MCP Governance

Default-deny tool registry

Servers must be inspected, provenance-checked, permission-approved and explicitly enabled before an agent can use their tools.

5catalog entries
0enabled by default
MFAapproval requirement
SHA-256stdio provenance gate
Context7 Documentation

documentation:read

discovered
GitHub MCP

issues:read, issues:write, pull_requests:read, pull_requests:write, repository:read, rules:read, workflows:read

discovered
Playwright Browser MCP

browser:read, browser:test

discovered
PostgreSQL Read-only MCP

database:read

discovered
Supabase MCP

documentation:read, database:read, database:migration, functions:read

discovered
anzenforge mcp inspect <id> --tools-file tools.json --digest sha256:... then approve and enable with an explicit permission subset.