For Platform and Security

Use this page if you are evaluating AI coding tools through the lens of permissions, credentials, MCP risk, review controls, and revocation.

Who This Is For

  • platform engineering teams
  • security engineers
  • compliance-minded engineering leads
  • internal developer platform maintainers

Best First Steps

  1. Read Security and Permissions.
  2. Review What is MCP?.
  3. Apply MCP Approval Policy.
  4. Use Security Checklist Template during review.

Highest-Priority Pages

Permissions and Approval

MCP Risk and Evaluation

Review Workflows

Reusable Controls

Start with a read-only tool or MCP pilot, define revocation before broader approval, and keep merge or deploy rights behind explicit human review.

Verification Note

This page points to the strongest security-facing material in the repo. Some MCP pages remain evaluation guides because implementation-level risk varies.