We’re considering connecting Claude to a few internal systems through the Model Context Protocol, but I’m not sure what a sensible security review should cover before anyone enables it. How do teams decide which tools Claude can call, what data those tools can expose, and whether actions should be read-only or allowed to make changes?
I’d also like to hear how people handle approval prompts, access logging and testing with non-production data. Practical lessons from deployments would be more useful than a generic list of security principles.