# Shadow MCP

The **Shadow MCP** page inventories MCP servers discovered in agent traffic that aren't managed by the platform — servers members connected on their own. Open it from **Secure > Shadow MCP** in the dashboard.

Shadow MCP detection depends on an active shadow MCP policy; a status banner on the page shows whether one is scanning and links to [Risk Policies](/docs/ai-control-plane/secure/risk-policies) if not.

## Access requirements

<Callout type="info">
  Viewing this page requires the `org:admin` scope. Access is included in the [default Admin role](/docs/ai-control-plane/org-admin/roles-and-permissions) but not the Member role.
</Callout>

## Inventory

The inventory table lists each discovered server with its status and allow decision. Statuses distinguish servers that are pending review from those that have been allowed or blocked.

## Server detail

Opening a server shows:

- The server's status and any allow rules that apply
- A **Top users** table — who uses the server, how often, and when it was last called
- An **Add Allow Rule** action to sanction the server for continued use

Use the detail view to decide whether a discovered server should be sanctioned (and ideally brought under management as a proper source) or blocked by policy.
