Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Claude, MCP, and agent tools: what does security need to govern?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15509
Topic starter  

TL;DR: The move into code, Cowork, skills, MCP servers, and agent workflows creates a security gap unless teams can inspect prompts, tool calls, and tool outputs before action is taken, according to Cato Networks. The governing assumption is shifting from session visibility to runtime control over what an agent can see, request, and do.

NHIMG editorial — based on content published by Cato Networks: How Cato AI Security Keeps Up With Claude

By the numbers:

  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.

Questions worth separating out

Q: How should security teams govern AI agents that use service accounts and MCP tools?

A: Start with ownership, then add runtime attribution and containment.

Q: Why do AI agents create a different risk model than chatbots?

A: AI agents can act, not just generate.

Q: What do security teams get wrong about MCP and tool governance?

A: They often review each integration in isolation and miss the combined permission path.

Practitioner guidance

  • Inventory agent tool chains as governed access paths Map every skill, MCP server, and connected tool an agent can invoke, then classify the resulting action path by data sensitivity and business impact.
  • Enforce policy before tool invocation Require runtime checks on the prompt, model output, tool input, and tool output so approval happens before the agent can execute an unsafe action.
  • Scope rollout to named users and devices first Start with tightly limited groups and verify that client identity, endpoint identity, and audit records all resolve to the correct actor before broad deployment.

What's in the full article

Cato Networks' full post covers the operational detail this post intentionally leaves for the source:

  • Specific deployment options for Claude Enterprise, Claude Code, and Claude Cowork in Cato's security stack
  • Workflow details for Cato Scout, including custom settings, plugin installation, and hook verification
  • Operational guidance for scoped rollout, attribution, and first-use protection across supported agents
  • Examples of how runtime policy is applied to prompts, responses, tool input, and tool output

👉 Read Cato Networks' analysis of AI security controls for Claude workflows →

Claude, MCP, and agent tools: what does security need to govern?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15094
 

Tool governance is now identity governance. When an AI system can call skills, MCP servers, and downstream tools, the security question moves from authentication to delegated capability control. The same actor can expose very different risk depending on which tools it can reach, so entitlement review must include the action surface, not just the login surface. Practitioners should treat agent tools as NHI-bearing privileges, not as optional app features.

A few things that frame the scale:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • Our research also found that lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, with inadequate monitoring and logging at 37%.

A question worth separating out:

Q: How do organisations know if agent security controls are actually working?

A: Look for evidence that the platform can inspect traces, classify risky actions, and stop unsafe tool use before completion. Effective controls leave an audit trail that shows why the action was allowed or denied, and they reduce false positives enough that teams can trust them in production.

👉 Read our full editorial: Claude security now depends on governing tools, skills, and MCP



   
ReplyQuote
Share: