<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>althor · Writing</title>
  <subtitle>Working notes from shipping agent systems into regulated environments.</subtitle>
  <link href="https://althor.dev/writing/feed.xml" rel="self"/>
  <link href="https://althor.dev/writing/"/>
  <id>https://althor.dev/writing/</id>
  <updated>2026-04-29T00:00:00Z</updated>
  <author>
    <name>Samuel Swegart</name>
    <email>contact@althor.dev</email>
    <uri>https://althor.dev/</uri>
  </author>
  <rights>© 2026 Samuel Swegart</rights>

  <entry>
    <title>Adding MCP servers to Copilot Studio in regulated environments</title>
    <link href="https://althor.dev/writing/mcp-copilot-studio/"/>
    <id>https://althor.dev/writing/mcp-copilot-studio/</id>
    <published>2026-04-28T00:00:00Z</published>
    <updated>2026-04-28T00:00:00Z</updated>
    <author>
      <name>Samuel Swegart</name>
      <uri>https://althor.dev/</uri>
    </author>
    <summary>Five architecture decisions the Copilot Studio MCP onboarding wizard quietly assumes you've already made — identity, DLP zone, generative orchestration, Streamable transport, tenant scoping.</summary>
  </entry>

  <entry>
    <title>Drawing the right boundaries for an MCP server</title>
    <link href="https://althor.dev/writing/mcp-server-boundaries/"/>
    <id>https://althor.dev/writing/mcp-server-boundaries/</id>
    <published>2026-04-21T00:00:00Z</published>
    <updated>2026-04-28T00:00:00Z</updated>
    <author>
      <name>Samuel Swegart</name>
      <uri>https://althor.dev/</uri>
    </author>
    <summary>Six rules that keep MCP tool surfaces narrow enough to defend without making them too narrow to use.</summary>
  </entry>

  <entry>
    <title>Making agent deployments pass security review</title>
    <link href="https://althor.dev/writing/agent-security-review/"/>
    <id>https://althor.dev/writing/agent-security-review/</id>
    <published>2026-04-21T00:00:00Z</published>
    <updated>2026-04-28T00:00:00Z</updated>
    <author>
      <name>Samuel Swegart</name>
      <uri>https://althor.dev/</uri>
    </author>
    <summary>A five-layer architecture for shipping agent systems into regulated environments — identity, credential broker, scoped tools, policy gating, audit.</summary>
  </entry>
</feed>
