What happened
Splunk published deployment guidance (Sept 8, 2026) for MCP Server 2.0, adding browser-based OAuth that binds agent access to an authenticated user, role-to-tool enforcement at discovery and invocation, safe SPL allowlists, rate/timeout/output-row limits, read-only alert tools, and provenance-labeled activity logged to _audit.
Why it matters
It's a concrete, shipping implementation pattern (from a major SIEM vendor) for the industry's biggest agentic-AI security gap: MCP tool calls executing with unbounded, un-auditable privilege — directly relevant as MCP-related CVEs (LiteLLM, DeepSeek Harness) proliferate this same week.
Applicability
Security teams deploying MCP servers against SIEM/telemetry data should adopt this as a reference architecture for OAuth-bound, role-scoped, audited agent tool access.