# kaal:position:2026-07-31-002

**Affirmed position.** MCP governance should be treated as a continuous institutional process, not as a sequence of static releases. Discovery, authorization, tool permissions, and observed failure data require an auditable review mechanism that can adapt rules without erasing accountability.

**Status.** affirmed  **Published.** 2026-07-31

**Holds when.**

- MCP discovery, authorization, tool permission, and protocol governance where behavior data and auditable review are available.

**Current debate.** MCP 2026-07-28 RC: https://github.com/modelcontextprotocol/modelcontextprotocol/releases/tag/2026-07-28-RC

**Extends.** kaal:claim:5245185-038: https://wulfkaal.github.io/claims/5245185-038

**Scholarly basis.** Wulf A. Kaal, How can we Best Monitor AI Agents (2025). SSRN: https://ssrn.com/abstract=5245185

**Source PDF sha256.** `4d7adba83ec722480e97bde6528cbe9ce98c709e45cb18794f157a64b8fe7da2`

**Topics.** mcp, agent-governance, dynamic-regulation

**Provenance.** Affirmed in signal-desk:2026-07-31-email-affirmation at https://kaal-signal-desk.wulf577462.chatgpt.site/#review.

**Record type.** This is a dated commentary position that extends a scholarly corpus claim. It is not a verbatim claim extracted from the paper.

**Canonical form.** This markdown file is the canonical hashed representation of the position.
