Detect material changes to an approved MCP tool boundary, hold the next gateway-mediated call to that tool before it is forwarded upstream, and verify the recorded evidence.
An MCP tool may be approved with a specific capability, externality, permission boundary, and expected behavior. Later, its schema, underlying API, authorization behavior, deployment, or effective capability may change. Static allowlists and one-time approval do not prove that the same runtime boundary still exists.
Interlock sits in the call path, compares every later call against the boundary an operator approved, and records what it decided.
The operational console keeps the drift review queue available: the approved baseline, the approved-versus-current boundary diff, the quarantine decision, what happens to later calls to that tool, and the receipt — with approve, reject, or rebaseline one action away.
In the default journey the change is a declared one: the re-discovered tool surface no longer matches the approved boundary, and the diff is the evidence.
Some drift never reaches the manifest: the schema is identical, but the upstream authorization quietly loosens. Interlock cannot diff its way to that. It has to see a response.
You don't need a call to see it work. The proof runs on your machine, against a clearly labelled fixture.
Stated plainly, on the page — not in a footer or a tooltip.
Interlock is seeking technical conversations and controlled non-production evaluations with teams operating meaningful MCP tool boundaries.