MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Microsoft 365
23 tools · footprint 41
8 high 14 med 1 low
Paytm for Business
24 tools · footprint 41
2 critical 7 high 5 med 10 low COSOPCI+1 more
Vercel
20 tools · footprint 41
2 critical 3 high 2 med 13 low COSOSOX
Cloudinary
23 tools · footprint 40
1 critical 4 high 15 med 3 low
Freshdesk
24 tools · footprint 40
6 high 14 med 4 low
Netlify
23 tools · footprint 40
2 critical 4 high 4 med 13 low
Zapier
14 tools · footprint 39
1 critical 3 high 3 med 7 low COSOPCI+1 more
Freshservice
23 tools · footprint 38
6 high 15 med 2 low
GitHub
83 tools · footprint 38
1 high 20 med 62 low COSOSOX
Bright Data
25 tools · footprint 37
5 high 17 med 3 low
Snowflake
6 tools · footprint 37
2 critical 3 high 1 med COSOSOX
Brex
25 tools · footprint 36
3 high 17 med 5 low COSOGLBA+2 more
Microsoft Dataverse
15 tools · footprint 35
1 critical 3 high 8 med 3 low
Calendly
35 tools · footprint 34
2 high 13 med 20 low
Lovable
25 tools · footprint 34
1 critical 2 high 9 med 13 low
Smartsheet
42 tools · footprint 34
2 high 9 med 31 low COSOSOX
‹ PrevPage 3 of 19Next ›
Calendly
2 high 13 med 20 low · 35 tools · 2 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDNIST_CSFPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (2 of 35)

calendly.organizations-delete_organization_membership high conf highhuman approval
Removes a user from the organization, revoking their access.
calendly.organizations-create_organization_invitation high conf highhuman approval
Invites a new user to the organization; expands access surface.
All other tools (33)
calendly.availability-get_user_availability_schedule low conf highallow
Reads a user's availability schedule.
calendly.availability-list_user_availability_schedules low conf highallow
Lists a user's availability schedules.
calendly.availability-list_user_busy_times low conf mediumallow
Reveals when a user is busy; minor calendar privacy exposure.
calendly.event_types-create_event_type medium conf highaudit
Creates a bookable event type that determines what meetings the org accepts.
calendly.event_types-get_event_type low conf highallow
Reads a single event type's configuration.
calendly.event_types-list_event_type_availability_schedule low conf highallow
Lists the availability schedule attached to an event type.
calendly.event_types-list_event_type_available_times low conf highallow
Lists open booking slots for an event type.
calendly.event_types-list_event_types low conf highallow
Lists configured event types; metadata only.
calendly.event_types-update_event_type medium conf highaudit
Modifies an event type's duration, location, or routing.
calendly.event_types-update_event_type_availability_schedule medium conf highaudit
Changes when an event type can be booked; can silently expand or restrict access.
calendly.locations-list_user_meeting_locations low conf highallow
Lists configured meeting locations (Zoom, in-person, etc.).
calendly.meetings-cancel_event medium conf highaudit
Cancels a scheduled meeting; affects invitee plans and notifies them.
calendly.meetings-create_invitee medium conf highaudit
Adds a person to a meeting; persists their PII (name, email).
calendly.meetings-create_invitee_no_show low conf highallow
Marks an invitee as a no-show; affects metrics and follow-up logic.
calendly.meetings-delete_invitee_no_show low conf highallow
Reverses a no-show flag; minor metric impact.
calendly.meetings-get_event medium conf highaudit
Reads a meeting record including invitee details.
calendly.meetings-get_event_invitee medium conf highaudit
Reads detailed invitee record including answers to intake questions.
calendly.meetings-get_invitee_no_show low conf highallow
Reads a no-show record.
calendly.meetings-list_event_invitees medium conf highaudit
Lists invitee PII attached to an event.
calendly.meetings-list_events medium conf highaudit
Lists scheduled meetings; reveals invitee identities and meeting cadence.
calendly.organizations-get_organization low conf highallow
Reads tenant-level metadata.
calendly.organizations-get_organization_membership low conf highallow
Reads a single membership record.
calendly.organizations-list_organization_invitations low conf highallow
Lists pending invitations to join the org.
calendly.organizations-list_organization_memberships medium conf highaudit
Enumerates members of the organization with role information.
calendly.organizations-revoke_organization_invitation medium conf highaudit
Cancels a pending invitation.
calendly.routing_forms-get_routing_form low conf highallow
Reads a routing form's configuration.
calendly.routing_forms-get_routing_form_submission medium conf highaudit
Reads a single routing-form submission with submitter PII.
calendly.routing_forms-list_routing_form_submissions medium conf highaudit
Lists form submissions; submissions typically include lead PII and qualifying answers.
calendly.routing_forms-list_routing_forms low conf highallow
Lists routing forms used for lead-to-rep matching.
calendly.scheduling_links-create_single_use_scheduling_link low conf highallow
Issues a one-time booking link.
calendly.shares-create_share low conf highallow
Creates a shareable scheduling artifact.
calendly.users-get_current_user low conf highallow
Returns identity of the calling user.
calendly.users-get_user low conf highallow
Reads a user record (name, email, role).