Three tools, not thirty-four.
MCP servers expose everything; an agent needs a fraction. Grant tools per team, project or user — or compose a virtual MCP from exactly the tools a job needs, with approvals on the calls that matter.




The right tools, for the right agent.
Scope by team, project, user
Every tool is granted to exactly who needs it — nothing more, nothing standing.
Compose virtual MCPs
Bundle tools across servers into one virtual MCP built for a single job, and reuse it.
Human-in-the-loop
Send the risky calls to a person — Slack, email or a strong-auth tap — before they run.
“We already gate MCP access.”
Server auth answers who connected, not which tool this agent may call for this job. TapPass permissions individual tools per agent, holds the risky ones for a person, and records every call — across every MCP server, from one place.
Templates and observe-then-propose do the heavy lifting: watch real traffic first, then TapPass drafts the least-privilege grant. Teams get exactly what they use, without a ticket queue.
Keep reading
What the MCP Boundary Actually Exposes
An MCP server is a privilege boundary. Three things cross it, not one.
Give Your Agents Less. On Purpose.
Everyone races to give AI agents more power.
AI Agent Security Is Not LLM Security
Agents call tools, chain actions, and make decisions.
Sandboxing AI Agents: Why Isolation Alone Is Not Enough
Kernel sandboxes like Landlock and Seatbelt can lock down an AI agent process.