Agent Security
Who decides which MCP tools an agent is allowed to call?

The decision should be owned by the organization, usually through platform, security, and application teams working together. Developers may request tool access, but production policy should define which agents can call which MCP tools, under what conditions, and with what audit trail. For sensitive tools, the CISO or security team may require approval before access is granted. A strong platform should make these policies enforceable rather than leaving them inside scattered application code. Diagrid Catalyst is positioned to support this governance layer through identity, policy, and audit controls around agents and MCP servers.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Agent Security
How should an enterprise prove which AI agent initiated an action?
An enterprise should prove which AI agent initiated an action by assigning the agent a verifiable workload identity and recording the execution path.
- Agent Security
Why is workload identity different from a user account for an agent?
Workload identity identifies software, services, agents, or tools, while a user account identifies a person.
- Agent Security
Where is cryptographic identity useful in agent-to-tool calls?
Cryptographic identity is useful when an agent must prove its identity to a tool or service before access is granted.