Now that you've connected Scrut MCP to your AI tool, here's what each tool does so you know what your AI assistant can find, read, answer, and file on your behalf.
How These Tools Work
You don't need to name a specific tool in your prompts. Describe what you're trying to do, and your AI assistant selects the right tool, or combination of tools, automatically. For example, asking for a compliance digest might call the frameworks, controls, evidence, and test tools together in a single response.
Scrut MCP Tools
Tool | What does it do? | Use this to | Sample Prompts |
|---|---|---|---|
scrut_list_frameworks | Lists your enabled compliance frameworks, such as SOC 2, ISO 27001, or GDPR, along with each one's next audit date. | Get a quick view of which frameworks are active and when they're next up for audit. |
|
scrut_list_controls | Lists framework controls, including code, domain, owner, and status. Can be filtered by framework or product. | See which controls exist under a framework and who owns them. |
|
scrut_get_control | Retrieves full details for a single control. | Check the specifics of one control before reporting on it or acting on it. |
|
scrut_list_policies | Lists your compliance policies, including status, owner, and review date. Can be filtered by framework, product, or status. | Find policies that are in draft, in review, or past their review date. |
|
scrut_get_policy | Retrieves full details for a single policy, including its owners, approvers, mapped frameworks and controls, and current policy document. | Check the status and ownership of a specific policy before an audit or review. |
|
scrut_list_evidence | Lists evidence items, including status, assignee, and review date. Can be filtered by framework, product, or status. | Find evidence that's stale, missing, or coming up for review. |
|
scrut_get_evidence | Retrieves full details for a single evidence item, including its status, owner, mapped controls, and currently uploaded documents. | Check what's currently attached to a specific piece of evidence. |
|
scrut_list_tests | Lists your automated tests, including cloud provider and pass or fail status. | See which cloud tests are currently failing across your program. |
|
scrut_get_test | Retrieves full details for a single continuous test, including the cloud provider, test level, and mapped controls. | Get the specifics of one failing test before working on a fix. |
|
scrut_answer_question | Returns a synthesized, sourced answer to a question, drawn from your published policies, Trust Vault, and Vault documents. If it isn't confident in an answer, it says so and flags the gap instead of guessing. | Draft security questionnaire answers or get a quick, sourced answer to a compliance question mid-task. |
|
scrut_get_document_ content | Retrieves the full text of one specific policy or evidence document. | Quote or verify exact wording in a document, or check whether a document still reflects a recent change. |
|
scrut_search_ documents | Finds a document by name across policies, evidence, and Trust Vault. | Locate a specific document when you don't have its exact ID or category. |
|
scrut_upload_file | Uploads a file and returns a document object. Doesn't attach it to anything on its own; pair it with scrut_attach_evidence_document. | Get a newly generated file, like an access review or config export, into Scrut. |
|
scrut_attach_evidence_ document | Attaches an uploaded document or an external link to an evidence item, with an optional date and note. | File a document or link to the right evidence item as soon as it's ready. |
|
Good to Know
Every tool returns clean, readable output by default. List tools return results in pages. If your program has many frameworks, controls, or evidence, ask your AI assistant to show you more, and it will automatically pull the next page.
Write actions are bounded. Scrut MCP can upload and attach evidence, but it cannot delete, overwrite, or freely edit anything already in your compliance program.
There is no tool to download the contents of an existing policy or evidence file. Read tools return the document's details and reference information, not the file itself.
Tips for Better Outputs
Name the framework when it matters, for example, SOC 2 or ISO 27001. A vague prompt may pull from every framework you have enabled.
State your goal, not just the data you want. Tell your AI assistant what you're trying to accomplish, and it selects the right tools on its own.
Ask for sources when the answer matters. Scrut's answer tool always returns sources, but asking explicitly makes sure your AI assistant surfaces them in its reply. This is super helpful for questionnaire answers you plan to send externally.
Review before you rely on it. MCP gives you a faster starting point, not a final answer. Check evidence decisions and questionnaire responses before you send them.
Confirm before filing evidence. Add "show me what you're about to attach before you do it" for anything you want to double-check first.
Chain a search with an action in one prompt: "Check whether we have evidence for X, and if we do, tell me its current status."
Reach out to support@scrut.io or contact your CSM for further assistance.