Your identity provider just learned AI tools exist
MCP's enterprise auth extension went stable in July, which means AI tool access can finally run through the front door. Most companies will keep using the window.
A quiet piece of July news deserves a louder audience. The Model Context Protocol's Enterprise-Managed Authorization extension went stable, which translates as: access to the tools your AI agents use can now be governed through your identity provider. The same place that governs everything else. Asana, Atlassian, Canva, Figma, Granola, Linear and Supabase already support it on their end; Claude and VS Code support it on the client side.
If that sentence made your eyes glaze, let me tell you what I watched a mid-size firm do last year instead. Their agents needed access to the ticketing system, so an enthusiastic engineer created a service account with a very long-lived token, stored it somewhere honest, and wired it into the agent platform. Then the document system needed the same, and the design tool, and by the time anyone senior asked "so what exactly can our AI agents touch", the accurate answer was a shrug with seven tokens in it. Nobody did anything wrong, exactly. The front door did not exist yet, so everyone used windows.
The front door now exists. That is the news.
What I would do with it, in order. First, inventory the windows: every service account, long-lived token and improvised credential your agent integrations currently use. This is an afternoon with your platform team and it will surprise you (it has surprised every team I have sat with; the record is nineteen).
Second, check your vendors against the supported list and turn on identity-provider control for the ones that have it. Your security team already knows how to reason about IdP groups; letting them reason about agents with the same vocabulary is worth more than any AI policy document you will write this year.
Third, for the vendors not on the list, ask them when. It is a one-line email, and vendors count those emails.
The pattern here is one I keep returning to: governance that works arrives as infrastructure, not as policy. The policy said "all agent access must be reviewed" for two years, and the tokens multiplied anyway. The infrastructure makes the reviewed path the easy path, and the tokens will quietly stop multiplying, not because anyone issued a memo but because the front door is now closer than the window. That is what winning at governance actually looks like. Undramatic, I know. The good kind usually is.