~/wiki

action discovery

---
title: Action Discovery
category: concepts
created: 2026-12-21
updated: 2025-01-04
tags: [action-discovery, mcp, tool-enumeration, security-boundary, enterprise-controls, authorization, governance, per-action-permissions, audit-trails, spolu-analysis, cli-limitations, platform-mediation, b2b-context, structured-events, granular-authorization, tools-list-endpoint, typed-audit-trails, opaque-execution-problem]
sources: [raw/articles/MCP vs CLI vs Code.md]
confidence: high
---

# Action Discovery

Systematic mechanism for AI agents to discover available actions and tools, enabling security boundaries and governance controls in enterprise environments. Central to [model-context-protocol](/concepts/model-context-protocol)'s enterprise value proposition and key differentiator from CLI/code execution approaches requiring runtime parsing of arbitrary strings.

## MCP Implementation

**`tools/list` Endpoint:**
- Platform intermediating between agent and MCP server discovers exactly which actions are available
- Enables security boundary: agents only discover tools they're authorized to use
- Foundation for granular permission systems in enterprise deployments

**Structured Action Enumeration:**
- Every MCP tool call is named, structured event
- Clear mapping between user permissions and available actions
- Unambiguous action boundaries for authorization systems

## Enterprise Control Scenarios

**Per-User, Per-Action Authorization:**
- "This agent can read Jira issues but not create them" - zero ambiguity
- Platform can enforce different permission sets for different users
- Granular controls without parsing execution strings

**Audit Trail Advantages:**
- **MCP**: Every tool call is typed, structured event with clear action semantics
- **Code Execution**: Every operation is opaque string requiring parsing for audit understanding
- **Governance Impact**: Structured events enable detailed compliance tracking

## CLI/Code Execution Limitations

**Opaque Execution Problem:**
- Sandboxing can control environment but not granular actions
- Authorization requires parsing arbitrary command strings
- "Anything the human can do, the agent will do" without separate controls
- Administrative oversight becomes difficult without action-level visibility

**Example Complexity:**
Determining if `gh issue create --title "Bug" --body "Description"` should be allowed vs `gh issue list` requires string parsing and semantic analysis rather than simple permission checking.

## Platform-Mediated Architecture

**B2B Context Requirements:**
- Company-controlled AI OS needs action-level governance
- Different employees require different permission boundaries  
- Integration with dozens of services, each with distinct action sets
- Administrative oversight and compliance requirements

**MCP Structural Advantage:**
Protocol design enables platform sitting between agent and services to implement governance layer with precise action control, something difficult to achieve with direct CLI/code execution patterns.

## Multi-User vs Single-User Context

**Single-User Context:**
Action discovery overhead may not justify governance benefits when user directly controls agent behavior.

**Multi-User Enterprise Context:**
Action enumeration and granular controls become essential for safe deployment across organization with varying permission requirements.

## See also

- [model-context-protocol](/concepts/model-context-protocol)
- [enterprise-ai](/concepts/enterprise-ai)
- [oauth-discovery](/concepts/oauth-discovery)
- [tool-permission-systems](/concepts/tool-permission-systems)
- [protocol-criticism](/concepts/protocol-criticism)
- [cli-agent-integration](/concepts/cli-agent-integration)