← Today's edition · Issue archive

Governance

JumpCloud ships Agentic IAM with MCP discovery: 8.5% of MCP deployments use OAuth

2 min read · 409 words · reading time calculated from the full text of this article (200 wpm)

Enterprise IAM is waking up to agents. JumpCloud's Agentic IAM update auto-discovers MCP server configurations across an organization and routes them through a governed AI Gateway, treating each agent as a first-class identity that can be audited, restricted, or revoked — the same lifecycle humans get, applied to non-human actors.

The stats behind the push explain why IAM vendors smell budget: 30 CVEs filed against MCP infrastructure in 60 days (Jan-Feb 2026), 82% of MCP deployments vulnerable to path traversal, only 8.5% using OAuth at all, and 88% of organizations have had or suspect an agent-related security incident in the past year. Machine identities outnumber humans 109:1 in the average enterprise, and only 14.4% of agents reach production with full security approval.

Read the numbers together and the picture is blunt: agents got deployed at consumer-grade security, and the tooling that would govern them did not exist. When a vendor like JumpCloud builds MCP discovery into IAM, that is the market admitting agents are infrastructure — with inventories, permissions and audit trails — not experiments on a laptop. If you run agents inside a company, the near-term checklist is unglamorous: inventory what you actually connected, put auth in front of it, and assume the audit question arrives before the ROI question.

From Issue #001 — the complete section as published in the daily digest:

Governance in practice — Frameworks & Tools of the week

8. WSO2 ships an open-source control plane, formalizing agent governance as infrastructure — forkast.news (via GNews)

Link: https://news.google.com/search?q=WSO2+open-source+control+plane+agent+governance

Governance moved from slide decks to deployable infrastructure this week. Builders: if you sell anything agentic, “works with your governance plane” just became a checklist item.

9. GitHub trending — the safety-tooling wedge is real:

Pattern to watch: three of the week's launches are “make agents checkable” tools. The governance/audit wedge is where small teams can still ship without a model budget.


Sources & further reading:
Coverage · Full Issue #001

Keep reading

← Today's edition (all stories) 📖 Issue archive — every daily digest → mcp security scan checklist→ x402 165m transactions→ litellm cisa kev