Derek Tu

Derek Tu

All Articles by Derek Tu

May 20, 2026

MCP access governance starts with RBAC

Hand-written Cedar policies won’t scale past a handful of MCP servers. Here’s how Stacklok Enterprise brings RBAC to ToolHive and what it looks like in practice.

April 20, 2026

GitHub authorization for MCP servers

It’s easy to justify static credential configuration when an MCP server starts out as a one-user, one-server setup in a developer environment. But things quickly get complicated when that server …

March 30, 2026

MCP server authorization for downstream access

In enterprise MCP deployments, authentication and authorization at the MCP server don’t fully determine downstream authorization. The server still has to reach downstream systems with the right credential, the right …