Connectors Are the New Attack Surface
Consider a payments connector wired into a workplace AI assistant. It can expose a balance lookup, which you probably want widely available, and a refund action, which you almost certainly do not. In most admin consoles today, those two capabilities arrive together, and your only control is a switch that turns the whole connector on or off.
That gap is why we tell clients that connectors have become the sharpest edge of an AI rollout. A connector is the piece that joins an assistant or agent to a real business system: email, files, CRM, finance. The model can only read what its connectors reach, and more importantly, it can only act through them. Whoever controls the connectors controls what the AI can actually do.
How connectors spread today
Two things happen in parallel in most organizations. Admins enable the vendor's official connectors from the console. Meanwhile, developers add their own local MCP servers without asking anyone, because the protocol makes that easy and the tools are useful. The result is over-broad access, tokens sitting in config files, and shadow MCP servers nobody has reviewed.
The vendor tooling has improved, but the gaps are still structural. In Claude Cowork, admins can run a private plugin marketplace, pre-approve plugins and scope them to specific groups. Connectors, however, are org-wide on or off, with no per-group control, and each user then authorizes individually. Anthropic's own guidance says some governance still requires manual processes outside the product.
The distribution channel is also a supply chain. Harmonic Security notes that a GitHub-synced marketplace pushes updates to all users when a version bump merges, so a single compromised commit reaches everyone, and that plugin hooks are not covered by Anthropic's scanning. If your connectors and plugins come from a repository, the review process for that repository is part of your security perimeter.
The fix is moving to the identity provider
The June 2026 Enterprise-Managed Authorization extension to MCP points at where this settles. It moves connector provisioning to the identity provider, so users get the servers their role allows without clicking through per-server consent screens. Access to a finance connector becomes a property of being in the finance group, granted and revoked the same way as access to the finance system itself.
We expect this to become the norm: by the end of 2027, connector access will sit with the identity provider, and per-user OAuth consent for MCP servers will fade in managed environments.
Until your vendors get there, the control that matters is least privilege applied per tool rather than per server. The minimum bar we score against in client reviews: access granted per capability, read-only by default, with write and delete actions granted by role. A connector that can refund customers should require more than a connector that can look up a balance, even when both ship in the same package.
What good looks like, for all four of the distribution channels we track, is the same shape: a curated registry, provisioning through the identity provider, and tool-level allowlists enforced through a gateway. Connectors are simply the channel where getting this wrong has the most immediate consequences, because they are the one that touches systems of record.
What to do this quarter
The practical sequence we recommend has four steps.
Set connectors to off by default and publish a short approved list. This is unpopular for about two weeks and then becomes normal.
Inventory the MCP servers already running, including the local ones developers added themselves. The identity provider's application list and a scan for tokens in config files will find most of them.
Default new connectors to read-only. Grant write actions deliberately, by role, with a named owner for each system an agent can change.
Put a gateway or registry in front of connector traffic where you can. Central enforcement gives you one place to see what was called, by whom, with what result, which is also the evidence an auditor will eventually ask for.
Connectors are one of four distribution problems we analyze in our white paper, alongside prompts, plugins and scheduled tasks. The full treatment, including the nine controls every deployment needs, is in Deploying AI at Scale.