← Back to all sparks
S

Speakeasy

DEVOPS
Velocity10.0

Speakeasy ships agent-as-principal identity and active Shadow AI blocking—moving from observing AI agents to controlling them.

ai-governancemcp-platformagent-identityenterprise-securityshadow-ai
◆Current state
Speakeasy has been building MCP governance infrastructure at a high shipping cadence. This week's most significant releases establish agents as first-class principals with their own scoped API keys, upstream accounts, and audit trail entries—ending the pattern of agents borrowing human identity. The MCP gateway now also actively refuses AI agents your organization has blocked via Shadow AI, shifting the platform from analytics-first to enforcement-first.
◆Where it's heading
The product is converging on enterprise AI governance: authorization, identity, billing, and enforcement for organizations managing many AI agents and MCP servers. Each release adds a control surface that enterprises need before deploying agents at scale—who is this agent, what can it do, what does it cost, and can we block the ones we don't want? The spend breakdown by product and incremental inference scanning point toward cost governance as the next focus.
◆Prediction
Agent-level identity and enforcement are now in place. Policy templates or role definitions that enterprise admins can apply across all agents without configuring each individually are the logical next step—reducing the per-agent setup overhead for large deployments.

◆Recent moves

  1. 3d ago

    Watchdog alerts are readable from Platform MCP, and the risk model can be compared before it enforces

    Making Watchdog alerts readable via Platform MCP and providing a dry-run comparison mode for the risk model lets teams audit what enforcement would do before it enforces—meaningful for teams introducing new security rules without wanting surprise lockouts.

  2. 3d ago

    Agents act as themselves: scoped keys, their own upstream accounts, and their own name in audit and usage

    ⚡ SPARK

    Agent-as-principal is the identity foundation everything else builds on: without agents having their own keys and audit trail, governance is a log search, not a control plane. This release makes agent identity a first-class fact in the platform and is the prerequisite for per-agent revocation, billing, and policy enforcement.

  3. 3d ago

    Issuers move between project and organization scope, and MCP servers pick an issuer that already exists

    Issuer scope mobility and MCP server reuse of existing issuers reduce duplicate configuration overhead for organizations managing many MCP servers across project and organization hierarchies. A maintenance improvement that matters at scale but is invisible to small deployments.

  4. 5d ago

    Workload sessions are labeled on the MCP Sessions page, and Platform MCP brings existing servers under management

    Labeling workload sessions separately from user sessions on the MCP Sessions page removes a source of confusion in deployments where both types run alongside each other, and bringing unmanaged MCP servers under Platform MCP management closes a coverage gap that would have left part of the infrastructure invisible to governance.

  5. 5d ago

    Spend by product for pay-as-you-go organizations, and inference scans that stop redoing work

    Per-product spend breakdowns give pay-as-you-go organizations a factual basis for AI cost allocation across agent session storage, risk scanning, and gateway egress. Incremental scanning that skips previously analyzed inference avoids redundant work and lowers the operational cost of running continuous risk scanning.

  6. 9d ago

    Claude Code and Codex tokens and cost reappear on usage, cost, and identity pages