MCP makes it easier for AI agents to connect to enterprise systems, but moving from experimentation to production raises a deeper question: is controlling what an agent can access enough? An agent may have permission to update customer data, but that doesn't mean every authorized action should be executed in the same way.
This talk introduces the distinction between Access Control — what an agent is allowed to do — and Execution Control — how an authorized request should actually be carried out. We'll explore how mechanisms such as business rules, deterministic logic, and auditability, among others, can work together behind MCP tools to shape how execution happens in the enterprise.
The goal is to provide a practical architectural lens for teams taking MCP beyond adoption and into production: enterprise trust requires controlling not only what agents can access, but how their actions are executed.
___________________________
Presentation Language: Japanese
Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.