The MCP gives you the voice; the skill gives you the judgement
A brand-voice connector pipes your tone into every AI tool, but it can't judge when not to apply it. That judgement is policy — a layer you still own.
Wire a brand-voice connector into your AI tools and it'll do exactly what it promises: every headline, every product description, every support reply comes out sounding like you. Then someone asks the same tool to draft a legal disclaimer, and it does that in your voice too — warm, confident, forty per cent friendly — which is the last thing a disclaimer should be. Ask it to reply to a customer and it'll stylise the customer's own quoted words back at them. Hand it a factual correction and it'll soften the wording until the correction no longer quite corrects. The connector has no opinion about when to keep its hands off, because having an opinion was never its job.
That gap is the whole subject of this piece. In the brand-voice protocol problem I argued that a brand-voice MCP fixes distribution but not definition — that piping your tone into every tool is easy, and deciding what that tone should actually be is the hard part that stays with you. This is the next step down into the architecture. Once you've defined the voice and wired it everywhere, you hit a second problem the plumbing can't touch: knowing when to apply it, when not to, and what wins when “on-brand” collides with something that matters more.
The MCP gives you the voice. It doesn't give you the judgement about using it.
Two layers, and why you need both
It's worth being plain about what these two things are, because the terms get thrown around as if we'd all already agreed on them. An MCP, or connector, is really just a place your tools can look things up. A brand-voice one holds the answer to a single question: what's our tone, our glossary, the words we'd never be caught using? Your AI tool reads from it as it writes, and that's the whole of its job. What it can't do is tell that tool whether this particular thing should be in your voice at all.
A skill is the other half, and it's the half that keeps you out of trouble. Where the connector supplies the voice, the skill supplies the procedure for using it: when to apply it, when to hold back, and what to do when two rules collide. Anthropic frames the split neatly — connectors expose a capability, skills carry the know-how for using it. It made the skill format an open standard in late 2025, which tells you it's treated as a layer in its own right, not a footnote to the connector.
They're built to work together, each doing a job the other can't. You can have the best voice config in the world piped into every tool you own, and still get a legal disclaimer written like a birthday card, because nothing in the pipe was ever responsible for the decision.
What the judgement layer actually holds
So what does that judgement layer contain? At minimum, four things.
- Exclusions — the categories the voice must never touch: legal text, direct quotes, factual and system messages, anything regulated or safety-related, and code. A quoted customer should sound like the customer, not like your brand ventriloquising them.
- Precedence — what wins in a conflict. Accuracy and clarity beat tone, every time. Accessibility and a platform's required format beat style. “On-brand but wrong” is just wrong with better production values.
- Escalation — if the model isn't sure whether something's on-brand, or on-policy, it flags it for a human rather than guessing. The guess is where the birthday-card disclaimer comes from.
- Ownership and change control — who's allowed to change the rules, and how a change ripples out. A single glossary edit now reshapes output across every connected tool, so it's not a thing you want anyone quietly adjusting on a Tuesday.
None of that lives in the connector. The connector distributes the capability; the policy governs it; and underneath both, a human still had to decide what's being governed in the first place. That's three layers, not two: definition, then policy, then distribution. Solving the last one, which is what a brand-voice MCP does, never removed the need for the first two.

Who gets to write the policy
There's a live question hiding in here about who writes that policy. A vendor could ship a skill alongside its connector — tidy, convenient, one less thing for you to build. But then the vendor is writing your rules about accuracy, escalation and what your brand will and won't say, which sits awkwardly with the whole point of the last piece: that someone inside your business has to own the voice. Ownership doesn't feel like ownership if the operating rules arrived in the box.
The more defensible pattern is that you write your own policy and have it reference the connector. The tool distributes; you (the founder, the ops lead, whoever owns the brand) own the rules. It's the same conclusion I keep landing on: governance doesn't move just because distribution got solved. It's the same thinking behind deciding, deliberately, what each AI tool in your business is allowed to touch before you've got forty of them assembling themselves into a stack nobody chose.
Keep it in proportion
A word on scale, because it's easy to make this sound like it needs a platform and a project plan. For most small businesses, a formal “skill” is over-engineering. The policy can be a paragraph written into your system instructions: apply our voice except to these categories; accuracy always wins; flag anything you're unsure about. That's a policy. It does the job. The formal version earns its keep once you've got many tools and several people, where a paragraph in one place can no longer keep them all straight — and I'm not sure most businesses ever reach that point, or need to.
But the policy has to exist in some form. Skipping the formal skill is fine — plenty of small teams never need one. Skipping the judgement layer altogether, and trusting the connector to supply it, is the mistake. And it's worth the sanity check the last piece warned about: make sure there's a real, decided voice underneath, not a set of slider defaults being enforced with perfect fidelity. A policy that faithfully applies a voice nobody actually chose just industrialises the guesswork.
The half that's still yours
The pattern goes well beyond brand voice. Every connector you wire in, whether for your CRM, your calendar, your documents or your inbox, is a capability with no opinion about how it ought to be used. It'll do what it's asked, wherever it's asked, until you add the layer that decides when it should and when it shouldn't. The connector is the easy half, and it's mostly a bought thing now. The judgement about using it is the half that's still yours to write, and it's the half worth taking your time over.
