Tristan Jones
IT Audit and Technology Risk leader with 15+ years across SOX compliance, cybersecurity governance, and internal controls for global financial institutions — specializing in AI Governance and Responsible AI.
https://tristanjones.aiConnect straight to this server’s public endpoint.
https://mcp.tristanjones.ai/mcpWe add this server to your workspace, walk through sign-in once, then open Studio with tools ready to run.
Last probed Sep 14, 2026 · mcp.tristanjones.ai
15tools discovered
Get Decomposition
Get pre-validated RG decomposition for a Diagnostic Statement. Returns the RG capabilities with required_control_characteristics for each RG. These decompositions are generated by L3 at high quality and cached. The client skill uses this instead of local model decomposition. Each RG includes: - required_control_characteristics: framework-neutral terms describing what controls must address - keywords: terms that should appear in matching controls - expected_evidence: what a satisfying control s
Get Control Characteristics
Get required control characteristics for a Diagnostic Statement. Returns framework-neutral characteristics that describe what kinds of controls are needed. These work regardless of the client's control framework (NIST, SCF, ISO, CIS, or custom). The client maps their own control families to these characteristics in their local profile.
Get Baseline
Get quality baseline for a Diagnostic Statement. Returns the known-good assessment metrics from L3 review. Used for model qualification — compare L1 results against these.
List Available
List all Diagnostic Statements with available decompositions.
Validate Selection
Validate selection metrics against baseline. Quick check: is the selection count in the acceptable range? Returns pass/fail with the expected range.
Get Methodology Rule
Get a standalone versioned methodology rule. These are the canonical standards that govern how CRI assessments are performed. They are independently versioned so methodology changes are tracked separately from prompt template changes. Available rules: - rating_definitions: Coverage rating definitions (Covered/Partial/No Coverage) - quote_verification: Rules for quoting control language as evidence - exclusion_rules: Rules for excluding controls from assessment Each rule includes: - version: S
Get Cri Source
Get CRI v2.2 source material for a Diagnostic Statement. Returns the DS text, full Response Guidance text, EEE packages, and metadata (function, category, impact tiers).
Get Prompt Template
Get a versioned prompt template for the assessment pipeline. Available templates: - selection: Control selection pipeline prompt - assessment: Coverage assessment pipeline prompt Templates include variable placeholders that the runner fills in. This keeps business logic (methodology rules, rating definitions) in the knowledge layer, not embedded in execution code.
Get Report Template
Get the HTML report template for CRI coverage assessment workpapers. Returns the canonical template with CSS, HTML structure, and row templates. The skill populates this template mechanically from assessment output. No model is involved in report generation. Template uses {{variable}} placeholders. Row templates are used in loops to generate repeated elements (decomposition rows, control rows, etc.).
Get Findings Taxonomy
Get the findings classification taxonomy for CRI assessments. Returns categories (Governance, Process, Technology, Monitoring, Documentation, Evidence, Coverage), conditions (Missing, Weak, Inconsistent, Inefficient, Undemonstrated), and severities (Critical, High, Medium, Low). L1 uses this taxonomy to classify each gap identified during assessment. The runner uses the classifications to populate Section 4 (Findings) of the report template.
Get Evidence Requirements
Get EEE evidence requirements for a Diagnostic Statement. Returns the examiner's evidence checklist — what artifacts an organization should produce to demonstrate that controls are actually operating. Each EEE package contains: - package_id: EEE identifier (e.g., EEE-035) - package_name: Evidence package title - evidence_items: List of specific evidence artifacts expected
Get Eee Package
Get a specific EEE package by ID. Returns the full evidence package with all expected artifacts. Useful for cross-referencing — the same EEE package may apply to multiple Diagnostic Statements.
Get Package Checksum
Get the SHA-256 checksum for a Knowledge Package. The checksum is computed on the canonical JSON of the data package (sorted keys, no whitespace). The runner recomputes the checksum on the received data and compares — if they don't match, the data was modified in transit or the server has a corrupted copy.
Get Evidence Graph
Get evidence-to-capability connections for a Diagnostic Statement. Returns which evidence items demonstrate which capabilities, and which technologies produce those evidence items. This is the bridge between "what controls exist" and "what proof should exist." The response includes: - Evidence items mapped to capabilities they demonstrate - Examiner objectives for each evidence item - Technologies that can produce each type of evidence - The full traceability chain: Evidence → Capability → RG
Get Technology Evidence
Get evidence artifacts that a technology platform produces. Returns what evidence each technology generates, which capabilities that evidence demonstrates, and which EEE packages it satisfies. Without a technology filter, returns the full registry summary. With a technology name, returns detailed evidence for that platform.
Get your MCP into directories
A working endpoint is step one. Directory coverage is the coordinated launch across ChatGPT, Claude, Cursor, the MCP Registry, and community indexes.
Directory coverage for brandsIT Audit and Technology Risk leader with 15+ years across SOX compliance, cybersecurity governance, and internal controls for global financial institutions — specializing in AI Governance and Responsible AI.
Use the MCP endpoint listed on this page in your MCP client configuration. One-click install pills support Claude, Cursor, VS Code, and other hosts. Copy the remote MCP URL if your client needs a manual entry.
Operate Tristan Jones? Verify ownership to take over this directory entry.
This server appears in the MCPBundles directory. Verify you operate it to take over the listing — name, description, logo, contact email, and skill content. We email a 6-digit code to a maintainer address your server publishes in /.well-known/security.txt or /.well-known/mcpbundles.json. Free, takes about a minute.
MCPBundles probed 15 tools on the live server. The tool list on this page reflects what was discovered at the last refresh — connect your client to see the full set available to your session.
Tristan Jones may require signing in to the provider before tools can run. Connect through MCPBundles or your MCP client and complete any provider login when prompted.
MCPBundles is an independent platform built on the open Model Context Protocol standard. Not affiliated with Anthropic PBC or Claude.