01 · Mental model
Action, connection, and retrieval are complementary
A function tool exposes a named application operation with structured arguments. MCP standardizes how a host discovers and exchanges tools, resources, and prompts with servers. Retrieval selects relevant evidence from a corpus and places it into context.
None of these mechanisms automatically grants trust. The application still authenticates the caller, authorizes the action, validates arguments and results, applies budgets, and records relevant evidence.
02 · Visual explanation
03 · Compare and decide
Match the mechanism to the problem
| Decision lens | Primary job | Security question |
|---|---|---|
| Function tool | Execute a named operation | Who may call this verb with which arguments? |
| MCP server | Expose reusable capabilities and resources | Do we trust this server, transport, and returned content? |
| RAG | Select passages relevant to a question | Which corpus, access filter, provenance, and freshness apply? |
| Browser | Reach changing external information | Which destinations, content types, and data egress are permitted? |
04 · Cybersecurity example
Building a Sentinel design assistant
The assistant needs Microsoft guidance, environment metadata, and a rendered architecture diagram.
RAG retrieves approved design standards.
A read-only tool obtains workspace metadata.
An MCP server exposes ArchStudio generation.
Policy validates scope before each call.
Outcome: Each mechanism has one job, one trust boundary, and one observable result.
05 · What to remember
The 60-second recall
Tools perform verbs; retrieval supplies evidence; MCP standardizes connection.
Connection standards do not replace authentication or authorization.
Prefer narrow, schema-defined operations over generic execution.
Teach-back prompt: Explain this concept to a teammate using the diagram, then name one failure mode and the control that stops it.
06 · Questions people ask
FAQ
07 · Primary sources