TL;DR: MCP standardises how AI systems connect to tools and data, but the real shift is in identity and authorization: agents need delegated, scoped access, session continuity, and runtime policy checks, according to Cerbos. The practical lesson is that AI integrations fail or succeed on governance assumptions, not just protocol design.
Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “AI agents, the Model Context Protocol, and the future of authorization guardrails”.
Key questions
Q: What breaks when AI agents use MCP without strong scope enforcement?
A: Least privilege breaks in practice because the agent can execute far more than the business task requires.
Q: Why do MCP-based AI workflows need runtime authorization checks?
A: They need runtime checks because the right to call a tool can change as the session evolves, the task expands, or the risk of an action rises.
Q: How do security teams know if MCP access policies are too coarse?
A: If a single role or policy grants access to broad datasets or multiple tools when the task needs only one resource, the policy is too coarse.
Practitioner guidance
- Define task-scoped agent authority Map every MCP connection to a specific user intent, allowed resource set, and expiry condition so the agent cannot reuse authority outside the task it was given.
- Enforce per-action policy checks Evaluate each tool invocation at the MCP server boundary using contextual rules for identity, resource sensitivity, and action risk instead of relying on initial login approval.
- Require step-up for destructive actions Pause high-impact actions such as deletes, bulk updates, or privilege changes and require a human confirmation or re-authentication before execution continues.
Bottom line: MCP changes the control problem by moving AI integrations from static access to delegated runtime authorisation.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Blanket app tokens are the wrong mental model for AI agent access: MCP turns a one-shot integration into a delegated action chain, so the access question is no longer whether an app can connect, but what the agent can do at each step. The article shows why scopes, consent, and transaction limits need to be expressed per action, not per integration. Practitioners should treat every agent session as a bounded delegation event, not a durable entitlement.
A few things that frame the scale:
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: What frameworks should teams use to control MCP and agent access?
A: Teams should combine zero-trust authorization, NHI governance, and agent-risk guidance such as OWASP Agentic Applications Top 10. The practical test is whether each tool invocation is checked against identity, scope, and context before execution, with logs detailed enough to support review and incident investigation.
👉 Read our full editorial: MCP changes identity and authorization for AI agent workflows
Blanket app tokens are the wrong mental model for AI agent access: MCP turns a one-shot integration into a delegated action chain, so the access question is no longer whether an app can connect, but what the agent can do at each step. The article shows why scopes, consent, and transaction limits need to be expressed per action, not per integration. Practitioners should treat every agent session as a bounded delegation event, not a durable entitlement.
A few things that frame the scale:
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: What frameworks should teams use to control MCP and agent access?
A: Teams should combine zero-trust authorization, NHI governance, and agent-risk guidance such as OWASP Agentic Applications Top 10. The practical test is whether each tool invocation is checked against identity, scope, and context before execution, with logs detailed enough to support review and incident investigation.
👉 Read our full editorial: MCP changes identity and authorization for AI agent workflows
Runtime authorization, not protocol adoption, is the real MCP question: MCP standardises how AI agents reach tools, but it does not by itself solve who may do what, when, and under which user context. The security boundary has moved from integration plumbing to per-action policy enforcement, and that is where IAM teams now carry the risk. The practical conclusion is that MCP success depends on authorization architecture, not connector count.
A few things that frame the scale:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should teams govern AI agents that use MCP?
A: Treat each connected agent as a non-human identity with an owner, a scope, and a review cycle. The practical control set is familiar: least privilege, secret rotation, access expiration, and auditability across the systems the agent can reach.
👉 Read our full editorial: MCP changes identity and authorization for AI agent workflows