---
title: "Who Approved That MCP Server? Governing the Tool Layer"
category: "talks"
date: "2026-06-29"
time: "1:55pm-2:15pm"
track: "Expo Stage 1 NE"
room: "Expo Stage 1 NE"
speakers: ["Jim Clark"]
sourceLabels: ["Official conference schedule", "Public YouTube metadata"]
scheduleTrack: ""
scheduleRoom: "Expo Stage 1 NE"
scheduleLabels: ["Expo Stage 1 NE", "session", "confirmed"]
---
# Who Approved That MCP Server? Governing the Tool Layer

## Conference Context
- Date/time: 2026-06-29 · 1:55pm-2:15pm
- Track/room: track TBD · Expo Stage 1 NE
- Speaker(s): Jim Clark
- Session type/status: session · confirmed

- Track: track TBD
- Room: Expo Stage 1 NE
- Session type: session
- Status: confirmed

## Session Description
Your developers are installing MCP servers faster than security can review them. An unvetted server is a direct line to your data. This talk shows how the Docker MCP Gateway puts every server and tool behind one org-managed catalog: vetted, signed, default-deny on anything unapproved, governed by the same policy engine as network and filesystem. Walk away with a hands-on demo: stand up a catalog, block an unvetted server, and watch policy enforce at the runtime.

## Media Evidence
No related AI Engineer channel video found yet.

## Evidence Graph
This evidence graph is generated from currently linked source material: official schedule text, related video pages, cached transcripts, visible slide text, dense/reconstructed slide pages, and AI slide-classification audits.

### Media Signals
No linked video, transcript, or slide source has been attached yet.

### Agent Reading Notes
Use these signals to refine the synopsis, topic links, people/company context, and method notes. If a source is a related external video rather than an exact official recording, keep it framed as supporting evidence.

## Transcript Status
No official session recording transcript was found by exact title match on the AI Engineer YouTube channel during this run.

## People
- [[jim-clark]]

## Notes
- Pending transcript synthesis when an official recording or confirmed matching video is available.

## Synthesis
### Synthesized Breakdown
# Who Approved That MCP Server? Governing the Tool Layer ## Conference Context - Date/time: 2026-06-29 · 1:55pm-2:15pm - Track/room: track TBD · Expo Stage 1 NE - Speaker(s): Jim Clark - Session type/status: session · confirmed - Track: track TBD - Room: Expo Stage 1 NE - Session type: session - Status: confirmed ## Session Description Your developers are installing MCP servers faster than security can review them. An unvetted server is a direct line to your data. This talk shows how the Docker MCP Gateway puts every server and tool behind one org-managed catalog: vetted, signed, default-deny on anything unapproved, governed by the same policy engine as network and filesystem.

### Speaker And Company Context
- [[jim-clark|Jim Clark]] — Principal Software Engineer at [[docker|Docker]].

### Topics Covered
- [[coding-agents]]
- [[mcp]]

### Derived Links And Source Material

### Novel Concepts / Clever Methods
- No highlighted novel concept has been detected yet.

### Evidence Boundary
This synthesis is based on the official schedule and linked source pages. It should be revisited when exact session recordings or transcript-backed secondary sources are available.
