CROSS-CATEGORY: MCP Governance Shipped Simultaneously in DevTools, Infrastructure and Security in a Single Week
Three unrelated categories all shipped agent access-control primitives between August 6 and 11: GitHub added allowedMcpServers/deniedMcpServers keys to enterprise Copilot managed settings that fail closed on malformed config (Aug 6) plus a usage API reporting totals_by_3rd_party_agent for per-agent spend attribution (Aug 7); Nutanix shipped an open-source MCP server for Nutanix Cloud Platform built on the Prism v4 API gateway so agents inherit existing RBAC (Aug 10); and 15+ security vendors launched agent-infrastructure products at Black Hat USA within 48 hours. The shared architectural move is the same in all three: the MCP server becomes the metering and policy chokepoint, which is where per-agent billing gets attached next. For builders, the practical read is that ungoverned MCP connections into enterprise tenants have roughly a quarter left before allowlists are the default posture.
Source
↳ Follow the thread