A Better Door, Same Broken House
Real-time access control for AI agents is a good idea. It's not the same as fixing your entitlements.
Noma announced the launch of Agent Access Control designed to govern Model Context Protocol (MCP) servers and autonomous AI agents throughout the enterprise. Instead of treating an enterprise AI tool like a static web app, Noma’s new feature acts as an inline authorization gatekeeper, discovering shadow AI-to-machine integrations and enforcing real-time access policies on what specific tools an agent can execute within an MCP server.
It’s an architecturally sound play if you are actively evaluating platforms to build a scalable security boundary around internal AI development. By building an abstraction layer that speaks MCP natively, Noma is saving your internal application security teams months of custom data-plumbing work and policy-as-code engineering.
But look past the sales collateral. “Out-of-the-box” agent posture control cannot fix broken backend entitlement logic. If your underlying S3 buckets or database service accounts already suffer from privilege creep, putting an agent access gateway on top just creates a prettier view of your existing identity debt. Evaluate it as a runtime policy engine, not a cure for bad IAM hygiene.

