Secure
Shadow MCP
The Shadow MCP page inventories MCP servers discovered in agent traffic that aren’t managed by the platform — servers members connected on their own. Open it from Secure > Shadow MCP in the dashboard.
Shadow MCP detection depends on an active shadow MCP policy; a status banner on the page shows whether one is scanning and links to Risk Policies if not.
Access requirements
Section titled “Access requirements”Viewing this page requires the org:admin scope. Access is included in the default Admin role but not the Member role.
Inventory
Section titled “Inventory”The inventory table lists each discovered server with its status and allow decision. Statuses distinguish servers that are pending review from those that have been allowed or blocked.
Server detail
Section titled “Server detail”Opening a server shows:
- The server’s status and any allow rules that apply
- A Top users table — who uses the server, how often, and when it was last called
- An Add Allow Rule action to sanction the server for continued use
Use the detail view to decide whether a discovered server should be sanctioned (and ideally brought under management as a proper source) or blocked by policy.