Kentico currently positions the Management API and MCP server for local development only, with basic authentication and no granular authorization. That makes today’s boundary clear: keep the interface away from staging, production, and anything publicly reachable. But as agent-driven workflows mature, it seems worth defining what would need to exist before that boundary could safely move.
Kentico now lets us restrict the tool groups and individual tools exposed to an AI client, which is useful for least privilege, but that is not the same as identity-based authorization. If a future version supports non-local environments, how should an agent’s permissions differ across development, QA or staging, and production? A development agent may need to create content types, workspaces, and test content. In staging, broader read access with narrowly scoped writes may be appropriate. In production, perhaps agents should be limited to named content operations within specific channels, workspaces, or languages, with structural changes prohibited entirely.
Would capability-specific scopes, environment-bound service accounts, allowlists, short-lived credentials, and human approval gates provide the right model? Which Management MCP operations should never be available in production, even with an approval step?