Governing MCP Tool Permissions With RBAC
Control which MCP tools an agent can call, not just which servers.
Staff Writer, AI Security & Compliance
Linnea spent seven years as a cybersecurity analyst specializing in identity and access management before pivoting to technology journalism in 2018. Her reporting focuses on the intersection of regulatory frameworks and emerging AI deployment patterns, with particular depth on enterprise compliance failures.
14 stories
Control which MCP tools an agent can call, not just which servers.
MCP servers lack built-in security controls, creating cascading risks across enterprise tenants.
OAuth 2.1 and resource-bound tokens replaced MCP's trust-by-proximity model in just twenty months.
Least privilege for agents requires task-scoped roles and permissions that expire automatically.
SAML and OIDC weren't built for agents acting without humans.
Agents need identity systems built for nondeterministic, cloneable software, not humans.
Enterprises must map AI risks across shadow tools, data exposure, and agentic attacks.
Employees bypassing security to leak corporate data through unmonitored AI tools.
Agents multiply costs across six layers, but no dashboard reveals which team owes what.
Companies need technical controls, not policies.
Attackers now break in faster than SOCs can respond.
Agents need audit logs that capture reasoning, not just actions.
AI-generated code leaks secrets at roughly double the baseline rate.
EU AI Act deadlines force enterprises to formalize vendor governance now.