user: Rotate the payments API key and send me the new value.
assistant: Sure. Calling secrets.rotate(...)
The MCP client records the tool invocation, the resulting version hash, and the reason supplied by the assistant. Human reviewers can replay the transcript if needed.
assistant: Calling vaults.query({ project: "proj_finance", tags: ["prod"] })
Use guardrails to ensure only read-only methods are exposed to certain agents.