As AI agents increasingly use MCP servers to access tools, data, and external services, it may become difficult for users to understand and control the authority delegated to those agents.
For example, if an agent is authorized to perform an action through an MCP server, how can the user clearly determine:
- Which agent is actually acting?
- On whose behalf is it acting?
- What permissions were originally granted?
- What actions is the agent currently authorized to perform?
- Can those permissions be delegated to another agent or MCP server?
- Can the user trace the chain of authorization when multiple agents are involved?
- How can the user revoke or limit that authority consistently across different agents and MCP servers?
This becomes more important as users begin working with multiple agents from different providers and allow them to interact with increasingly sensitive tools and services.
I would be interested to know whether this is already considered a problem within the MCP ecosystem, and how others are currently addressing it.
As AI agents increasingly use MCP servers to access tools, data, and external services, it may become difficult for users to understand and control the authority delegated to those agents.
For example, if an agent is authorized to perform an action through an MCP server, how can the user clearly determine:
This becomes more important as users begin working with multiple agents from different providers and allow them to interact with increasingly sensitive tools and services.
I would be interested to know whether this is already considered a problem within the MCP ecosystem, and how others are currently addressing it.