MCP servers across the team
One laptop can say which MCP servers it launches. Only the team can say that the same Stripe server is wrapped on four machines and launched bare on the fifth, which is the fifth machine's agent reaching refunds with nothing in its way. That server is a shadow server, and it is named under Waiting on you until somebody approves it or blocks it. Nothing else about the inventory asks for attention: it fills and stays current by itself.
What the inventory holds
One row per server, from the scan each enrolled machine sends: which machines and agents configure it, whether every one of them reaches it through the proxy, how many of its tools write, and when it was first and last seen.
Shadow servers come first. A server is a shadow when it is launched without
Memnox in the way on at least one machine and nobody has approved it, and its row
names that machine and whose it is. The whole inventory is read from
GET :ws/mcp-servers, for a script or a report; the console shows only the
servers that need a decision.
Approving one
Approve is a person's word that the team runs this server on purpose, and it takes the server off the shadow list and out of Waiting on you. It needs an admin.
Blocking one for everybody
Block for the team proposes a rule that refuses every tool on that server, added to the rules already in force. It is a proposal like any other rule set: nothing is in force until a second admin approves it under Autonomy, and the person who proposed it cannot be that admin.
On one machine
The same question has a local answer that needs no account:
$memnox scan --mcp <server>$memnox mcp wrap$memnox mcp trust <server>
