Tool-Level RBAC for MCP Servers — Now Generally Available
Share one MCP server across your entire org and control exactly which tools each user group can call — reads for everyone, writes and destructive actions only for the roles that need them. No duplicate servers, no code changes.
- Per-Tool, Per-Group Access — Grant a group access to a server, then scope it to specific tools, so each person’s agent sees only what they’re authorized to use.
- One Server, No Sprawl — Share a single mixed-sensitivity server across the whole org instead of maintaining watered-down copies per role.
- Contained Blast Radius — A hijacked or over-eager agent can only reach tools within its user’s authorized scope — nothing outside it.
Learn more in MCP.