Decide which agent may call which tool.
MCP gives agents capability. Xybern decides authority: which agent may reach which MCP server, which tool it may call, with what arguments, under what conditions and for how long. Every call is evaluated before it runs. MCP provides capability, Xybern provides authority.
Grant access to specific MCP servers and specific tools, not blanket capability. One agent may reach the finance server while another cannot, and a read tool can be allowed while a transfer tool is blocked.
Authorisation looks at the arguments, not just the tool. A transfer can be permitted only below a limit and only to approved counterparties, evaluated at the intercept before the call runs.
Access granted to one agent cannot silently propagate to another. Delegation rules apply to tool calls exactly as they do to any other action.
Related capabilities on the same authorisation layer. Every one is enforced before an action runs and sealed to the Provenance Vault.
Put one workflow behind Xybern and watch every agent action authorised, and sealed to the vault.