---
title: Your Vendors Shipped a Dozen MCP Servers This Month. Nobody Is Auditing What They Add Up To.
description: "Eventtia, Stravito, Panopto, and G2 all shipped MCP servers in the same week. The single-vendor governance playbook everyone is writing misses the risk that actually matters: the combined surface across every vendor at once."
author: LETSGROW Dev Team
date: 2026-09-27
category: AI Tools
tags: ["MCP", "AI Agents", "Security", "Marketing Technology", "Integrations"]
url: "https://letsgrow.dev/blog/mcp-server-sprawl-marketing-stack-audit"
---
# Your Vendors Shipped a Dozen MCP Servers This Month. Nobody Is Auditing What They Add Up To.

Eventtia shipped an MCP server on September 25 with read-and-write access to attendees, sessions, and payments. Stravito shipped one the day before. Panopto bundled an MCP Server into a video-knowledge feature launch the same week. G2 expanded its own MCP offering in the same seven days. That is four new agent-facing entry points into a mid-size marketing stack in a single week, and none of those vendors had an MCP server six months ago.

Every post about this trend treats it as a one-vendor problem. Salesforce shipped 40 new MCP tools, so the advice is a Salesforce permission audit. Canto turned its asset library into an MCP server, so the advice is a brand-governance review. Demandbase gave an agent ad-spend control, so the advice is an approval workflow. Each piece is right on its own terms and each piece misses the actual risk, because the risk is not what any single vendor's MCP server can do. It is what an agent can do once it holds valid credentials to twelve of them at once, and nobody in your organization has ever looked at that set as a set.

## The math nobody is running

A marketing stack with 15 to 20 connected tools is normal. If a third of those vendors have shipped an MCP server by year end, which is roughly the pace this year has set, you are looking at five to seven live agent entry points into systems that hold customer PII, payment data, brand assets, and campaign spend authority. Each one was provisioned by a different person, approved through a different process, and scoped by whatever the vendor's default permission tier happened to be at signup time.

Nobody owns the union of those scopes. Your Salesforce admin knows what the Salesforce MCP tools can touch. Your events team knows what Eventtia's server can touch. Nobody has ever asked what an agent can do if it is handed working credentials to both at the same time, because that question does not belong to either team. It belongs to whoever owns agent governance for the whole stack, and at most companies that role does not exist yet. The individual audits are not wrong. They are just answering a smaller question than the one that matters.

## What changed this specific week

The volume is the tell. Before this year, an MCP server launch was a headline event for one vendor at a time; you had months to write the governance policy before the next one showed up. That gap closed. Four unrelated vendors serving four different functions in a typical marketing stack shipped MCP servers inside the same seven days, with no coordination between them and no shared standard for what "read-only" or "write access" actually means at the credential level. Stravito's server is read-only research access. Eventtia's is read-write, including check-in and payment data. Panopto's plugs an entire video knowledge base into whatever agent framework calls it. Three different risk profiles, three different vendors, one week, and the person deciding whether to turn each one on almost certainly evaluated it in isolation.

::stat-block
title: The compounding surface
value: 4
label: New vendor MCP servers shipped in a single week (Sept 19-25, 2026)
context: Each approved independently, none evaluated against the others already live in the same stack
::

## The audit that actually catches this

A vendor-by-vendor security review will keep passing every individual check while the aggregate exposure keeps climbing. The fix is a stack-level inventory that treats every MCP server as one row in a single table, not as a checkbox in each vendor's own onboarding doc.

::checklist
title: Stack-level MCP audit
items:
  - Build one inventory listing every MCP server connected to any marketing tool, who provisioned it, and what scope it holds (read-only, read-write, payment-adjacent)
  - For each entry, name the specific agent or workflow that actually uses it. An unused live credential is pure liability with zero offsetting value.
  - Map overlapping scopes across vendors. If three servers can each touch customer contact data, that is one risk surface, not three.
  - Assign a single owner for the whole inventory, separate from any individual vendor relationship owner.
  - Set a 90-day re-certification cycle. Vendor MCP scopes change with every release; your last approval is not your current exposure.
  - Route new vendor MCP connections through this owner before provisioning, not after.
::

## Build the gateway before the twentieth vendor ships one

The teams handling this well are not writing a new governance memo every time a vendor announces an MCP server. They are routing every agent-to-vendor connection through a single internal gateway that holds the actual vendor credentials and issues short-lived, scoped tokens to agents on request. The agent never sees the Eventtia key or the Salesforce key directly. It asks the gateway for a token scoped to exactly the task in front of it, and that token expires. One place to audit. One place to revoke. One log that shows every vendor an agent touched, instead of six vendors' worth of scattered access logs that nobody cross-references.

This is more setup than approving each vendor's default integration, and it is the only version of this that scales past the pace vendors are shipping at right now. If your team is still writing a fresh governance doc for every new MCP server announcement, you are already behind the vendors, not ahead of them. Stop auditing one door at a time and start auditing the building.
