For Platform and Security
Use this page if you are evaluating AI coding tools through the lens of permissions, credentials, MCP risk, review controls, and revocation.
Who This Is For
- platform engineering teams
- security engineers
- compliance-minded engineering leads
- internal developer platform maintainers
Best First Steps
- Read Security and Permissions.
- Review What is MCP?.
- Apply MCP Approval Policy.
- Use Security Checklist Template during review.
Highest-Priority Pages
Permissions and Approval
MCP Risk and Evaluation
Review Workflows
Reusable Controls
Recommended Next Action
Start with a read-only tool or MCP pilot, define revocation before broader approval, and keep merge or deploy rights behind explicit human review.
Verification Note
This page points to the strongest security-facing material in the repo. Some MCP pages remain evaluation guides because implementation-level risk varies.