Discovery sweeps managed endpoints for MCP client configurations and running servers — Claude Desktop, IDE extensions, agent frameworks — and code repositories for server manifests and the credentials that sit beside them. The first inventory is usually the deliverable that reorganizes the roadmap: servers nobody registered, holding production access nobody scoped.
Inventories decay; controls do not. Per-agent server allowlists, argument-level tool-call policy, and approval gates on destructive operations mean a prompt-injected instruction to read a credential store is stopped as an action — not discovered in a postmortem. Aligned with the hardening direction of the NSA’s 2026 MCP guidance and the current MCP specification’s authorization model.
Every MCP interaction lands in the audit trail attributed to a specific agent identity — which server, which tool, what arguments, what verdict. When someone asks what your agents actually did last quarter, the answer is a query, not an investigation.
Briefly. MCP is now how developer tools expect to reach context — prohibition pushes usage onto unmanaged devices, the same failure mode as banning chatbots. Allowlist and inspect preserves the productivity with the control.
Enforcement lives on the device, not the wire. Device-level discovery reads the configurations and processes themselves, which is the only vantage point that covers stdio servers.
Yes — inspection operates at the tool-call layer, so spec revisions to transport and authorization strengthen rather than break the model. We track the specification as it evolves.
A discovery sweep. Counting your servers and the plaintext credentials sitting next to them takes days and settles the urgency question with your own numbers — it is one of the first findings our 72-hour pilot surfaces.