Step 1Take the inventory
What runs on developer machines today, and with which permissions.
ATALAIAFirst, what runs on your laptops? Extensions, agents, MCP servers.
DEVELOPERI use an AI agent with a database MCP server. It saves me hours.
DEV LEADWe never listed any of it. Everyone installs their own.
Leaves the roomInventory: 41 extensions, 6 agents, 9 MCP servers
Step 2Rank the exposure
Which tools can read code, keys or tokens, and which talk to the internet.
ATALAIAThat MCP server holds a read-write token for the staging database.
DEVELOPERAnd the agent can run any shell command I can.
ATALAIASo a web page the agent reads could tell it to run commands as you.
Leaves the room3 tools can reach production keys
Step 3Set the gate
An allow-list, a review path and sane defaults for agents and MCP.
PLATFORMWe ship an allow-list. New extensions get a short review.
ATALAIAMCP tokens become read-only and expire daily. Shell commands need a confirm.
DEVELOPERFine, as long as a review takes a day, not a month.
Leaves the roomAllow-list, review path, scoped tokens
Step 4Keep it current
Telemetry and a monthly review so the list doesn't rot.
ATALAIATelemetry lists what's installed. We review the new ones every month.
DEV LEADAnd the local firewall blocks unknown traffic from dev machines.
Leaves the roomMonthly review, telemetry on
- ATALAIA
- DEV LEAD
- DEVELOPER
- DEVELOPER 2
- DEVELOPER 3
- PLATFORM