Native MCP enforcement from immutable TrustOps decisions
Verify evaluates canonical evidence once, preserves the organization decision, and compiles the result into Microsoft-managed settings. Verify produces the auditable artifact; your infrastructure deploys it and Microsoft/GitHub enforce it.
Evidence to enforcement artifact
Native policy contract
The generated file uses allowedMcpServers, deniedMcpServers, and, in strict mode, allowManagedMcpServersOnly. It contains no Verify metadata, workstation credentials, wildcards, or local-command rules.
Responsibility boundary
Verify: evidence, immutable decisions, deterministic artifacts, validation, hashes, and audit history.
Customer: approval and deployment through GitOps, MDM, configuration profiles, or equivalent enterprise tooling.
Microsoft/GitHub: interpretation and enforcement of managed settings inside VS Code and GitHub Copilot.