Automated Policy Generation just got its MCP debut
Say hello to Making Compliance Programmatic. See what I did there?
With the new generatePolicy MCP tool, you can now generate policy content directly through MCP using the same Vanta agent intelligence; so the output is consistent with what you'd get in the platform, no separate implementation needed. Once generated, just create a custom policy container in Vanta and upload the doc.
![]()
Jacob G. How do I try it out?
hey Esmeralda O. forgive me for not making that clearer! Thank you for the follow up. to begin, has your team connected to Vanta's MCP server? that will need to be done first, followed by authentication (admins have the ability to set up mcp). Then once connected, generatePolicy becomes available as a callable tool. Here are direct instructions for connecting to Vanta MCP; do you know if your team was already connected? Or do they need to set that up?
hey Glenn G.! great question. not quite yet; generatePolicy is focused on creating policy content rather than analyzing gaps. but I like the way youre thinking about this because the team is building for that eventually. no timeline yet that I can see, but will keep you (and the Community) up to speed as I learn more! ![]()
hey Jacob G. I created a policy with Claude desktop and tried to upload it with generatePolicy and got this message. There's also an uploadPolicy tool, but seems like that doesn't let me create a net new policy, just replace another existing one. Sorry if me or my Claude are missing something, but might be worth clarifying or updating the tool capabilities to provide more flexibility for people
hey Rob G. sorry about this, thanks for calling this out. you're right. generatePolicy produces the content but doesn't save it to Vanta, and uploadPolicy only works against an existing policy container, so it won't create a new one from scratch.
my original post said "end-to-end" which set the wrong expectation, sorry again for this. The MCP value here is the content generation, not the full save-to-Vanta workflow. I've updated the language accordingly.
lmk if this helps clarify; if not, ill dig in further with the PM ![]()
