MCP Tool Controls are part of Agent Governance and are available on the Enterprise plan. Enforcement supports Cursor, Claude Code, Factory Droid, OpenAI Codex, and Devin Desktop through Hooks.
The policy page
Open Governance → MCP in the Corridor dashboard. The page shows one row for each MCP server found in your team’s Artifact Inventory. Each row shows the server’s installations, observed tools, rules, and current policy. Expand the row to see its tools and installations, then select an installation to open its details. Choose one setting for each server:
Each tool has the same Inherit / Allow / Block settings. The page shows the tool’s effective decision and whether it came from a tool rule, server setting, or team default.
The team-wide default at the top of the page, Allow all or Block all, applies to every tool without an explicit rule. Before you confirm a change, Corridor shows how many tools will switch.
How Corridor resolves a decision
The most specific explicit setting wins:- Tool rule: An explicit Allow or Block on a tool overrides a server-level setting. You can block a server while allowing one approved tool, or allow a server while blocking a specific tool.
- Server setting: If the tool has no rule, the server’s Allow or Block setting applies.
- Team default: If the server is set to Inherit, the team-wide default applies.
Reviewing new servers and tools
Newly discovered servers and tools show a NEW badge until someone marks them reviewed. The page also counts items that still need review. Corridor shows how each observed tool was discovered: from the server’s published tool list, a session transcript, or a live agent tool call.Roles
How enforcement works
When a developer’s agent attempts an MCP tool call, Corridor’s hook checks the call against your team’s policy before it executes. A blocked call never reaches the MCP server. The agent receives a message explaining that your organization’s compliance policy blocked the tool and that the developer should contact a team administrator. Enforcement is best-effort and fail-open. If Corridor cannot check the policy, such as when the developer’s machine is offline, the call is allowed so development can continue. Agent Telemetry records which tools were called, including calls that enforcement could not check.Some locally launched MCP servers on Cursor and Devin Desktop are identified by their launch command. Configure these servers through the legacy MCP Compliance allow/block lists. The server and per-tool settings on this page do not apply to those calls.
Next steps
Artifact Inventory
See every MCP server, skill, and plugin across your team
Shell Command Controls
Deny risky shell commands with bans and patterns