
Anyone giving agents write access through MCP faces the same attribution and blast-radius problem this describes, and now has a named control model for it.
“The system records all those changes under Joe regardless of whether it was him or his agent, and the network logs do not distinguish one agent session from another.”
“At Cloudflare, we knew we could not depend on every employee to configure every agent perfectly or watch every tool call.”
“If Joe cannot close a particular issue, Joe’s agent cannot close it either.”
“Because an agent can repeat an action much faster than a person, we also needed central auditing across every MCP server.”
Checking sign-in…
Loading comments…