Solutions

Choose where your agents can share sensitive data.

Find the workflow that matches yours. See which reads you can allow, which destinations you can block, and how to set the policies.

Financial services

Control where your agents share customer financials.

An analytics agent queries customer financials in Snowflake for a board summary, then tries to publish that summary to a public Notion page.

Data covered
Customer financials in Snowflake and live Stripe records. Test and aggregate data stay out of scope.
Blocked after access
Posts to public pages, writes to external bases, and sends outside business hours by the same identity.
Still allowed
Updates to internal pages and private channels.
Snowflake
Queries customer financialsSnowflake MCP · sensitive read
✓ Allow
Notion
Publishes the summary to a public pageNotion MCP · public page
✗ Deny
Notion
Publishes it to the finance team’s pageNotion MCP · internal page
✓ Allow

Why: customer financials read by the same identity.

Both servers connect through Wicket.

Healthcare

Keep your agents’ patient updates with the care team.

A care-coordination agent reads a patient’s record through the hospital’s EHR MCP server, then tries to post a visit summary to a department-wide Slack channel.

Data covered
Patient records and lab results through your EHR’s MCP server. Scheduling and directory lookups stay out of scope.
Blocked after access
Department-wide channels, external bases, and ticket systems.
Still allowed
The care team’s private channel and internal notes.
Custom MCP
Reads a patient’s recordEHR MCP · patient record
✓ Allow
Slack
Posts a visit summary to a department channelSlack MCP · department-wide channel
✗ Deny
Slack
Posts it to the care team’s channelSlack MCP · private channel
✓ Allow

Why: patient record read by the same identity.

Both servers connect through Wicket.

Software

Let your agents debug private code. Block public posts.

An engineering agent reads a private repository to debug an incident, then tries to post the details to a public Slack channel.

Data covered
Private repositories, production databases, and environment variables. Public repositories stay unrestricted.
Blocked after access
Public channels, public repositories, and ticket systems.
Still allowed
The private incident channel, so the agent can keep the team updated.
GitHub
Reads a private repositoryGitHub MCP · private read
✓ Allow
Slack
Posts the details to a public channelSlack MCP · public channel
✗ Deny
Slack
Posts them to the private incident channelSlack MCP · private channel
✓ Allow

Why: private-repository read by the same identity.

Both servers connect through Wicket.

Our team can help you plan a custom MCP connection for your EHR or document management system during onboarding. Wicket uses earlier policy matches for the same identity to authorize calls. It does not classify message contents, and both servers must connect through Wicket.