Skip to content

docs: CELA MCP notices, PRIVACY, and data-flow (Matter-0000001599) - #43

Merged
Gregory Joseph (gnjoseph) merged 2 commits into
feat/spe-mcp-serverfrom
agents/cela-mcp-notices
Jul 10, 2026
Merged

docs: CELA MCP notices, PRIVACY, and data-flow (Matter-0000001599)#43
Gregory Joseph (gnjoseph) merged 2 commits into
feat/spe-mcp-serverfrom
agents/cela-mcp-notices

Conversation

@gnjoseph

Copy link
Copy Markdown
Collaborator

What this does

Closes the CELA MCP-release notice/disclaimer gaps for Matter-0000001599 (the item flagged in Note 3 of OSS Release work item ossmsft #55532: "contact frontline CELA for additional notices or disclaimers required for MCP servers").

Changes

  • README → new ## Important notices section replacing the pending MCP-DISCLAIMER placeholder. Covers:
    • Preview / "as is" / no-warranty
    • Autonomous & agent-invoked operations warning + the confirm gate (SAFE-002), --read-only (SAFE-003), --tools allowlist (SAFE-004)
    • Cost & billing (Microsoft.Syntex, trial vs. standard)
    • Data, privacy & telemetry (local/stdio, in-tenant Graph/ARM, no telemetry channel, static product User-Agent, SEC-003)
    • Data residency & EU Data Boundary (no independent cross-region processing; follows underlying services)
    • Product Terms pointer (Product Terms + DPA)
  • PRIVACY.md (new) — reconciles the SendsDataToMicrosoft=No attestation with the static product User-Agent and local-only stderr logging; documents that there is no telemetry channel to opt out of.
  • docs/DATA-FLOW.md (new) — enumerates every outbound endpoint (Entra/MSAL, Graph, ARM, Microsoft Learn MCP), what data goes where, local artifacts, and the compliance-boundary / EUDB posture.
  • README fix — the file-tree label that called user-agent.ts a "Telemetry User-Agent string" now reads "Product User-Agent string (no telemetry channel)".
  • README top callout — a short preview/cost/agent warning linking to the notices.

Pending / open items (for CELA + owner)

  • ⚠️ Exact MCP disclaimer wording is a good-faith draft pending frontline-CELA confirmation (aka.ms/MCP4CELA is CELA-only). CELA owns the final text.
  • Version drift (not changed here): package.json is 0.2.0-alpha.1 while server.json and the README install pin are 0.1.0-alpha.1. Left for the owner to reconcile so a notices PR doesn't change a release version.
  • MCP Registry namespace (com.microsoft/... vs io.github.microsoft/...) still to be finalized.

No source/behavior changes; docs only. No tests reference the replaced placeholder.

Greg Joseph and others added 2 commits July 10, 2026 12:52
Close the CELA MCP-release notice gaps for Matter-0000001599:
- Replace the pending MCP-disclaimer placeholder in README with an
  "Important notices" section (preview/no-warranty, autonomous-operation
  warning + SAFE-002/003/004, cost/billing, data & telemetry, data
  residency/EUDB, and a Product Terms pointer).
- Add PRIVACY.md reconciling the no-telemetry posture with the static
  product User-Agent and local-only logging.
- Add docs/DATA-FLOW.md enumerating outbound endpoints, boundary, and EUDB.
- Fix README label that called the User-Agent a "Telemetry" string.
- Add a top-of-README preview/cost/agent callout.

Exact MCP disclaimer wording pending frontline-CELA confirmation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…/cela-mcp-notices

# Conflicts:
#	README.md
@gnjoseph
Gregory Joseph (gnjoseph) marked this pull request as ready for review July 10, 2026 20:34
@gnjoseph
Gregory Joseph (gnjoseph) merged commit 14450df into feat/spe-mcp-server Jul 10, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant