Your agent is the harness. ISMS Copilot is the GRC specialist it delegates to.
Talk to a specialist compliance AI from the harness you already use. Your coding agent keeps the code, the repo and the plan. When a task turns into ISO 27001, SOC 2, GDPR, NIS 2 or DORA work, it sends the question to ISMS Copilot over MCP and gets the answer back.
Claude Code, one line
claude mcp add --scope user --transport http ismscopilot https://account.ismscopilot.com/v1/account/mcp --header "Authorization: Bearer pat-isms-..."How delegation works
- 01
Your agent sends the question
Mid-task, your harness calls ISMS Copilot through the MCP tools create_conversation and send_message. What travels is the message your agent writes, nothing else from your repository or filesystem.
- 02
The specialist does the GRC work on its side
Curated framework knowledge, the memories and files of the workspace the conversation runs in, and the drafting itself all happen on ISMS Copilot's side. A policy draft or a gap analysis is generated there, not in your agent's context window.
- 03
Only the answer comes back
Your agent receives the finished answer as a tool result. The bulk of the GRC context never enters its transcript, so it is never re-sent on every later turn of the session.
- 04
The answer still counts, so ask for short ones
The returned answer is read by your agent like any other tool result, and it stays in the transcript from then on. When you only need a decision or a list, tell the agent to ask for a brief answer.
What to delegate, what to keep local
| Work | Where it runs | Why |
|---|---|---|
| Policy and procedure drafting | Delegate to ISMS Copilot | Long drafting is generated on the specialist's side; your agent receives the finished draft. |
| Gap analysis and control mapping | Delegate to ISMS Copilot | Framework knowledge is injected there, so you do not paste standards into your own context. |
| Statement of Applicability justifications, risk register entries | Delegate to ISMS Copilot | Structured GRC output grounded in curated framework modules. |
| Audit preparation and framework questions | Delegate to ISMS Copilot | ISO 27001, ISO 27701, ISO 42001, SOC 2, GDPR, NIS 2, DORA, EU AI Act, HIPAA, PCI DSS and more. |
| Code, git, tests, configuration | Keep in your harness | That is your agent's job. ISMS Copilot has no access to your repository. |
| Reading and editing local files | Keep in your harness | The specialist only sees what your agent puts in the message. |
| One-word lookups and trivia | Keep in your harness | A round trip is not worth it for something your model already knows. |
Connect your harness
| Harness | Status | How it connects |
|---|---|---|
| Claude Code | Supported | The one-line claude mcp add above, with the Authorization: Bearer pat-isms- header. |
| Cursor | Supported | An HTTP MCP server entry in mcp.json: the endpoint URL plus the Authorization header. |
| Codex | Supported | An mcp_servers entry in ~/.codex/config.toml: the endpoint URL plus the Authorization header. |
| OpenCode | Supported | A remote MCP server entry with the endpoint URL and the Bearer header. |
| Grok | Supported | An HTTP MCP server entry with the endpoint URL and the Bearer header. |
| Claude Desktop and claude.ai connectors | Not yet | Connectors need OAuth; the endpoint takes personal access tokens today. |
| ChatGPT | Not yet | ChatGPT connectors need OAuth; the endpoint takes personal access tokens today. |
The connection
- Endpoint
- https://account.ismscopilot.com/v1/account/mcp
- Transport
- HTTP MCP (Streamable HTTP)
- Auth
- Authorization: Bearer pat-isms-...
- Token
- chat.ismscopilot.com, Settings, Connected apps, Create token. Shown once; grant only the scopes the agent needs.
- Smoke test
- Ask your agent to list your ISMS Copilot workspaces.
Compliance answers you can trust, inside Claude Code, Cursor or Codex, without burning your Claude or ChatGPT plan
Delegated conversations ride your ISMS Copilot chat plan and its 4-hour UTC session window. There is no separate billing, no credits and no per-token meter for the MCP connection. The free plan connects too; Think mode needs a paid plan, and Beyond runs on paid plans under a daily run cap. If you exhaust your chat plan's 4-hour session window, the plan-limit error tells your agent when it resets, and read tools keep working. Your harness model still reads the answer it gets back, so the answer is not free for your Claude or ChatGPT plan: the drafting behind it is what stays on our side.
The cost comparator, with sources and dates →Sources and product truth
- Connect any MCP client
Token, endpoint, per-client notes, usage limits
- Connect Cursor and Codex
mcp.json and config.toml shapes, smoke test, rotation
- Tokens, scopes, and security
Least privilege, revoke, expiry, hard limits
- Why connect a specialist
Skill file vs maintained registry, with the benchmark's losses stated
- The agents product
Tools, scopes, limits and the honest not-list
- For GRC engineers
Account MCP vs the Model API, and the cost comparator
Frequently Asked Questions
Does this replace Claude, Cursor or Codex?
No. Your agent stays the harness: it keeps the code, the repository, the plan and the tool loop. ISMS Copilot is the GRC specialist it hands compliance questions to. Use both.
Does delegating save tokens in my harness?
By mechanism, the framework knowledge, workspace context and long drafting stay on ISMS Copilot's side, so they never enter your agent's transcript and are never re-sent on later turns. The answer that comes back does enter the transcript, so ask for brief answers when that is enough. We publish no savings figure until we have measured one with a reproducible method.
What does it cost?
Nothing on top of your ISMS Copilot chat plan. Delegated conversations count against the same 4-hour UTC session window as the web app, and there is no separate billing for the MCP connection.
Why can't I connect claude.ai, Claude Desktop connectors or ChatGPT?
Those connectors need OAuth. The ISMS Copilot endpoint accepts personal access tokens sent as a Bearer header today, which Claude Code, Cursor, Codex, OpenCode and Grok support.
What does ISMS Copilot see from my project?
From your project, only what your agent writes into the message: ISMS Copilot has no direct access to your repository, your filesystem or your harness's context. On its own side, the answer can also draw on the memories and pinned files of the ISMS Copilot workspace the conversation runs in. The conversation is stored in your ISMS Copilot account like any other chat.
What can the token do?
It acts as you, within the scopes you grant when you create it: for example reading workspaces and memories, or starting conversations. A read-only token cannot start conversations. Revoke it in Settings at any time; revocation takes effect immediately.
Give your agent a GRC specialist
One token, one MCP entry. Your agent keeps the code; the compliance work goes to the specialist.
