Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

MCP tunnels and enterprise access control: what changes now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: Anthropic MCP Tunnels invert the traditional network exposure model by letting internal systems reach out to Claude, while Stacklok adds the policy, segmentation, and orchestration layer needed to make MCP usable in production. The real issue is not connectivity but governance: tool scope, identity controls, and observability must move with the tunnel, or AI access simply recreates old risk in a new path.

NHIMG editorial — based on content published by Stacklok: Stacklok and Anthropic MCP Tunnels securely connect Claude to everything behind your firewall

By the numbers:

Questions worth separating out

Q: How should security teams govern managed MCP access for AI clients?

A: Security teams should treat managed MCP as a federated resource server and issue identity-bound tokens for each delegated task.

Q: Why do MCP tunnels still require IAM and NHI controls?

A: MCP tunnels solve the connectivity problem, but they do not decide who can reach which tools or how long that access should remain valid.

Q: What breaks when AI platform access is managed like ordinary user access?

A: What breaks is the assumption that access is stable, human-owned, and easy to review in a later cycle.

Practitioner guidance

  • Define MCP server ownership and approval boundaries Assign every MCP server to a named system owner, then require approval for any new tool exposure, group membership change, or external AI surface connection.
  • Segment tool access by role and purpose Use group-based segmentation to ensure engineering, marketing, and shared AI users see only the MCP tools required for their function.
  • Review tunnel access as a privileged pathway Treat the tunnel endpoint as a privileged access route and apply the same scrutiny you would use for service accounts, delegated admin paths, and other NHI entry points.

What's in the full article

Stacklok's full blog post covers the operational detail this post intentionally leaves for the source:

  • Exact deployment flow for the tunnel endpoint, including Docker Compose and Helm-based setup
  • How Stacklok's virtual MCP server model segments tools by group and maps to identity policy
  • Details on how Anthropic's Toolbox client handles MCP calls across Claude surfaces
  • Production considerations for moving from local experiments to monitored Kubernetes deployments

👉 Read Stacklok's blog post on Anthropic MCP Tunnels and enterprise tool access →

MCP tunnels and enterprise access control: what changes now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
Share: