- Best automation platformsVendors compared, with sources
- Best AI agent buildersVendors compared, with sources
- What is MCP?The Model Context Protocol explained.
- MCP serversWhere to find them and how to vet one.
- MCP vs APITwo layers, not rivals.
See the three buyer guides: best automation platforms, best AI agent builders and best data intelligence platforms.