MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
n8n
25 tools · footprint 56
1 critical 7 high 13 med 4 low
PagerDuty
64 tools · footprint 55
5 high 16 med 43 low
Datadog
24 tools · footprint 52
1 critical 11 high 12 med
Attention
25 tools · footprint 51
1 critical 6 high 18 med
Box
37 tools · footprint 50
10 high 14 med 13 low COSOHIPAA+1 more
Gusto
36 tools · footprint 48
12 high 11 med 13 low COSOGLBA+1 more
ActiveCampaign
58 tools · footprint 47
4 high 15 med 39 low COSOSOX
GitHub
24 tools · footprint 47
5 high 12 med 7 low COSOSOX
Sanity
36 tools · footprint 47
1 critical 5 high 12 med 18 low
Amplitude
43 tools · footprint 44
6 high 16 med 21 low
Mem
23 tools · footprint 44
5 high 8 med 10 low
Microsoft SharePoint (Work IQ)
23 tools · footprint 44
1 critical 5 high 13 med 4 low
PagerDuty
25 tools · footprint 44
6 high 18 med 1 low
Coralogix
21 tools · footprint 43
5 high 13 med 3 low
Sentry
25 tools · footprint 43
3 high 14 med 8 low
Clarify
25 tools · footprint 42
3 high 15 med 7 low
‹ PrevPage 2 of 19Next ›
AshbyDocs ↗
1 high 8 med 8 low · 17 tools · 0 SoD-flagged
regimes APPICCPAEU_AI_ACTGDPRISO_27001LGPDNIST_AI_RMFPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (2 of 17)

ashby-api.filter_records high conf mediumOBO
Runs criteria-based queries across candidates, applications, and jobs, returning matching records in bulk — an exfiltration path for candidate PII at scale.
ashby-api.get_interview_plan low conf lowallow
Shows the configured candidate progression stages for an interview plan; largely structural pipeline configuration.
All other tools (15)
ashby-api.add_note_to_candidate low conf mediumallow
Drafts a profile note on a candidate for later confirmation; reversible and does not commit until the user approves it.
ashby-api.change_application_stage medium conf mediumaudit
Advances a candidate's application through interview stages, effecting a consequential step in an automated hiring pipeline.
ashby-api.consider_candidate_for_job medium conf mediumaudit
Creates a new application linking a candidate to a job, entering that person into the hiring pipeline for the role.
ashby-api.create_candidate medium conf mediumaudit
Adds a new candidate record with contact information, writing applicant personal data into the ATS.
ashby-api.describe_object_fields low conf mediumallow
Returns the filterable field metadata for an object type as a backend helper; exposes schema shape, not record data.
ashby-api.get_candidate medium conf mediumaudit
Pulls a comprehensive candidate profile including resume and interview feedback — a rich single-record disclosure of applicant personal data.
ashby-api.get_interview_details medium conf mediumaudit
Provides pre-interview briefing materials for a scheduled interview, including candidate-specific context.
ashby-api.get_job_pipeline low conf mediumallow
Displays aggregate candidate counts at each pipeline stage for a job; exposes summary metrics rather than individual records.
ashby-api.get_pending_tasks low conf mediumallow
Lists the caller's own outstanding scorecards and approvals; a personal task queue read scoped to the authenticated user.
ashby-api.get_record_details medium conf mediumaudit
Retrieves full information for a job, application, or offer, including offer compensation terms and applicant details.
ashby-api.get_submitted_feedback low conf mediumallow
Retrieves the caller's own submitted scorecard feedback, scoped to the authenticated interviewer.
ashby-api.get_upcoming_interviews medium conf mediumaudit
Lists scheduled interviews with candidate and job details, surfacing identifying applicant information and schedules.
ashby-api.search_product_docs low conf mediumallow
Queries Ashby's product documentation; a read of public help content with no customer data exposure.
ashby-api.search_records_by_name medium conf mediumaudit
Locates candidates, jobs, applications, and email templates by name, surfacing identifying candidate details to the caller.
ashby-api.submit_mcp_feedback low conf mediumallow
Sends a suggestion to the Ashby team about the MCP server; a low-impact outbound feedback message.