Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

MCP and agentic AI governance: what identity teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15984
Topic starter  

TL;DR: Agentic AI and Model Context Protocol are expanding enterprise access faster than security teams can govern it, with Unosecur arguing that persistent credentials, weak rotation, and limited auditability are now the dominant MCP pattern. Static IAM models are failing because MCP turns non-human identity into a live execution layer, not just a tooling layer.

NHIMG editorial — based on content published by Unosecur: The New Frontier of Identity Security: Governing Agentic AI and MCP with Unosecur

By the numbers:

Questions worth separating out

Q: How should security teams govern MCP-enabled AI assistants that can act on tools and data?

A: Treat MCP-enabled assistants as non-human identities with scoped authority, not as passive interfaces.

Q: Why do MCP environments create more identity risk than standard API integrations?

A: MCP environments increase identity risk because they add tool discovery, delegated access, and multiple authentication paths on top of existing APIs.

Q: What do security teams get wrong about least privilege for agentic systems?

A: They often scope access as if the agent’s purpose is fixed at provisioning time.

Practitioner guidance

  • Inventory every MCP server and AI client Build a complete register of MCP endpoints, the credentials they use, the tools they expose, and the data sources they can reach.
  • Replace persistent secrets with short-lived access Move MCP access toward short-lived tokens, task-scoped permissions, and explicit revocation paths.
  • Separate read and write authority for agent workflows Define distinct permissions for data retrieval, system modification, and external transmission.

What's in the full article

Unosecur's full blog covers the operational detail this post intentionally leaves for the source:

  • A step-by-step description of the secure MCP Gateway architecture and how it handles authentication and authorization.
  • Operational examples of session and token tracking across MCP traffic, including the telemetry teams would need for investigations.
  • The specific policy manager and JIT control flows used to enforce task-based access in agentic workflows.
  • The article’s mapping of these controls to OWASP Agentic Threat Model concerns such as tool misuse and privilege compromise.

👉 Read Unosecur's analysis of agentic AI governance and secure MCP access →

MCP and agentic AI governance: what identity teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15569
 

MCP is now an identity expansion event, not an integration detail. Once an AI system can choose tools, call APIs, and act on live data, the security problem moves from application connectivity to identity governance. That means security teams must classify MCP servers and AI clients as governed non-human identities, not as passive middleware. The practical conclusion is that identity architecture, not model capability, becomes the control plane.

A few things that frame the scale:

  • 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: How do compliance teams prove what an AI agent accessed through MCP?

A: They need session logs that connect authentication, token use, tool calls, and resulting actions into one audit trail. If each tool logs in isolation, you lose chain of custody and cannot reconstruct the agent’s behaviour with confidence. That creates a gap for incident response, audit, and regulated reporting.

👉 Read our full editorial: Agentic AI and MCP governance exposes a new identity security gap



   
ReplyQuote
Share: