# The Blind Spot

## You've seen this before

### 01.
#### Security blocked it
Engineering adopted Cursor and Claude Code. Productivity went up. Security filed a ticket. Now there's a meeting next Tuesday to "discuss AI tool policy." You know how this ends: a blanket ban, a spreadsheet of approved tools, and your best devs updating their LinkedIn.

### 02
#### You approved it with duct tape
You built a Notion database of approved MCP servers. Developers self-report what they connect. It's an honor system. You have no way to enforce read vs. write access, no way to know who's connecting to what, no way to prove anything to security.

### 03
#### Shadow MCP is already here
Developers didn't wait for approval. They spun up MCP servers for GitHub, Postgres, internal APIs. Connected them to Cursor and Claude Code. Running in production. You don't know how many exist because your tooling doesn't see MCP traffic.

MCP and integrations connect to your data. No LLM control. No visibility. Blind stack.

# How Golf Solves It

## Enforce. Discover. Audit.

### 01
### **Enforce**
Set policies once, apply everywhere. Read vs. write per MCP server. Per team, per tool, per data source. Your devs keep Cursor, Claude Code, Copilot - security gets granular control. Nobody asks you to manually approve each connection.

### 02
### **Discover**
See every MCP server running in your environment. No more Notion databases. No more honor system. Auto-discovered, auto-classified. You finally have the inventory security keeps asking for.

### 03
### **Audit**
When compliance asks "what's connected and who authorized it?" - you have the answer in seconds. Full log of every connection. No more scrambling to build a spreadsheet before a review.

## Deployment

### 3 steps. Live in days.

#### STEP 1
### Connect
Your identity provider and your SIEM. Golf maps your org and starts streaming logs.

#### STEP 2
### Deploy
MCP Control Plane in your environment. On-prem, hybrid, or cloud. Data never leaves.

#### STEP 3
### See everything
Every MCP server. Every agent. Every connection. Secured.

# Why Golf

## Enable MCP without becoming the bottleneck

### Zero developer friction
Previous solutions: 17 onboarding steps per developer. Golf: 3 steps. No CLI changes, no IDE plugins, no workflow disruptions. Developers don't know it's there.

### Governance ≠ blocking
Every other approach either blocks tools or ignores them. Golf is the third option - govern at the MCP layer, invisible to the people using the tools.

### You own the catalog
No more Notion databases and honor systems. Golf auto-discovers every MCP server and gives you a real catalog - approved, pending, shadow - that security actually trusts.

# Arm Your Champion

## Need to sell this internally?
You can't buy this alone. Here's ammo for the 3–12 people to convince.
