← All case studies

Case study 04 of 15

MCP Became a Governance Challenge

Teams wanted agents and AI coding tools to reach enterprise context through MCP-style integrations.

James Staud · Anonymized field pattern — details generalized to protect specifics

Business challenge

The business value was obvious. The security model wasn't — trust, access, logging, and tool-level permissions all needed answers before rollout.

Architecture approach

Registries, gateways, allowlists, and enforcement layers were evaluated as ways to give agents controlled access to real tools.

How the work moved from request to production

  1. Business need
  2. Intake & risk classification
  3. Select reusable pattern
  4. Build / configure
  5. Review & validate
  6. Deploy / enable
  7. Monitor usage, risk, cost, value

Feeds back into intake to improve the pattern or the governance around it

Governance considerations

Approval workflows, trusted server lists, prohibited tools, auditability, and periodic review turned MCP access from an open door into a managed one.

Results

The conversation matured from "enable this" to governed integration infrastructure with a real owner.

Lesson learned

MCP shouldn't be treated as a convenience setting. It should be treated like API infrastructure for agents.

Discussion questions

  • Who approves MCP servers?
  • Should approval happen at the server level or the tool level?
  • How should usage actually be audited?