governanceoracle
GovernanceOracle - 10 governance tools: board packs, policies, attestations, evidence.
Should I use this
Quality & Safety
Findings (2)
- LOWin control_status
- LOWin health_check
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"governanceoracle": {
"url": "https://tooloracle.io/governance/mcp/"
}
}
}Remote endpoints
https://tooloracle.io/governance/mcp/streamable-httpWhat it can do
Tool inventory
Tools (11)
⚪register_finding(finding_id, title, description, severity, source, ...)
Register an audit finding, risk, or control gap.
Input Schema
{
"type": "object",
"properties": {
"finding_id": {
"type": "string"
},
"title": {
"type": "string"
},
"description": {
"type": "string"
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low",
"info"
]
},
"source": {
"type": "string",
"description": "audit, pentest, incident, self-assessment"
},
"domain": {
"type": "string",
"enum": [
"access_management",
"change_management",
"incident_management",
"business_continuity",
"third_party_risk",
"data_protection",
"network_security",
"vulnerability_management",
"logging_monitoring",
"cryptography",
"physical_security",
"awareness_training"
]
},
"status": {
"type": "string",
"enum": [
"open",
"in_progress",
"remediated",
"accepted",
"overdue"
]
},
"owner": {
"type": "string"
},
"due_date": {
"type": "string"
},
"remediation_plan": {
"type": "string"
},
"related_article": {
"type": "string"
},
"evidence_ref": {
"type": "string"
},
"notes": {
"type": "string"
}
},
"required": [
"title",
"severity"
],
"additionalProperties": false
}🟢list_findings(status, severity, domain, owner)
List findings with optional filters.
Input Schema
{
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"open",
"in_progress",
"remediated",
"accepted",
"overdue"
]
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low",
"info"
]
},
"domain": {
"type": "string",
"enum": [
"access_management",
"change_management",
"incident_management",
"business_continuity",
"third_party_risk",
"data_protection",
"network_security",
"vulnerability_management",
"logging_monitoring",
"cryptography",
"physical_security",
"awareness_training"
]
},
"owner": {
"type": "string"
}
},
"additionalProperties": false
}⚪board_report(period)
Generate Management Body review pack — executive summary, open findings, risk posture, overdue items.
Input Schema
{
"type": "object",
"properties": {
"period": {
"type": "string",
"description": "Reporting period (e.g., 'Q1 2026')"
}
},
"additionalProperties": false
}⚪framework_review
ICT Risk Management Framework annual review — effectiveness assessment per DORA area.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪control_status
Control effectiveness dashboard across all DORA control domains.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟡exception_register(add, finding_id, title, risk_description, accepted_by, ...)
View or add risk acceptances / exceptions with expiry tracking.
Input Schema
{
"type": "object",
"properties": {
"add": {
"type": "boolean",
"description": "Set true to add a new exception"
},
"finding_id": {
"type": "string"
},
"title": {
"type": "string"
},
"risk_description": {
"type": "string"
},
"accepted_by": {
"type": "string"
},
"acceptance_date": {
"type": "string"
},
"expiry_date": {
"type": "string"
},
"compensating_controls": {
"type": "string"
}
},
"additionalProperties": false
}⚪action_tracker(add, finding_id, title, owner, due_date, ...)
Track remediation actions with deadlines and ownership.
Input Schema
{
"type": "object",
"properties": {
"add": {
"type": "boolean",
"description": "Set true to add a new action"
},
"finding_id": {
"type": "string"
},
"title": {
"type": "string"
},
"owner": {
"type": "string"
},
"due_date": {
"type": "string"
},
"priority": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low"
]
}
},
"additionalProperties": false
}⚪kpi_dashboard
ICT Risk KPIs — open findings, overdue rate, remediation rate, exception count.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪annual_review
Annual framework review evidence bundle — checklist, stats, Art. 6(5) compliance.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪board_report_llm(language, additional_context)
AI-powered board executive summary using local Gemma 4 LLM. Generates narrative summary from current findings in German or English.
Input Schema
{
"type": "object",
"properties": {
"language": {
"type": "string",
"description": "Language: de or en",
"default": "en"
},
"additional_context": {
"type": "string",
"description": "Extra context to include (deadlines, events)"
}
},
"additionalProperties": false
}🟢health_check
Server status.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Community
Evidence