Frequently asked questions
Straight answers to the questions people ask about MCP, how it applies to IT infrastructure, why direct agentic AI infrastructure access doesn't work, and what OneIQ Infrastructure Context Gateway actually does.
What MCP is, and why it matters for infrastructure specifically.
The Model Context Protocol is the open standard AI models use to query external systems for real information instead of guessing. Anthropic created it, but OpenAI, Google, and Microsoft all ship native support now - it's become the common language between AI agents and the tools they need to reach.
A context collector that senses telemetry across your estate and sends it to OneIQ Infrastructure Context Gateway (ICG) - continuously, agentlessly, keeping a live 7-day rolling window that ICG draws on to answer AI queries, 24×7×365. It's included at no charge with every assessment, so ICG always has fresh context to work from rather than a stale snapshot. Collection spans whatever makes up the estate - virtual, HCI, cloud, or bare metal - with nothing installed on target systems.
Because infrastructure telemetry wasn't built to be read by AI. It's fragmented across hybrid platforms, often on legacy gear with no API, and raw on its own. An MCP gateway can't just be a regular gateway by itself - it must provide context by normalizing and scoping that data into something an AI agent can safely and usefully query.
You can, and it looks fine in a demo. In production it fails because platform credentials are almost never scoped narrowly enough - the agent gets ungoverned access to everything, not just the one fact it's asking about. That turns into overreaching queries, credential sprawl, and a security team that (correctly) won't sign off.
No. A prompt instruction is a request, not an enforcement mechanism - it can be ignored, worked around, or simply fail silently. OneIQ ICG enforces scope at the gateway level, deterministically, in product logic. The boundary holds even if the agent misbehaves.
What actually changes once the gateway is in place.
Raw telemetry means nothing on its own - a CPU spike could be a critical billing server or a forgotten test box, and the agent has no way to tell. Worse, it's expensive: an agent hunting through raw data for one answer burns roughly 38,000 tokens, versus about 600 for the same answer pre-shaped by the gateway.
No. It sits alongside them, reading the signals they already expose. It doesn't replace your hypervisor management, monitoring stack, or cloud consoles - it's an additional, governed layer between your infrastructure and whichever AI you choose to use.
Collection is agentless and read-only, and the AI holds its own gateway credentials - production credentials are never exposed. Anonymous Agent Zones can also strip identifying details like IPs and hostnames before anything is shared with an external model.
A specifically governed slice of your estate - a single workload, one cluster, or a migration wave. Its boundaries are hard and enforced at the gateway, not by asking an LLM politely, so an agent's blast radius is confined to that zone even if it goes rogue.
No - beyond security and privacy, Agent Zones give you the benefit of isolating exactly the slice of infrastructure you want a query to run against. Examples: a capacity-planning zone covering only production clusters, a patch-risk zone scoped to just the Linux fleet, a cost zone covering only cloud + on-prem workloads flagged for right-sizing, or a migration-wave zone limited to the hardware in that specific wave. Each zone becomes a focused lens - the agent reasons only over the slice relevant to the question, not the whole estate.
Its blast radius hits a wall at the zone boundary - it's strictly confined to that single isolated slice, never the whole estate. Every request also passes through one gateway choke point, so you get a centralized audit trail: exactly what was asked, what was returned, and what scope was touched.
The part of OneIQ ICG that does the heavy lifting inside the gateway itself. When an agent asks a natural-language question, the engine resolves it against your already-modeled, already-enriched estate and hands back compact, structured facts - instead of making the AI burn tokens parsing raw data or API documentation to find the answer itself.
Because raw telemetry on its own is just a list of what you own - it can't tell you what's three generations out of date, what your power bill implies, or what a cloud alternative would cost. OneIQ joins that telemetry with real-world context so the answer is decision-ready, not another spreadsheet to interpret.
Continuously updated libraries covering real-time cloud pricing, currency exchange rates, hardware age, software support lifecycles, and power consumption data - joined automatically with your own telemetry so the gateway can answer things like "is this out of warranty" or "is this costing a fortune in power" without an open web search.
What day one actually looks like.
Because your estate is already modelled and enriched by the gateway, prebuilt universal agents turn on immediately: a renewal and license watchdog, a lifecycle and end-of-life tracker, a waste and right-sizing analyst, and an open-ended ask-your-infrastructure agent - each backed by a prebuilt dashboard.
Collection can begin immediately, normalization and enrichment run within minutes, and scoping your first zone in the UI typically means a live, governed Agent Zone in under 30 minutes - no advanced AI engineering team or capital hardware budget required.
What changes once other AI systems get involved.
Yes - that's the "my AI talks to your AI" model. As vendors and partners expose their own governed AI interfaces, an external AI can safely reason over exactly the anonymized context you choose to share, and nothing more, to do things like coordinate a migration or answer an RFP - without either side exposing raw infrastructure.
Without a gateway, yes - that would be a real risk. With OneIQ ICG, the external AI only ever sees the specific anonymized Agent Zone you've defined, enforced the same way internal access is enforced. The rails are already laid; you're not opening a new door for every partner.
Still have questions
Pick any environment - virtual, HCI, physical, cloud, or a mix. We'll deploy a governed Agent Zone and show you exactly what an AI sees. No prep, no project, no commitment.