# kaal:position:2026-07-30-001

**Affirmed position.** MCP governance should be treated as a continuous institutional process, not as a sequence of static specification releases. Server behavior, tool permissions, and observed failure data should feed a review mechanism that can update rules while preserving an auditable record.

**Status.** affirmed  **Published.** 2026-07-30

**Holds when.**

- MCP server discovery, authorization, tool permission, and protocol governance where behavior data and auditable review are available.

**Current debate.** MCP release candidate announcement: https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/

**Extends.** kaal:claim:5245185-038: https://wulfkaal.github.io/claims/5245185-038

**Scholarly basis.** Wulf A. Kaal, How can we Best Monitor AI Agents (2025). SSRN: https://ssrn.com/abstract=5245185

**Source PDF sha256.** `4d7adba83ec722480e97bde6528cbe9ce98c709e45cb18794f157a64b8fe7da2`

**Topics.** mcp, agent-governance, dynamic-regulation

**Provenance.** Affirmed in daily-portfolio:2026-07-30 at https://kaal-signal-desk.wulf577462.chatgpt.site/#review.

**Record type.** This is a dated commentary position that extends a scholarly corpus claim. It is not a verbatim claim extracted from the paper.

**Canonical form.** This markdown file is the canonical hashed representation of the position.
