Advanced
Open
Pro
What `managed-mcp.json` Actually Locks Down
Your organization deploys managed-mcp.json to every engineer's
machine, listing three approved MCP servers. A project's own
.mcp.json, checked into the repo, configures a fourth server that
isn't in that list. An engineer on that machine runs claude mcp add
to add the fourth server locally, for that project.
What happens?
Share this question