TL;DR: MCP elicitation adds a standard way for servers to request missing context during a live session, but the article also says it must not be used for sensitive information and clients need approval, schema validation, clear server identity, and rate limiting, according to WorkOS. The governance issue is no longer whether models can ask more questions, but which runtime trust assumptions remain safe when context negotiation becomes part of execution.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “MCP elicitation: Request user input at runtime”.
Key questions
Q: What breaks when runtime context requests are allowed without clear boundaries?
A: The session boundary breaks first.
Q: Why do runtime context prompts need schema validation in AI systems?
A: Because the prompt is not the control point, the accepted value is.
Q: How should teams handle sensitive data that a live AI workflow wants to collect?
A: They should keep it out of elicitation entirely and route it through a separate secure flow.
Practitioner guidance
- Define runtime context boundaries List which context fields your MCP clients may expose during a live session and which inputs must never be requested through elicitation, especially sensitive or identity-linked data.
- Enforce schema-first validation Validate every elicitation response against the requested JSON schema before the value is used in branching logic, tool calls, or downstream state changes.
- Show requesting server identity Display the server name or source of the elicitation request so users can distinguish legitimate context requests from cross-server or cross-agent confusion.
Bottom line: MCP elicitation moves context collection into the live execution path, which makes it an identity governance issue as well as an interaction design feature.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Runtime elicitation creates a new identity control surface inside execution. The article is not really about asking more questions. It is about moving context resolution into the live session, where the control is now part of the workflow rather than a setup step. That matters because identity governance usually assumes the access context is established before execution begins. Practitioners should treat elicitation as an authorization-adjacent event, not a UX convenience.
A few things that frame the scale:
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: What should teams do when multiple servers or agents can issue context requests?
A: They should make the requesting identity visible to the user and to the audit trail, then define rejection handling and fallback behaviour before deployment. In a multi-server environment, accountability depends on knowing who asked for the data, why it was requested, and what the system does if the request is refused.
👉 Read our full editorial: MCP elicitation shifts runtime context into AI identity governance