| Where it runs | Remote HTTP MCP at the Cloudflare edge | Local gateway on each machine (stdio + HTTP bridge), plus hosted or self-host Teams control plane |
| Secrets | Platform / org patterns | No org secret vault. Keys stay in each member's OS keychain |
| Shared server catalog | Portal config | Teams config sync with version history (Team+) |
| Who can use which server | Portal access controls | Per-server member and group grants (Team+ to edit) |
| Per-tool allow / deny | Portal tool policy | Org allow-lists and deny-lists enforced in the local gateway (Team+) |
| Safety policy | Platform controls | Destructive block, human approval, quarantine, content defense; org can only tighten |
| Proof policy applied | Inline path = enforced at edge | Apply receipts + coverage for instructions and screening policy (cooperative, with timestamps) |
| Runaway tool-call protection | Spend / identity budgets (model and platform) | Hard tool-call rate limits (day/month, member/tool axes) in the gateway (Team+); 80% webhook warn |
| Spend budgets | Dollar limits with block at model layer | Monthly estimated-cost budget with admin email alert (Team+). Not a model-meter hard block |
| Audit trail | Analytics + Logpush-style export | Usage and events CSV; Free 14-day floor; opt-in per-call export (tool, time, duration, ok, args hash; never args or results) |
| Webhooks / alerts | Platform notifications | HMAC-signed webhooks, retries, all or security filter; Free includes one security channel |
| Dashboard sign-in | Cloudflare Access (any IdP, MFA, device posture) | GitHub / Google OAuth, magic link, and TOTP 2FA |
| SSO (SAML / OIDC) + SCIM | Yes via Access / IdP | Roadmap (Enterprise). Contact for scoping Roadmap |
| Device posture | Yes (Cloudflare One) | Not a product lane (local-first) N/A by design |
| Self-host control plane | Different product shape | Yes: Docker image on your network |