Skip to content

feat: per-org MCP server governance policies #737

@imran-siddique

Description

@imran-siddique

Summary

MCP server allow/block exists in marketplace_policy.py and the MCP proxy has enterprise policies, but there is no org-level scoping. Policies are global only.

What's Missing

  • Org-scoped MCP server allowlists (different orgs may permit different servers)
  • Inherit/override model: enterprise base policy + org-level additions
  • Policy resolution: org policy inherits from enterprise, can add but not remove base restrictions

Context

In multi-org deployments, different organizations have different security requirements for which MCP servers are permitted. The current global-only model forces a lowest-common-denominator approach.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions