# AI Agents for Compliance | Probo MCP

ai agents for compliance

# Run your compliance program from the tools you already work in.

Connect Claude, Cursor, ChatGPT or any MCP client to your live Probo data. Ask what is failing, update the risk register, prepare the audit. Every agent stays inside the permissions of the person who connected it. 
[Connect Probo MCP](/docs/developers/api/mcp/overview) [Book a demo](/contact) 

Connect your AI tools

Claude Cursor VS Code Windsurf Zed OpenCode 
## Everything in Probo, available to your AI agents.

Install one plugin to give an agent more than 350 tools, ready-made
compliance workflows, and the same permissions the person behind it
already has.

### +350 tools, one connection

Reach every Probo record from a single MCP endpoint, with tools and schemas discovered at connection time.

### Works in the tools your team already opens

Connect Claude, Cursor, VS Code, Windsurf, Zed, and OpenCode without building an integration.

### Scoped to what each person can already do

Grant read-only or read-write scopes per resource, and never above the user’s own permissions.

### Skills that know how to use the tools

Install open-source compliance workflows next to the tools, so an agent follows a procedure instead of improvising.

### Agents that act, not only report

Create and update records so an agent can carry a piece of compliance work to the end.

## An agent never sees more than the person who connected it.

Choose the scopes when you create the token, and keep every agent
inside the permissions its owner already holds.

### Install the plugin, then sign in

- Install the Probo plugin with a single command. 
- Sign in with your Probo account in one click. 
- Works with Probo Cloud, or your own self-hosted instance. 

[ See the full connection guide ](/docs/developers/api/mcp/overview) 
### Connect the client your team already uses

- Sign in with interactive OAuth from Claude, Cursor, VS Code, Windsurf, and Zed. 
- Use a static scoped token for clients that cannot run an interactive flow. 
- Load the same package in Codex, OpenCode, and Cursor from one plugin manifest. 

### Scope every agent before it connects

- Grant v1:resource:read for read-only access, or v1:resource to allow writes. 
- Keep access at the intersection of the token scopes and the user’s permissions. 
- Rotate or replace a token without touching the person’s account. 

### Ask questions against live compliance data

- Query risks, controls, evidence, audits, and findings in plain language. 
- Page through large result sets with cursors instead of truncated answers. 
- Read the current state of your program without exporting anything first. 

### Let agents do the work, not only describe it

- Create and update risks, measures, tasks, documents, and evidence. 
- Build agentic workflows without writing an API client first. 
- Check the behavior hints that mark each tool read only, destructive, idempotent, or open world. 

## +350 tools across 21 categories, ready at connection.

Discover the full catalog the moment your client connects, from risk
registers and control mappings to audits, access reviews, and privacy
records.

Opus 5 Extended RisksDocuments and approvalsPrivacyAccess reviewsFrameworks and controlsAudits and findingsRisksDocuments and approvalsPrivacyAccess reviewsFrameworks and controlsAudits and findingsRisksDocuments and approvalsPrivacyAccess reviewsFrameworks and controlsAudits and findings 
Run campaigns, pull entries from connected sources, and record decisions.
18 tools 
## Trusted by 130+ companies

Compliance teams use Probo to answer security questions, update risk
registers, and prepare audits from the AI tools they already work in.

"Probo handled our SOC 2 and compliance, so we could focus
on building."
Paul Sinai 
CEO & Co-founder of Blaxel

Trusted by teams building compliance-ready workflows

## Frequently asked questions

### How do we connect our AI assistant?

With one endpoint. Point your MCP client at us.probo.com/api/mcp/v1 or eu.probo.com/api/mcp/v1, complete the OAuth flow, and the tools appear.

### Does it work with self-hosted Probo?

Yes. Use the same /api/mcp/v1 endpoint on your own Probo origin, with the authentication and permissions of your deployment.

### Which AI agents and assistants are supported?

Connect Claude, ChatGPT, Codex, Cursor, VS Code, Windsurf, Zed, OpenCode, or another compatible MCP client. The setup and authentication method depend on the client.

### What can an AI agent actually do in Probo?

Agents can query risks, controls, evidence, audits, and findings, and create or update records when you grant the required write scopes.

### Can the agent change our compliance data?

Only when both its token scopes and the connected user’s permissions allow it. Use read-only scopes when the agent only needs to inspect data.

### Can an AI agent see more than the person who connected it?

No. Access is limited to the intersection of the token scopes and the permissions of the person who connected it.

### Do we have to update anything when Probo adds tools?

Clients discover the available tools and their schemas when they connect. Reconnect to discover newly available tools, subject to your granted scopes.

### Is this a proprietary integration?

No. Probo uses the open Model Context Protocol, so compatible clients can connect without a proprietary integration.

### What is the difference between the tools and the skills?

Tools let an agent read or change Probo records. Skills provide reusable compliance workflows that guide how the agent uses those tools.

### Can we read, fork, or write our own skills?

Yes. The compliance skills are open source, so you can read them, adapt them to your procedures, or write your own.

### Who decides what an agent is allowed to touch?

You choose the token scopes, and Probo enforces the connected user’s existing permissions on every operation.

### Is every agent action attributed and recorded in the audit log?

Yes. Agents go through the same authorization layer as the console, and every authorized call is written to the audit log with the timestamp, the action, the resource, and the identity behind it. Since an agent authenticates with an OAuth token issued to a person, its actions are attributed to that person. Entries are immutable and exportable as CSV.

### Does connecting an agent send our compliance data to Anthropic or OpenAI?

Probo sends nothing to a model provider. The MCP server only answers the client you connect, so where the data goes depends on that client: with Claude or ChatGPT it is processed by Anthropic or OpenAI under your own plan and your own retention and training settings. Point a local model at it and no third party sees anything. Probo's own AI features do use Anthropic and OpenAI, both listed on our subprocessor page.

### Is MCP access included in our plan?

Yes. API, MCP, and CLI access are included for every customer, with no add-on, no tier, and no per-call quota tied to a plan. What an agent can reach is set by OAuth scopes and user permissions, not by billing.

## Discover what else Probo can do

- [ 
### Compliance Officer Service

Expert-led compliance, end to end 
](/) 
- [ 
### Compliance Portal

Share security documents securely 
](/products/compliance-portal) 
- [ 
### Access Review

Monitor user access across all your systems 
](/products/access-review) 
- [ 
### AI Agents

Run your compliance program from the tools you already work in 
](/products/ai-agents-for-compliance)
