---
title: Action Discovery
category: concepts
created: 2026-12-21
updated: 2025-01-04
tags: [action-discovery, mcp, tool-enumeration, security-boundary, enterprise-controls, authorization, governance, per-action-permissions, audit-trails, spolu-analysis, cli-limitations, platform-mediation, b2b-context, structured-events, granular-authorization, tools-list-endpoint, typed-audit-trails, opaque-execution-problem]
sources: [raw/articles/MCP vs CLI vs Code.md]
confidence: high
---
# Action Discovery
Systematic mechanism for AI agents to discover available actions and tools, enabling security boundaries and governance controls in enterprise environments. Central to [model-context-protocol](/concepts/model-context-protocol)'s enterprise value proposition and key differentiator from CLI/code execution approaches requiring runtime parsing of arbitrary strings.
## MCP Implementation
**`tools/list` Endpoint:**
- Platform intermediating between agent and MCP server discovers exactly which actions are available
- Enables security boundary: agents only discover tools they're authorized to use
- Foundation for granular permission systems in enterprise deployments
**Structured Action Enumeration:**
- Every MCP tool call is named, structured event
- Clear mapping between user permissions and available actions
- Unambiguous action boundaries for authorization systems
## Enterprise Control Scenarios
**Per-User, Per-Action Authorization:**
- "This agent can read Jira issues but not create them" - zero ambiguity
- Platform can enforce different permission sets for different users
- Granular controls without parsing execution strings
**Audit Trail Advantages:**
- **MCP**: Every tool call is typed, structured event with clear action semantics
- **Code Execution**: Every operation is opaque string requiring parsing for audit understanding
- **Governance Impact**: Structured events enable detailed compliance tracking
## CLI/Code Execution Limitations
**Opaque Execution Problem:**
- Sandboxing can control environment but not granular actions
- Authorization requires parsing arbitrary command strings
- "Anything the human can do, the agent will do" without separate controls
- Administrative oversight becomes difficult without action-level visibility
**Example Complexity:**
Determining if `gh issue create --title "Bug" --body "Description"` should be allowed vs `gh issue list` requires string parsing and semantic analysis rather than simple permission checking.
## Platform-Mediated Architecture
**B2B Context Requirements:**
- Company-controlled AI OS needs action-level governance
- Different employees require different permission boundaries
- Integration with dozens of services, each with distinct action sets
- Administrative oversight and compliance requirements
**MCP Structural Advantage:**
Protocol design enables platform sitting between agent and services to implement governance layer with precise action control, something difficult to achieve with direct CLI/code execution patterns.
## Multi-User vs Single-User Context
**Single-User Context:**
Action discovery overhead may not justify governance benefits when user directly controls agent behavior.
**Multi-User Enterprise Context:**
Action enumeration and granular controls become essential for safe deployment across organization with varying permission requirements.
## See also
- [model-context-protocol](/concepts/model-context-protocol)
- [enterprise-ai](/concepts/enterprise-ai)
- [oauth-discovery](/concepts/oauth-discovery)
- [tool-permission-systems](/concepts/tool-permission-systems)
- [protocol-criticism](/concepts/protocol-criticism)
- [cli-agent-integration](/concepts/cli-agent-integration)