governanceoracle

GovernanceOracle - 10 governance tools: board packs, policies, attestations, evidence.

Should I use this

Quality & Safety

B
Description quality
88%
Schema completeness
57%
Naming quality
82%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (2)

  • LOWTool 'control_status' description lacks action verbin control_status
  • LOWTool 'health_check' description lacks action verbin health_check

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~927Tokens (tool definitions)
~767 BTypical response size
Moderate attention impact (0.72% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "governanceoracle": {
      "url": "https://tooloracle.io/governance/mcp/"
    }
  }
}

Remote endpoints

https://tooloracle.io/governance/mcp/streamable-http

What it can do

Tool inventory

Tools (11)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
⚪register_finding(finding_id, title, description, severity, source, ...)

Register an audit finding, risk, or control gap.

Input Schema

{
  "type": "object",
  "properties": {
    "finding_id": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low",
        "info"
      ]
    },
    "source": {
      "type": "string",
      "description": "audit, pentest, incident, self-assessment"
    },
    "domain": {
      "type": "string",
      "enum": [
        "access_management",
        "change_management",
        "incident_management",
        "business_continuity",
        "third_party_risk",
        "data_protection",
        "network_security",
        "vulnerability_management",
        "logging_monitoring",
        "cryptography",
        "physical_security",
        "awareness_training"
      ]
    },
    "status": {
      "type": "string",
      "enum": [
        "open",
        "in_progress",
        "remediated",
        "accepted",
        "overdue"
      ]
    },
    "owner": {
      "type": "string"
    },
    "due_date": {
      "type": "string"
    },
    "remediation_plan": {
      "type": "string"
    },
    "related_article": {
      "type": "string"
    },
    "evidence_ref": {
      "type": "string"
    },
    "notes": {
      "type": "string"
    }
  },
  "required": [
    "title",
    "severity"
  ],
  "additionalProperties": false
}
🟢list_findings(status, severity, domain, owner)

List findings with optional filters.

Input Schema

{
  "type": "object",
  "properties": {
    "status": {
      "type": "string",
      "enum": [
        "open",
        "in_progress",
        "remediated",
        "accepted",
        "overdue"
      ]
    },
    "severity": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low",
        "info"
      ]
    },
    "domain": {
      "type": "string",
      "enum": [
        "access_management",
        "change_management",
        "incident_management",
        "business_continuity",
        "third_party_risk",
        "data_protection",
        "network_security",
        "vulnerability_management",
        "logging_monitoring",
        "cryptography",
        "physical_security",
        "awareness_training"
      ]
    },
    "owner": {
      "type": "string"
    }
  },
  "additionalProperties": false
}
⚪board_report(period)

Generate Management Body review pack — executive summary, open findings, risk posture, overdue items.

Input Schema

{
  "type": "object",
  "properties": {
    "period": {
      "type": "string",
      "description": "Reporting period (e.g., 'Q1 2026')"
    }
  },
  "additionalProperties": false
}
⚪framework_review

ICT Risk Management Framework annual review — effectiveness assessment per DORA area.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪control_status

Control effectiveness dashboard across all DORA control domains.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟡exception_register(add, finding_id, title, risk_description, accepted_by, ...)

View or add risk acceptances / exceptions with expiry tracking.

Input Schema

{
  "type": "object",
  "properties": {
    "add": {
      "type": "boolean",
      "description": "Set true to add a new exception"
    },
    "finding_id": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "risk_description": {
      "type": "string"
    },
    "accepted_by": {
      "type": "string"
    },
    "acceptance_date": {
      "type": "string"
    },
    "expiry_date": {
      "type": "string"
    },
    "compensating_controls": {
      "type": "string"
    }
  },
  "additionalProperties": false
}
⚪action_tracker(add, finding_id, title, owner, due_date, ...)

Track remediation actions with deadlines and ownership.

Input Schema

{
  "type": "object",
  "properties": {
    "add": {
      "type": "boolean",
      "description": "Set true to add a new action"
    },
    "finding_id": {
      "type": "string"
    },
    "title": {
      "type": "string"
    },
    "owner": {
      "type": "string"
    },
    "due_date": {
      "type": "string"
    },
    "priority": {
      "type": "string",
      "enum": [
        "critical",
        "high",
        "medium",
        "low"
      ]
    }
  },
  "additionalProperties": false
}
⚪kpi_dashboard

ICT Risk KPIs — open findings, overdue rate, remediation rate, exception count.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪annual_review

Annual framework review evidence bundle — checklist, stats, Art. 6(5) compliance.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪board_report_llm(language, additional_context)

AI-powered board executive summary using local Gemma 4 LLM. Generates narrative summary from current findings in German or English.

Input Schema

{
  "type": "object",
  "properties": {
    "language": {
      "type": "string",
      "description": "Language: de or en",
      "default": "en"
    },
    "additional_context": {
      "type": "string",
      "description": "Extra context to include (deadlines, events)"
    }
  },
  "additionalProperties": false
}
🟢health_check

Server status.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded11 tools
verifiedversion not recorded11 tools
verifiedversion not recorded11 tools