Workato announced on July 16, 2026, the launch of its Enterprise MCP Registry, a governed inventory that gives a company a single record of every Model Context Protocol server running across its business. The registry is part of Workato Enterprise MCP, the company's control platform for connecting AI to corporate data and processes, and it arrives with a catalog of more than sixty ready-to-run MCP servers spanning functions from finance and HR to CRM and IT operations. Workato positions the registry as the system of record for discovering, approving, and governing the AI capabilities that agents call on.
Workato is an automation and orchestration company that connects more than fourteen thousand applications and runs processes for a large share of the Fortune 500. The Model Context Protocol has become a common way for AI systems to reach enterprise software, and Workato's argument is that the protocol handles the connection while leaving the harder questions unanswered, among them which capabilities are approved, who is allowed to use them, how security policy is applied, and what an agent did once it acted. Chief Product Officer Bhagat Nainani put the case simply, saying that "protocols alone can't run your business."
"MCP is becoming the standard way AI systems interact with enterprise software, but protocols alone can’t run your business. You need a platform,"
"As AI adoption accelerates, organizations need more than a protocol. They need a control platform that governs discovery, policy enforcement, identity, and accountability across every AI interaction. Workato’s Enterprise MCP Registry provides that foundation, allowing customers to scale AI safely while focusing their engineering effort on solving business problems instead of rebuilding infrastructure every team already needs."
Bhagat Nainani, Chief Product Officer at Workato
The registry is Workato's answer to that sprawl, and it reflects a shift GAIG has watched take shape across the field. The move worth noting is that agent capabilities are being treated as things that need an inventory, an owner, and an audit trail, the same discipline enterprises already apply to every other system that touches production.
Conditions Driving This Change
Enterprises are moving from a handful of AI pilots toward hundreds and eventually thousands of agents operating across the business, which turns the connections those agents use into infrastructure that has to be managed.
The Model Context Protocol has become a standard way to connect AI to enterprise data and processes, and it handles the connection itself while leaving governance, discovery, and auditing to the organization.
As teams build their own MCP servers, the number of them multiplies, and each tends to arrive with its own access model and no shared record of what exists or who may use it.
Security reviews stall when a company cannot say which agent took an action, which capability it invoked, and whether every step can be traced afterward.
Many MCP implementations simply expose raw APIs, which leaves an agent to discover, select, and orchestrate dozens of low-level calls, a pattern that invites error and runs up token costs.
Agents that act through shared service credentials break the link between an action and the person responsible for it, which weakens the least-privilege model that enterprise security depends on.
Buyers now expect an AI capability to carry the same security, versioning, and audit discipline as any other mission-critical system, and a protocol on its own does not provide that.
Component | What it does |
|---|---|
Enterprise MCP Registry | A governed system of record that inventories, versions, and approves MCP servers so only vetted versions reach agents |
Enterprise Skills | Reusable, tested business operations, such as creating a purchase order in SAP, that agents invoke instead of stitching together raw API calls |
MCP Composer | A builder for creating or extending MCP servers, drawing on connectors for more than 14,000 applications |
MCP Gateway and Proxy | The enforcement layer that applies authentication, authorization, credential management, rate limits, and data protection before a request reaches a system |
Verified User Access (VUA) | A control that runs each agent action under the requesting user's own identity and permissions rather than a shared service account |
What AI Governance Looked Like Before This
For most of the short history of enterprise AI agents, the connection was the whole conversation. A team that wanted an agent to reach a corporate system wired it up through whatever method was at hand, and once the agent could read and write to the system, the job was considered done. The Model Context Protocol made that wiring cleaner and more standard, and it spread quickly for that reason.
The trouble showed up as the count grew. One team's approved way of reaching Salesforce was not the same as another's, and a company running dozens of these connections had no single place to see what existed, which versions were live, or who had signed off on them. Each server carried its own access model, so a capability that one group had vetted could be rebuilt, slightly differently, by the next group that needed it.
Accountability was the weakest part. When an agent acted through a shared service account, the record showed that the service had done something without showing which person was behind it, and reconstructing what an agent actually did meant piecing together logs from several systems. A company could connect an agent to its most important systems while struggling to answer basic questions about who authorized a given action.
"Governance is one of the biggest barriers to deploying AI at enterprise scale,"
"It's not enough to know an agent is connected; you need to know who authorized the action, what capability was invoked, and whether every step can be audited. Workato gives us a consistent governance model across every AI interaction while allowing our teams to focus on business outcomes instead of infrastructure."
Kevin Wolf, Vice President of AI and Information Technology at Swanson Health.
What It Looks Like Now
The Enterprise MCP Registry puts a single inventory in front of that sprawl. Every MCP server, whether built by Workato, a vendor, a partner, or an internal team, moves through a managed lifecycle from development and testing to publishing, versioning, and retirement, and only approved versions become visible to developers and agents. A company gets one catalog of capabilities that teams can find and reuse in place of a scatter of overlapping servers.
The control does not stop at discovery. Workato's MCP Gateway applies authentication, authorization, credential handling, rate limits, and data protection before a request reaches a system, and its Verified User Access feature runs each agent action under the requesting user's own identity rather than a shared credential. A centralized audit trail records who initiated an action, which agent carried it out, which capability it used, and which systems it touched.
Workato is also pushing a particular way of building these capabilities. Rather than exposing raw APIs, its Enterprise Skills wrap complete business operations, such as creating a purchase order in SAP or reconciling records across Salesforce and Zendesk, into single governed actions an agent can call. Workato says this cuts the errors and token costs that come from asking an agent to orchestrate many low-level calls, though its claim that the approach removes hallucination risk reads stronger than the evidence supports, since constraining what an agent can do reduces certain failures without erasing the model's capacity to choose wrongly.
Our Take
AI Governance Take
The thinking behind this launch is sound, because the protocol was always going to be the easy part. Connecting an agent to a system is a solved problem, and the real work is knowing which connections are approved, who stands behind each action, and what happened after the fact, which is the ground a registry, a gateway, an identity check, and an audit trail cover together. Verified User Access is the detail worth watching, since tying an agent's action to a real person's permissions is the kind of accountability that agent security has mostly lacked.
The cautions are the ordinary ones for a fast-moving space. Workato is one of several companies building a control layer for MCP, alongside gateway and governance efforts from others, so buyers should compare how each handles identity, audit, and policy rather than assume the category has settled. The growth figures in the announcement, including a jump of more than two thousand percent in customer-published servers over six months, are genuine signals of momentum from a low starting base, and the claim that Enterprise Skills remove hallucination risk deserves the skeptical reading above.
The launch is one more sign that enterprises are treating agent capabilities as governed infrastructure, with inventories, owners, and audit trails, the same shift GAIG has tracked across the platforms it covers. Buyers weighing how to govern the connections between their agents and their systems can compare the options in the AI Governance category at GetAIGovernance.net, where the platforms that bring discovery, identity, and audit to the agent layer sit alongside the rest.