Default-deny every tool
Every agent starts with zero tool access. Add allowlist entries explicitly per agent. Most production agents need 5–10 tools, not 50.
Teams that hand agents a full MCP server end up with agents calling tools nobody knew existed.