TechnologyOct 9, 202610 min read

Introducing Rubrik MCP: Bring Your Own Agent to Your Cyber Resilience Data


In cybersecurity, an AI assistant is only as useful as the context it can reach. If you ask an agent to investigate a ransomware event without access to your backup environment, the best it can do is recite generic advice.

But if you give it real-time visibility into snapshots, recovery points, event history, and anomaly signals, you can get real value.

Unfortunately, security teams building on AI need two things from an agent at once: direct access to protection data, and firm limits on what it can do with that access. Visibility without limits puts the backup environment itself at risk. Limits without visibility leave the agent reciting generic advice while the clock runs on an incident. 

But Rubrik MCP, now generally available, can deliver both without burdening IT with custom integration work for every agent and every use case.

 

Connect Any Agent to Rubrik Security Cloud

Today, getting quality intelligence to an AI agent is highly inefficient. An analyst has to paste job logs into a chat window to ask what changed overnight. A platform engineer copies SLA reports into a prompt to find out which workloads fell out of compliance. A developer building an internal incident workflow stitches together API calls by hand so an agent can see anything at all. Every copy and paste is time spent while the clock runs on an incident.

Model Context Protocol (MCP) is an open standard created by Anthropic and now widely adopted across the AI industry that lets an AI assistant connect to external systems. Instead of pasting data into a chat window, an MCP-enabled assistant reaches out, queries the system directly, and surfaces what it finds in the middle of a conversation. 

MCP servers already exist for code repositories, databases, observability platforms, and CRMs. The Rubrik MCP server brings that same pattern to Rubrik Security Cloud (RSC), connecting AI agents directly to the RSC API. The agent can be a coding assistant, a custom enterprise agent, or an internal workflow. Once connected, it can:

  • Enhance protection posture with query coverage across VMs, databases, and cloud resources

  • Access event history by retrieving backup job status and the record of recent activity

  • Support anomaly investigation by flagging unusual activity as it surfaces

  • Enforce SLA compliance through an understanding of where the environment meets its objectives and where it does not
     

Recovery depends on knowing the state of your data before an incident, not after. Rubrik MCP puts that state in front of the agent your team already trusts.

 

A Server That Discovers the API on its Own

Most MCP servers are thin wrappers around a fixed list of hardcoded operations. Rubrik MCP reads the Rubrik Security Cloud schema in real time instead. It exposes tools for schema discovery, and the agent uses them to explore which operations exist, read their arguments, and construct correct queries on its own.

The result is a gateway to the full Rubrik Security Cloud API. New Rubrik capabilities are reachable as soon as they become available.

 

Security Controls Set by Administrators, Not Agents

Giving an AI agent access to your backup environment demands a clear answer to one question: “What can it do?” 

Rubrik MCP answers it with a local policy file. Administrators define exactly what each agent may do. The policy layer sits on top of existing Rubrik Security Cloud role-based access control and adds a second, explicit check on agent behavior. The agent holds exactly the authority the administrator granted.

 

Read Operations by Default, Write Operations by Exception

Read operations run by default. A small set of write operations, including taking snapshots, assigning SLAs, and registering hosts, ships switched off. Administrators turn each one on individually, so every write capability stays closed until someone opens it deliberately.

 

Saved Workflows Any Approved Agent Can Run

Teams can combine multiple Rubrik Security Cloud API calls into a named workflow that works as a single reusable tool. Workflows live locally and appear in the agent's toolset automatically. A multi-step investigation your best analyst runs by hand becomes one callable action for any approved agent.

 

Rubrik MCP and Rubrik AI: Two Paths to the Same Data

Customers most often ask how Rubrik MCP differs from Rubrik AI. The two complement each other, and each fits a different way of working.

Rubrik AI is built into Rubrik Security Cloud. Once you open the console, you can enable it and it understands Rubrik data natively, surfacing insights inside the product experience. It suits customers who want AI capability out of the box.

Rubrik MCP allows you to bring your own agent. It serves teams building on AI who need protection and backup data inside their existing workflows. It connects your chosen tooling to Rubrik Security Cloud from the outside, with the same visibility into your protection environment.

Both talk to the same API and run side by side. Many customers will run both.

 

Availability and Getting Started

Rubrik MCP is generally available now. Visit the GitHub repository and the quickstart guide to get connected: GitHub repository and the quickstart guide.

This is the first post in a series. Next, we will cover how the adaptive architecture works, including schema discovery, query construction, and why it matters for API coverage. We will then go deep on the policy model, including the available controls, how to configure them, and how to think about agent trust in a security context. Finally, we will walk through real workflows end to end, showing what an AI conversation looks like when it has live access to RSC data.

 

Related Articles

Blogs by This Author