Solutions · MCP and tool governance

MCP sprawl is not a discovery problem.

Finding them is the easy half, and most tools stop there. Backplanes turns the inventory into a decision: which servers, tools and skills your agents may use, enforced where they run.

MCP servers, tools, skills, plugins, domains and commands

Proposed controlDraft

Backplanes proposes

block: file-transfer.external
WhyDrafted from this week. An MCP server nobody has approved was reached by 2 people.
If liveLast 30 days: 3 sessions blocked. Nothing else affected.
DecisionApprove as rev 5Monitor first

The easy half

An MCP server installs in seconds from a config file, with nobody asked. By the time security hears about it, it is already in production work. Scanning tells you they are there. It does not tell you whether they should be.

Start by knowing

The first controls are drawn from what is already there.

Backplanes does not ask you to imagine which servers your organization needs. It starts from the ones your agents already use, across Claude Code, Codex and Cursor.

Every MCP server your agents connected to, and whether anyone has signed off on it.

External access

90-day observed window · generated now · MCP servers, organization-wide

External domains
47
MCP servers
12
MCP tools
31
Skills
9
Needs review
3
All 99MCP servers 12MCP tools 31Skills 9Plugins 4External domains 47Needs review 3Blocked 1
ResourceKindStatusSessionsCallsReached byLast
githubmcp_server:githubMCP serverSanctioned382,140team9m
web-searchmcp_server:web-searchMCP serverSanctioned221,2046 engineers1h
filesystemmcp_server:filesystemMCP serverSanctioned186425 engineers3h
issue-trackermcp_server:issue-trackerMCP serverSanctioned14380alex, maya2h
file-transfer.externalmcp_server · not in the reviewed setMCP serverNeeds review361sam, maya2d
playwrightmcp_server:playwright · first seen this weekMCP serverUnreviewed495maya4h
A Backplanes session report: verdict, time breakdown, findings, and the session story

And underneath

Every number has an audit trail.

A verdict, the findings worth acting on, and the full story of each run.

See the full report
Org report, Security view: top risks and a severity-triaged findings table

And above

Rolled up for the org.

Every session across your org, triaged by severity. No new instrumentation.

Explore org reports

What it answers for you

Inventory, decision, enforcement.

Q1

What is installed, across everyone?

Every server, tool, Skill, plugin and domain your agents reached, built from the sessions they already produce. Each row names who brought it in.

Q2

What may be used, and at what granularity?

Per resource kind, each with its own default for anything unlisted. That one setting decides allowlist or watchlist.

Q3

How does it apply on a machine I do not manage?

The rules travel as a signed document the engine verifies and evaluates locally. A catalog outage cannot stop a decision.

The review queue

Anything new arrives undecided.

Nothing nobody has ruled on is quietly allowed. It lands as unreviewed, and you work through the queue.

  • Flagged the first time it is reached.
  • Sanction or block from the row.
  • Queue length tells you how stale your controls are.

Filter · needs review & blocked

api.example-vendor.comDomainNeeds review47
browser_navigateMCP toolUnreviewed260
unknown-cdn.ioDomainBlocked2
I spend half my time just struggling to understand our subprocessor chain. What does Slack use? What did they add while I wasn’t looking?

Security Engineer

What it does not do

What approving an MCP server does not mean.

The part a security engineer will test first.

An MCP server name is not a verified identity.
Approving web-search approves a string a config file claims is web-search. That is vendor management, not attestation, and we would rather say so than let you assume otherwise.
Real verification exists, and only for plugin builds.
Builds are checked against catalog digests per harness profile, all builds rather than any build. One modified copy beside an official one fails the check.
Cannot verify is never banned.
With no inventory entry or no comparable digest, the result is unverifiable: under every mode including block, the call is allowed and flagged. A control that fails closed on its own blind spots gets switched off.

This list is maintained, not decorative. If something here is wrong or out of date, tell us.

Next

Start with the inventory. Decide from there.

See what your agents reached, then tell us which of it should have been allowed.