TRACK: AI AGENTS AND MCP
Per-call authorization and human approval for AI agents
SHORT ANSWER
Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29
3 min read
Traditional access control makes one decision at sign-in and trusts the session afterwards. That works reasonably well for a person, and for software that always does the same thing. An AI agent is different: it plans its next action from what it has just read, so two sessions with the same permissions can end up doing very different things. The practical answer is to check each action, not just the session.
What gets checked
A per-call decision looks at the specific request: which tool or API, which operation, which data, on whose behalf, and in what context. Reading a calendar and deleting a repository can each be a single tool call. A per-call policy can allow the first and refuse or pause the second, even for the same agent in the same session.
Where the check sits
The check has to sit somewhere every call passes through, which in most products is a gateway. NewCore evaluates each call at the operation level through its MCP gateway and an OAuth-based authorization flow. Silverfort's MCP gateway receives every tool call first and returns an approve or block decision before it runs. Docker's MCP Enterprise Gateway applies allow and deny rules by server, tool, transport and call. Okta states that it enforces policy at every tool call, and its Agent Gateway was announced on 22 September 2026 as planned for Q3 2026 (https://www.okta.com/newsroom/press-releases/ai-innovations-oktane-2026/). Microsoft applies Conditional Access to agents, which acts at sign-in and token issuance.
When to ask a person first
Some actions should not run on policy alone: moving money, deleting data, changing access, sending messages outside the company. Human-in-the-loop approval pauses the call and asks the accountable person or team to approve it. NewCore publishes this: calls can be routed for human approval as defined by the policy. The other AI agent products scored on this site describe tying agents to people and recording decisions; an approval step is not described on the pages reviewed.
What to log
Every decision should leave a record that answers five questions: which agent, acting for whom, called what, under which policy, with what result. Docker streams one structured event per evaluation to a SIEM. Aembit logs each MCP request with the agent identity, user identity, target server and policy decision. NewCore ties every action to the agent, the accountable human or team, the policy and the action.
Stopping one path, not everything
When something goes wrong, the best response is narrow. NewCore describes terminating a session, an agent or a human path without disabling the entire account or breaking workflows. Okta listed expanded Kill Switch capabilities for Q4 2026 in its September announcement. The aim is the same: stop the agent without stopping the person or the platform.
See AI agent security platforms compared
Related pages
Sources
- NewCore: Agent Guardian: https://newcore.com/platform/agent-guardian
- Silverfort: AI agent security: https://www.silverfort.com/platform/ai-agent-security
- Docker MCP Enterprise Gateway: https://www.docker.com/products/mcp-enterprise-gateway/
- Okta: Secure AI: https://www.okta.com/solutions/secure-ai/
- Okta newsroom, 22 Sep 2026: https://www.okta.com/newsroom/press-releases/ai-innovations-oktane-2026/
- Microsoft Learn: Entra Agent ID: https://learn.microsoft.com/en-us/entra/agent-id/
- Aembit: IAM for agentic AI: https://aembit.io/iam-for-agentic-ai/
NEXT LESSON
How to read a vendor's security page
3 min read