Solutions
Choose where your agents can share sensitive data.
Find the workflow that matches yours. See which reads you can allow, which destinations you can block, and how to set the policies.
Financial services
Control where your agents share customer financials.
An analytics agent queries customer financials in Snowflake for a board summary, then tries to publish that summary to a public Notion page.
- Data covered
- Customer financials in Snowflake and live Stripe records. Test and aggregate data stay out of scope.
- Blocked after access
- Posts to public pages, writes to external bases, and sends outside business hours by the same identity.
- Still allowed
- Updates to internal pages and private channels.
Why: customer financials read by the same identity.
Both servers connect through Wicket.
Healthcare
Keep your agents’ patient updates with the care team.
A care-coordination agent reads a patient’s record through the hospital’s EHR MCP server, then tries to post a visit summary to a department-wide Slack channel.
- Data covered
- Patient records and lab results through your EHR’s MCP server. Scheduling and directory lookups stay out of scope.
- Blocked after access
- Department-wide channels, external bases, and ticket systems.
- Still allowed
- The care team’s private channel and internal notes.
Why: patient record read by the same identity.
Both servers connect through Wicket.
Legal
Control where your agents share privileged files.
A research agent reads a privileged case file in the firm’s document management system, then tries to publish its summary to a page shared with the client.
- Data covered
- Privileged matters and confidential deal spaces. Public filings stay out of scope.
- Blocked after access
- Client-shared pages, external channels, and vendor bases.
- Still allowed
- The matter team’s pages and the firm’s internal channels.
Why: privileged case file read by the same identity.
Both servers connect through Wicket.
Software
Let your agents debug private code. Block public posts.
An engineering agent reads a private repository to debug an incident, then tries to post the details to a public Slack channel.
- Data covered
- Private repositories, production databases, and environment variables. Public repositories stay unrestricted.
- Blocked after access
- Public channels, public repositories, and ticket systems.
- Still allowed
- The private incident channel, so the agent can keep the team updated.
Why: private-repository read by the same identity.
Both servers connect through Wicket.
Our team can help you plan a custom MCP connection for your EHR or document management system during onboarding. Wicket uses earlier policy matches for the same identity to authorize calls. It does not classify message contents, and both servers must connect through Wicket.