In the previous article, we explored Model Context Protocol (MCP) and how Spring AI applications can connect to external capabilities through MCP clients and servers.

Our architecture evolved from:

LLM
↓
RAG
↓
Tool Calling
↓
Memory
↓
Agents
↓
MCP

But there is a problem.

Building an agent that can perform actions is very different from building an agent that can perform those actions reliably and safely in production.

Imagine an agent that can:

Read customer data
Update CRM records
Create invoices
Send emails
Issue refunds
Call internal APIs
Execute MCP tools

The model may select the wrong tool.

It may provide invalid arguments.

It may retry a payment operation.

It may call a destructive tool without sufficient authorization.