All Posts

Best Practices

6 min.

 min read

August 5, 2026

Model Context Protocol in Production: AI-Native Privileged Access with VISULOX

Privileged remote access generates critical data that has largely gone unused. With the Model Context Protocol, we make that data accessible to AI enabling new approaches to auditing, anomaly detection, and real-time support.

Jan Zeppernick - Amitego CEO

Jan Zeppernick

Management

Introduction

Software integration has never really been "solved." We've just learned to live with it. APIs gave us structure, but they also introduced a quiet kind of complexity versioning issues, brittle dependencies, undocumented edge cases. Most of the time, humans sit in the middle and make it work. They read the docs, debug the errors, and adapt when something breaks.

Key Takeaways

    • Privileged remote access systems generate highly valuable security data that is often underutilized.
    • Traditional API-based integrations are not sufficient for reliable AI interaction.
    • MCP provides structured, deterministic access between AI and critical systems.
    • AI can interact with privileged access data in real time instead of relying on static logs.
    • New capabilities emerge in audit, anomaly detection, and operational support.
    • Systems need to be redesigned to be truly AI-ready, not just API-accessible.
    • Structured access enables better observability, traceability, and control.
    • MCP reduces ambiguity and replaces prompt-based guesswork with defined capabilities.
    • Security workflows can become more dynamic and responsive through AI interaction.
    • AI becomes an active participant in security operations, not just an analysis layer.
  • Software integration has always been a balancing act. Over the years, APIs became the standard way to connect systems, and for a long time, that was good enough. Humans sat in the loop, interpreting responses, handling edge cases, and making sense of what systems exposed.

    That assumption no longer holds.

    As soon as AI becomes part of the equation, the way systems interact starts to break down. Models do not read documentation like engineers do. They do not reliably interpret loosely defined interfaces. And yet, we are increasingly asking them to work with sensitive systems, make decisions, and operate workflows.

    Nowhere is this more critical than in the domain of privileged remote access.

    Why privileged remote access is the critical case

    Systems like VISULOX sit at the center of highly sensitive operations. They control who gets access to what, when, and under which conditions. They record sessions, enforce policies, and generate some of the most valuable security data in an organization. But despite this, most of that data remains underutilized. It is stored, audited occasionally, and rarely turned into something actionable in real time.

    At amitego, we reached a point where traditional approaches were no longer sufficient. Trying to connect AI to systems like VISULOX through APIs and prompt logic quickly becomes fragile. Too much interpretation, too little structure, and no reliable way to ensure that what the model does is actually correct.

    This is where the Model Context Protocol comes in.

    What the Model Context Protocol changes

    Introduced by Anthropic, MCP defines a structured way for models like Claude or ChatGPT to interact with external systems. Instead of relying on loosely described endpoints and instructions hidden in prompts, MCP exposes capabilities as clearly defined functions with strict input and output structures.

    That might sound like an incremental improvement, but in practice, it changes how systems can be used.

    From API to capability: our MCP server

    When we built our MCP server at amitego, the goal was not to experiment with a new protocol. The goal was to make systems like VISULOX directly usable by AI in a way that is reliable, observable, and secure.

    This required a different way of thinking.

    Instead of asking how to connect to an API, we asked what capabilities should exist. Instead of exposing raw endpoints, we defined explicit actions. For example, retrieving session data is no longer a generic API call. It becomes a structured capability with clear parameters, constraints, and expected results. The same applies to actions like querying access logs, analyzing session behavior, or evaluating policy compliance.

    Once these capabilities are defined, something interesting happens.

    AI can start to operate on top of them in a way that feels natural, but is actually grounded in strict structure. A request like “show me all unusual privileged sessions from the last 24 hours” is no longer a vague instruction. It becomes a sequence of well-defined operations that the system can execute and verify.

    This opens up a range of use cases that were previously difficult or impractical.

    Use cases: from real-time analysis to operational support

    One of the most immediate ones is real-time session analysis. Privileged sessions are often recorded for later review, but by the time someone looks at them, the moment has passed. With MCP, AI can access session data as it is generated and analyze it continuously. Patterns that would normally go unnoticed can be flagged instantly. Suspicious behavior does not have to wait for an audit cycle.

    Another important area is anomaly detection. Traditional approaches rely on predefined rules, which are limited by what you expect to happen. AI, when given structured access to session data and system context, can identify deviations that are harder to encode manually. The key difference is that this analysis is not happening on exported data or approximations, but directly within the system boundary.

    Audit and compliance workflows also change significantly. Instead of manually reviewing logs or generating static reports, teams can query their systems in a more dynamic way. Questions that used to require custom scripts or data exports can now be answered directly. More importantly, the answers are grounded in actual system data, not in partial snapshots.

    There is also a strong case for operational support. Engineers working with privileged access systems often need context quickly. What happened in a session? Who accessed which system? Was a policy violated? With MCP, AI can act as a layer that retrieves and composes this information in real time, without requiring manual navigation through multiple interfaces.

    Not just access, but structure

    What ties all of this together is not just access to data, but the way that access is structured.

    MCP enforces clarity. Every capability has a defined shape. Every interaction can be traced. Every action can be understood after the fact. This is particularly important in a security context, where ambiguity is not acceptable. If an AI system is interacting with privileged access controls, you need to know exactly what it is doing.

    This also highlights a broader issue. Many systems claim to be ready for AI, but in reality, they are only accessible through interfaces designed for humans. MCP exposes this gap. It requires systems to be explicit, consistent, and predictable. Adopting it often means improving the underlying architecture, not just adding a new layer on top.

    At amitego, building an MCP server was as much about that internal clarity as it was about external capability. It forced us to define what our systems should expose and how they should behave when used by AI. It made implicit assumptions visible and required us to resolve them.

    The result is a system where AI interaction is no longer based on guesswork.

    Outlook: AI as an active participant in security operations

    More importantly, it creates a foundation for what comes next.

    If AI is going to play a role in security operations, it needs more than access. It needs structure. It needs boundaries. And it needs a way to interact with systems that does not depend on interpretation.

    MCP is one of the first approaches that provides that.

    We do not see this as a finished solution. The ecosystem is still evolving, and there are open questions around standardization, tooling, and best practices. But the direction is clear. Systems will increasingly be designed not just for human users, but for AI as an active participant.

    That shift is already happening.

    At amitego, we are making our MCP server available to teams who want to explore this space in a real environment. If you are working with privileged access, security operations, or AI-driven workflows, this is an opportunity to test what structured AI interaction actually looks like in practice.

    The question is no longer whether AI will interact with systems like VISULOX. The question is whether those systems are ready for it.

    Contact

    Your Direct Path to Secure Remote Access

    Speak directly with a cybersecurity expert.

    Personal Meeting
    Personal Meeting
    Personal Meeting

    Conclusion

    AI is moving from an analysis layer to an active participant in security operations. The systems it touches  and none are more sensitive than privileged remote access  need structure, boundaries, and traceability, not human-oriented interfaces bolted onto an API. The Model Context Protocol is one of the first approaches that delivers exactly that. With its MCP server, VISULOX turns privileged-access data into something AI can work with reliably, observably, and securely. The question is no longer whether AI will interact with systems like VISULOX  but whether those systems are ready for it.

    Jan Zeppernick - Amitego CEO

    Jan Zeppernick

    Management

    Jan verfügt über mehr als 12 Jahre Beratungserfahrung bei PwC und Ernst & Young, mit Schwerpunkt auf Informationssicherheit und Compliance für kritische Infrastrukturen und die Automobilbranche. Als zertifizierter ISO 27001 Lead Auditor und Strategieexperte berät er Organisationen beim Aufbau und der Auditierung von Sicherheitsmanagementsystemen nach ISO 27001 und TISAX.