Dev puts policy enforcement in front of MCP tool calls, asks if wrong layer

Exotic-Border-5328 · reddit · 2026-10-02

A solo engineering student presents an MCP security gateway that sits between an agent and write-capable MCP servers. Before each tool call it evaluates a policy and returns allow, deny, or require-approval, with a shadow mode that only logs what would be blocked. Every decision is signed and timestamped for independent verification.

The design assumes policy enforcement belongs outside both the model and the MCP server so neither sets its own permissions—at the cost of an extra component in the execution path. He asks where developers enforce authorization today, whether they'd accept a gateway in that path, whether plain logs suffice, and whether they ever need to prove which policy was in force for a specific call. Limitations: only covers routed traffic, no customer deployments yet.

Original post →

More from coding & agent

coding & agent channel →