the moat
Production & Governance
MCP servers that touch money, customers, or regulated data need more than a demo. This section turns operating discipline — approval, gateways, audit, threat modeling, cost control — into concrete patterns any team can apply. All examples generic, no vendor pitch.
Rolling out MCP in an organization: an approval and governance framework
A practical governance framework for MCP at work: server intake reviews, per-team allowlists, permission scoping, EMA-based SSO, audit trails, and a phased rollout ladder.
The MCP gateway pattern: one controlled door to every server
Why organizations put a gateway in front of MCP servers: auth termination, logging, allowlisting, rate limits, tool filtering — architectures, logging spec, and trade-offs.
A threat model for MCP deployments (defensive)
A structured risk register for MCP: tool poisoning, confused deputy, token passthrough, session hijacking, SSRF, supply chain, exfiltration, and prompt injection — with mitigations.
Controlling the token cost of MCP: measurement and design
MCP tool definitions consume context on every request. How to measure per-server overhead, design token-efficient tools, trim responses, and add observability hooks.
newsletter
One practical MCP guide in your inbox. No news, no hype.
Tutorials and decision frameworks as they ship. Unsubscribe anytime.