Field note
Anthropic made enterprise-managed authorization generally available for MCP connectors: an admin provisions a connector for the whole organization through the identity provider, starting with Okta, and users get access automatically on first login. The August update lists Datadog, Notion and Slack as supported, with Exa, Miro and Zoom named as coming, alongside existing support for Asana, Atlassian, Canva, Figma, Granola, Linear and Supabase.
The change removes one of two steps. Previously an admin enabled a connector for the organization and then every individual user authorized it themselves; now the admin authorizes once and users inherit access through the IdP groups and roles they already hold, which Anthropic describes as zero-touch setup for the end user. The authorization decision therefore moves from the person using the agent to the directory that already describes what that person may reach.
That is the control plane forming around agents, described in agent operations converging on connectors, memory and observability, and it is the identity-first position argued in ChainDrop showing why agent security starts with identity. The MCP hub tracks how connector permissions are governed.
The announcement covers provisioning and supported applications, not what a connector may do once granted or how revocation propagates. The condition to watch is whether inherited access publishes a per-connector scope and an audit trail, because inheriting a connector from a directory group is only safe if the group's reach is legible.