From what I can see, if a user has access to a mcp server, it has access to every tool of that server.
The auth check is done at the agent or gateway by making the tool available. There isnt a way for me to be able to restrict a users access to a limited subset of tools on an mcp server without restricting their ability to create apps, gateways and agents, and preconfiging gateways and agents for them?
An example is we use a microsoft graph mcp server, i may not want user to be able to send emails using the mcp server, but might want user b to be able to. With gateways and agents being the gate, I have to prevent user a from being able to create their own gateways and agents.
There's also that I'm pretty sure they could just create an app that accesses the send email tool on their behalf.