The tools that caught shadow IT can't see MCP sprawl
Blog post from WorkOS
AI agents are rapidly proliferating in corporations, with Gravitee reporting more than three million deployed in 2026, roughly doubling within four months while average monitoring coverage remained at 52 percent and only 14.4 percent of organizations fully reviewed every agent before deployment. Although this trend resembles earlier shadow IT, the text argues that traditional SaaS-discovery and network-monitoring tools are insufficient because many Model Context Protocol servers operate locally through stdio within developer tools rather than sending observable traffic across network boundaries. The security risk also differs from conventional data exposure because agents can actively perform consequential actions, such as modifying records, transferring funds, or accessing internal systems through employees’ existing permissions, often via personal accounts outside identity governance. With most organizations lacking visibility into their agent and MCP-connected environments and many reporting suspected security or privacy incidents, the proposed approach is to monitor security at the tool-call level by maintaining continuously updated inventories, assigning agent identities, and logging each tool call’s arguments and outcome.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.