Browser surface
Registers, refreshes and removes WebMCP tools on the live page.
BubbleSurface lets a cybersecurity product expose the right agent capabilities at the right moment—while keeping sensitive actions under human and server-side control.
inspect_incidentget_active_sessionsreview_evidence_timeline remove_approved_privilegeSensitive capabilities remain unavailable until state and approval allow them.
The control layer
Registers, refreshes and removes WebMCP tools on the live page.
Reloads authoritative state and revalidates permissions, versions, approvals and applicability.
Keeps consequential actions gated behind explicit review and approval.
One shared workflow
Both act against the same live page, state and workflow.
A dynamic surface
Investigate → Propose → Approve → Execute → Verify
Security application loads BubbleSurface
BubbleSurface derives current WebMCP capabilities
Agent discovers investigation tools
Agent investigates and prepares a consequential action
Human reviews the exact proposal
BubbleSurface exposes the exact approved execution capability
Agent executes; the server revalidates authority
Execution disappears, verification appears, and the result is verified
The governed workflow in motion
Watch an external agent investigate, request a sensitive action, wait for human approval, execute through the newly exposed capability, and verify the result.