Illustrative Non-Executing MCP Example

How ChatGPT Launches an OACP-Grounded Commerce Preview on AgenticOrg

This fictional sample uses no live tenant, buyer, merchant, or provider data. It shows how a compatible MCP client could request a comparison while the Commerce Sales Agent evaluates cached OACP artifacts and returns a non-executing handoff or refusal.

Architecture Stack

1
UserChatGPT, Claude, Cursor, Custom App
2
MCP ClientModel Context Protocol transport (stdio/SSE)
3
AgenticOrg MCP Serveragenticorg-mcp-server (npx)
4
Auth LayerAPI Key (ao_sk_) / Grantex Token / JWT
5
Agent RuntimeLangGraph + OACP cache evaluator; allowed_to_execute=false
6
HITL GatewayPrepared handoff review, not execution
7
ConnectorsOACP-governed commerce tools + native connectors
Data flows top-to-bottom, results return bottom-to-top

Step-by-Step Workflow

Click any step to see details. The flow is intentionally non-executing until separate Grantex and production approvals exist.

Step 1User

Asks ChatGPT to compare products

"Hey ChatGPT, find wireless earbuds under $50, compare the safest options, and tell me whether checkout can be prepared."
Step 2ChatGPT

Discovers AgenticOrg via MCP

Step 3ChatGPT

Calls commerce agent via MCP

Step 4AgenticOrg

Authenticates via API Key / Grantex

Step 5Commerce Sales Agent

Evaluates cached OACP artifacts

Step 6AgenticOrg

Prepared handoff review

Step 7User

Reviews the prepared state

Step 8Commerce Sales Agent

Returns safe result

Sequence Diagram

  User          ChatGPT         MCP Server       AgenticOrg API      Commerce Agent      Review
   |               |               |                  |                    |               |
   |  "Compare     |               |                  |                    |               |
   |   earbuds"    |               |                  |                    |               |
   |──────────────>|               |                  |                    |               |
   |               |  list_tools() |                  |                    |               |
   |               |──────────────>|                  |                    |               |
   |               |  [safe tools] |                  |                    |               |
   |               |<──────────────|                  |                    |               |
   |               |               |                  |                    |               |
   |               |  run_agent(   |                  |                    |               |
   |               |   commerce,   |                  |                    |               |
   |               |   earbuds)    |                  |                    |               |
   |               |──────────────>|                  |                    |               |
   |               |               | POST /a2a/tasks  |                    |               |
   |               |               | Bearer ao_sk_... |                    |               |
   |               |               |─────────────────>|                    |               |
   |               |               |                  | validate API key   |               |
   |               |               |                  | extract tenant     |               |
   |               |               |                  |                    |               |
   |               |               |                  | invoke LangGraph   |               |
   |               |               |                  |───────────────────>|               |
   |               |               |                  |                    |  read cache   |
   |               |               |                  |                    |  check TTL    |
   |               |               |                  |                    |  verify rev   |
   |               |               |                  |                    |               |
   |               |               |                  |                    | source refs   |
   |               |               |                  |                    | handoff?      |
   |               |               |                  |                    |──────────────>|
   |               |               |                  |                    |               |
   |  Review: "Prepared handoff only; no execution"   |                    |               |
   |<──────────────────────────────────────────────────────────────────────────────────────|
   |               |               |                  |                    |               |
   |  [Review]     |               |                  |                    |               |
   |──────────────────────────────────────────────────────────────────────────────────────>|
   |               |               |                  |                    |               |
   |               |               |                  |                    | no execute()  |
   |               |               |                  |                    |<──────────────|
   |               |               |                  |                    |               |
   |               |               |                  |  safe result       |               |
   |               |               |                  |<───────────────────|               |
   |               |               | 200 OK           |                    |               |
   |               |               |<─────────────────|                    |               |
   |               |  result JSON  |                  |                    |               |
   |               |<──────────────|                  |                    |               |
   |  "Grounded options returned;                  |                    |               |
   |   checkout/payment blocked"  |                  |                    |               |
   |<──────────────|               |                  |                    |               |

Key Takeaways

OACP-Grounded, Not Provider-Direct

Commerce answers come from valid cached artifacts or Grantex authority paths. The agent does not call direct provider, merchant-private, checkout, or payment rails.

HITL on Prepared Handoffs

Human review can acknowledge source/freshness limits, but it does not override revocation, stale evidence, or missing approval gates.

Designed for Compatible MCP Clients

Compatible MCP clients can use the governed tool surface when transport, authentication, versions, scopes, and tenant configuration are supported and tested.

Fail-Closed Commerce Boundary

Live checkout, live payments, public discovery, provider rails, and merchant-private APIs stay blocked until separately approved and verified.

Ready to Evaluate a Governed Integration?

Start with a sandbox or fictional sample, verify client compatibility and scopes, and test source checks, refusals, provider outages, and rollback before production use.