MCP servers expose tools, resources, and prompts to AI agents via a flat discovery list with no native scoping. In shared production environments, this creates over-permissioned agents, credential sprawl, and missing audit trails. The post outlines a two-level provisioning model: organization-level controls set the ceiling
Table of contents
What MCP servers actually expose to agentsWhy unrestricted tool access breaks in productionThe two levels of tool provisioning in MCP serversCredential management and authentication at the tool layerPolicy enforcement, rate limits, and auditability across tool invocationsHow Portkey's MCP gateway handles tool provisioning at scaleGovern your MCPsFAQsSort: