Security

Identities, tool and MCP permissions, threats and findings per AI system.

Northwind Mutual ⌄Console › Security › Tool and MCP permissionsSearch ⌘KProductionModelPolling

Tool and MCP permissions

What each agent can reach, and what needs a person first.

ExportReview access
Agents with external actions4of 9 governed
Privileged tool grants113 unused in 30 days
Service identities142 keys due for rotation
Open findings51 high

Access matrix

AllowedApproval
AgentPayments APIClaims DB (write)Email (external)Policy MCPWeb searchFile store
Claims triage agentApprovalAllowedNo accessAllowedNo accessAllowed
Broker email drafterNo accessNo accessApprovalAllowedAllowedAllowed
Customer reply assistantNo accessNo accessApprovalAllowedNo accessNo access
Underwriting risk summariserNo accessNo accessNo accessAllowedNo accessAllowed
Fraud signal modelNo accessAllowedNo accessNo accessNo accessAllowed

Findings

5 open
  • HighUnused write grant, Fraud signal model can write to Claims DB but has not in 30 days
  • MediumPrompt injection test, Broker email drafter followed an instruction in a supplier attachment
  • MediumKey rotation due, two service identities older than 90 days
  • LowNew MCP server, Policy MCP added by Legal, reviewed
Security, Tool and MCP permissions: what each agent can reach, and what needs a person first.

What Security covers

Identities and accessService identities and keys used by each agent, with owners and rotation dates.
Tool and MCP permissionsWhich agents can reach which tools and MCP servers, and which actions need approval.
ThreatsRisks catalogued against the OWASP Top 10 for LLM applications and MITRE ATLAS.
FindingsUnused grants, prompt injection test results and overdue rotations, each with an owner.

Least privilege, enforced

A permission marked Approval in the matrix is enforced by the gate: when the agent tries to use that tool, the request is routed to a person. No access means the action is blocked.

Last reviewed October 2026Suggest a change