### Featured Stories

- **[Announcing Permit MCP Gateway](/content/blog/announcing-permit-mcp-gateway/index.html)**  
  **Author:** Or Weis  
  **Date:** Mar 17 2026  
  Announcing Permit MCP Gateway, a new trust and enforcement layer for MCP that brings identity, consent, fine-grained authorization, auditability, and runtime control to AI agent actions.

- **[Introducing the New Permit.io CLI: A New Era of Access Control Developer Experience](/content/blog/introducing-the-new-permit-cli/index.html)**  
  **Author:** Gabriel L. Manor  
  **Date:** Apr 21 2025  
  The new Permit.io CLI brings developer-first workflows to access control. Define, test, deploy, and enforce fine-grained authorization using AI, CI/CD, GitOps, and OpenAPI — all from your terminal.

### All Stories

- **[How to Govern AI Agents Operating Cloud and API Control Planes Through MCP](/content/blog/govern-ai-agents-cloud-api-control-planes-mcp/index.html)**  
  **Author:** Or Weis  
  **Date:** Aug 11 2026  
  MCP servers are now operational control surfaces for cloud and API platforms. This article explains the trust model, control stack, and audit architecture enterprises need before AI agents can safely execute infrastructure actions.

- **[Shared Agent Memory Is a Permissions Problem](/content/blog/shared-agent-memory-is-a-permissions-problem/index.html)**  
  **Author:** Ziv Cohen  
  **Date:** Aug 04 2026  
  Shared coding-agent memory over MCP improves velocity, but every retrieval is a delegated access decision. This guide explains runtime authorization, ReBAC modeling, inheritance boundaries, revocation, and audit design for secure team memory.

- **[MCP Auth vs Tool-Call Authorization After the 2026-07-28 Spec](/content/blog/mcp-auth-vs-tool-call-authorization-2026-07-28/index.html)**  
  **Author:** Or Weis  
  **Date:** Jul 29 2026  
  The MCP 2026-07-28 spec hardened authentication and routing, but OAuth alone still cannot decide whether a specific tool call should run. This guide explains the authn-vs-authz split and shows how to enforce runtime policy on tools/call.

- **[Read-Only Is a Trust Level, Not a Feeling: How to Govern AI Ops Agents Before They Remediate Production](/content/blog/read-only-trust-level-ai-ops-agents/index.html)**  
  **Author:** Gabriel L. Manor  
  **Date:** Jul 28 2026  
  AI incident-response agents should not inherit remediation authority by default. This guide defines a practical trust-level taxonomy for MCP tool calls, shows where policy step-up approvals are required, and explains what enterprise audit trails must capture before any production mutation.

- **[Agent-Generated APIs Need Governance Before They Become Agent-Callable Tools](/content/blog/agent-generated-apis-governance-before-mcp-tools/index.html)**  
  **Author:** Gabriel L. Manor  
  **Date:** Jul 22 2026  
  Coding agents can generate OpenAPI specs faster than most governance programs can review them. This article explains how to connect design-time API governance to runtime MCP tool authorization with policy decisions, constrained credentials, and audit receipts.

- **[Can AI Generate Authorization Policy Safely?](/content/blog/can-ai-generate-authorization-policy-safely/index.html)**  
  **Author:** Gabriel L. Manor  
  **Date:** Jul 08 2026  
  LLMs can draft authorization policy, but safe policy authoring for AI agents still depends on explicit intent, verifier-guided synthesis, and runtime PDP decisions on real tool calls.

- **[MCP Auth Bypasses Show Why Tool Calls Need Runtime Authorization](/content/blog/mcp-auth-bypasses-tool-call-runtime-authorization/index.html)**  
  **Author:** Ziv Cohen  
  **Date:** Jul 07 2026  
  The fast-mcp-telegram and LiteLLM CVE chains show that authentication failures rapidly become unauthorized tool execution. The fix is fail-closed, runtime tool-call authorization at the MCP boundary.

- **[Payment Is Not Permission: How to Authorize Paid MCP Tool Calls](/content/blog/payment-is-not-permission-authorize-paid-mcp-tool-calls/index.html)**  
  **Author:** Gabriel L. Manor  
  **Date:** Jul 05 2026  
  Cloudflare's x402 and paid MCP tooling make agentic payments real, but payment proof is not runtime permission. This guide explains spend authorization, consent tiers, and audit requirements for paid tool calls.

- **[MCP in ERP: Why Agentic Business Workflows Need Runtime Authorization](/content/blog/mcp-in-erp-runtime-authorization/index.html)**  
  **Author:** Or Weis  
  **Date:** Jul 01 2026  
  MCP is making agentic ERP integration easier, but security now depends on runtime authorization at the tool-call layer. Learn how to model scoped permissions, trust levels, and audit evidence for finance, HR, procurement, and payroll workflows.

- **[MCP Server Supply Chain Is Runtime Supply Chain: Tool Manifests Need Policy and Evidence](/content/blog/mcp-server-supply-chain-is-runtime-supply-chain/index.html)**  
  **Author:** Or Weis  
  **Date:** Jun 30 2026  
  MCP risk is not frozen at build time. This article explains how to vet third-party MCP servers, treat manifests as security boundaries, enforce runtime authorization, and preserve incident-grade audit evidence.

- **[CVE-2026-49257: Why MCP Database Servers Need Fail-Closed Authorization](/content/blog/cve-2026-49257-mcp-database-fail-closed-authorization/index.html)**  
  **Author:** Or Weis  
  **Date:** Jun 29 2026  
  CVE-2026-49257 in mcp-pinot shows why network-reachable MCP database servers must fail closed: secure startup, endpoint authentication, and per-tool runtime authorization are all mandatory. This guide breaks down the confused-deputy pattern, risk-tiered tool policy for read vs schema/admin operations, and the audit model needed for real incident forensics.

- **[Zero Standing Permissions for Coding and Automation Agents](/content/blog/zero-standing-permissions-coding-automation-agents/index.html)**  
  **Author:** Or Weis  
  **Date:** Jun 28 2026  
  Specs and PRDs make coding agents more accurate, but not inherently safe. This guide explains how to secure MCP-enabled coding and workflow agents with short-lived delegated access, runtime policy decisions, and auditable zero standing permissions.
