MCP approval workflow: fast, defensible reviews for unverified MCP servers
Blog post from Speakeasy
Speakeasy has introduced MCP Approval Flow within its AI Control Plane to help organizations turn blocked connections to unreviewed Model Context Protocol servers into documented security decisions. When a shadow MCP policy blocks an agent’s tool call, the user can submit a justification through a link without needing dashboard access, while designated reviewers receive a server profile containing automated evidence about its publisher, authentication requirements, capabilities, maintenance status, organizational usage, and prior reviews. Security teams can approve or deny requests and limit approvals to an individual, team, or project, with each decision and rationale recorded directly in the blocking policy. Optional research agents can collect cited information from independent sources but cannot make approval decisions. After approval, daily checks compare relevant server permissions and advisories against the original review snapshot, flagging changes for renewed evaluation while emphasizing that narrow access grants remain important because interface-based comparisons cannot detect all behavioral changes.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 23 | 8,729 | 854 | 211 | -20% |
| Secrets Management | 1 | 2,244 | 480 | 132 | -13% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.