I’ve had the same conversation repeatedly this month. Someone building an AI agent system, getting excited about MCP, connecting their agents to internal tools and then asking: “Wait, how do we rate limit this? How do we audit what the agents are calling?