Skip to content
MODEL CONTEXT PROTOCOLUPDATED 2026-09-29

Governing MCP tools in the enterprise

THE SHORT ANSWER

The Model Context Protocol (MCP) is an open standard for connecting AI applications to tools and data. It makes connecting easy; it does not decide who may use which tool. Enterprise MCP governance adds that missing layer: tool servers are certified before anyone can use them, assigned per company, re-checked when they change, and every call is authorised against the person the agent is working for.

What MCP is

MCP was introduced by Anthropic in November 2024 and has become the common way to give AI applications tools. A server exposes tools, resources and prompts; a client — an assistant, an IDE, an agent platform — discovers and calls them. One integration works with every MCP client, which is why adoption has been fast.

What can go wrong

  • Over-broad tools: a tool that can do far more than the task needs, used by everyone who can reach it.
  • Tool poisoning: instructions hidden in a tool’s description or its output that try to steer the model.
  • Silent change: a tool’s definition changes after it was reviewed.
  • Credential exposure: API keys placed where the model — and so a prompt injection — can see them.
  • Unexpected destinations: a tool that calls internal or unintended hosts.
  • No per-person authority: every user of the agent gets every tool.

Controls that work

  • Register servers in a catalogue and certify them before they can be assigned.
  • Re-certify on a schedule and when a definition changes.
  • Assign tools per company and department, not globally.
  • Authorise each call against the permissions of the person the agent acts for.
  • Resolve credentials at call time on the server side; never place them in the model’s context.
  • Treat everything a tool returns as untrusted data, never as instructions.
  • Validate outbound destinations and pin them to the checked address.
  • Record every call with its decision.
HOW A2A MATRIX DOES IT
  • An MCP hub where people and agents find, describe and plan with tools — answers filtered to what that person may do.
  • Certification before assignment and scheduled re-certification runs; assignment per company.
  • A tool gateway that authorises each call, resolves credentials from the company’s vault and pins outbound addresses.
  • The platform itself is reachable from MCP clients such as Claude, with every action filtered to the signed-in person.
What it works with
QUESTIONS

Asked often.
Answered plainly.

Is MCP secure?+

MCP defines how to connect, not who may do what. Its safety in an enterprise depends on the governance around it: certification, per-person authorisation, credential handling and records.

What is tool poisoning?+

Instructions hidden in a tool’s description or output that try to make the model do something else. The defence is to treat tool output as data and to authorise every action independently of the model.

Can different companies have different tools?+

Yes. Tools are assigned per company, and per department where needed.

Do agents ever see API keys?+

No. Keys are resolved by the gateway at call time from the company’s own vault and never enter the model’s context.