[ TRANSMISSION // BLOG ]
Planting the flag: runtime governance, in public.
AI agents became production actors this year, and the ecosystem — Microsoft included — is converging on the same conclusion: tool execution needs a control plane. Today we're committing to the category out loud: one phrase, one definition, and a public body of work behind it.
Blog/September 7, 2026·Rupam Biswal
We had three names for the same idea floating around — and if your own properties can't agree on what you are, neither can a search engine or a language model. So we picked one: AI agent runtime governance is the category. The MCP firewall is the wedge — the enforcement layer that makes governance real for agents acting through the Model Context Protocol. That hierarchy now reads the same on this site, in llms.txt, on GitHub, and on LinkedIn.
[ WHAT SHIPPED ]
- The knowledge layer. /learn opened with eight articles across four pillars — from the category definition to the MCP threat model and securing Claude Code. Every page opens with the definition, includes real YAML, and ends with exactly one paragraph about us. The answer is never behind marketing copy.
- Runnable labs. mcp-security-examples — per-call tool authorization and six-field audit logging, implemented from scratch in tested, dependency-light Python. Vendor-neutral: everything works without any SentnelOps product.
- Receipts. Every statistic we cite now lives on /research/mcp-landscape with its primary source — the April disclosure that put ~200,000 MCP instances in scope, the 97M monthly SDK downloads, and Microsoft's "Securing MCP" control-plane post. One number we'd been carrying couldn't be sourced, so it's gone. That's the standard.
- Comparisons. MCP firewall vs API gateway and governance vs guardrails — because category borders matter as much as category centers.
[ WHY NOW ]
Because the question stopped being hypothetical. Agents hold real credentials and act on real systems, and every control that exists — IAM, service accounts, gateways, guardrails — was built for a different actor. The industry is arriving at the same answer from different directions; our view is simply that the enforcement point belongs in the request path, outside the agent's process, with an identity for every agent and evidence for every decision.
What's next: one article a week, a lab per implementation guide, and an ecosystem-wide MCP security survey later this quarter. Autonomous, never ungoverned.
SentnelOps is an AI agent runtime governance platform — an MCP firewall giving every agent an identity, runtime policy on every tool call, and an audit-ready evidence trail. Start with the knowledge layer or log your first call in 10 minutes.