Saying no didn't work. People just routed around it.
AI workflows at Stability AI were held together by personal API tokens, usually sitting in a dotenv file on someone's laptop. Security had almost no visibility into what was connected or how it was being used, and blocking a request only pushed people to find another way in.
“The problem isn't getting people to use AI. It's that every workflow was held together by personal API tokens sitting in a dotenv file on someone's laptop.”
Christian Burrows
Head of Security, Stability AI
The review load made it worse. Requests came into IT and security as one-off tickets, someone wanting their email, their wiki, or their ticket tracker as an MCP server, and each one had to be reviewed twice, first by IT and then by security, reinventing the wheel every time for what one person could and couldn't do.
So the real question wasn't whether to allow AI. It was how to say yes without losing control.
One policy, from the top down: yes, but nothing destructive.
Instead of reviewing servers one at a time, Stability's IT team looked back at every MCP server anyone had ever asked for, evaluated each one from the catalog, and added them proactively. The policy was simple to state: AI can do anything except remove or delete. For end users, connecting is just a slash command.
“A company doesn't exist because I'm trying to secure it. I'm trying to support the business. Mint let us say yes while still controlling which tools and which types of calls can be made.”
Christian had looked hard at building it in-house, and he had shopped around. There were some near fits, but his real problem was agent identity and tool-level control. He knew the shape of what he'd have to build: the broker, agent identity, a token vault, connector runtimes, RBAC, audit. He also knew the cost would shift from building it once to maintaining the connector catalog forever. Mint solved the real problem without that ongoing tax.
What Stability AI told us
From evaluation to company-wide in less than a month. Everyone with a seat uses it, which at Stability means everyone. Christian is clear that Mint was never the blocker: if the situation had demanded it, they could have launched to the whole company in a week or two.
The day-to-day change was the point. People went from using one or two services to connecting ten different types of MCP tools, so instead of copy-pasting between a ticket, a repo, and a doc, someone could read a ticket, check the repo, cross-reference the doc, and draft the update in one place. Nobody was hand-wiring a four-system workflow like that before.
“It went from really, really loud to really quiet. Nobody's talking to us about MCPs anymore. The cognitive overhead of considering MCPs just completely went away.”
His advice to another head of security is short: don't build the broker. Decide your policy in one sentence for your own company, do the audit-log work before you launch, plan the telemetry as a product, and assume vendor drift and build for it.
Move from reviewing every MCP twice to one policy from the top
See how Mint lets you say yes to AI across the company with the visibility and controls security needs. Read more stories