Instrument your MCP server: audit, signing, and policy enforcement in half a day.
October 21 — Workshops Day · 9:00 AM · 3 hours · Auckland University of Technology
Most MCP setups in production have no audit trail, no policy enforcement, and no signed evidence of what the agent actually did. That's fine for prototypes — and it's exactly why security teams block these systems from going further.
This half-day workshop takes a working MCP setup and instruments it end-to-end: tamper-evident audit logs, Ed25519-signed receipts of every tool call, and a policy engine that blocks or allows at the proxy layer. You'll leave with a running pipeline you could demo to a security stakeholder on Monday.
We'll use agent-receipts (open-source, MIT) as the demo audit tool, but cover the alternatives — Pipelock, mcp-firewall — and discuss when each fits. The goal isn't to sell one tool; it's to give you a concrete, working starting point for the audit and policy conversation that's currently blocking your agentic features in production.

Otto Jongerius
Senior Backend Engineer
Tempo by Forsyth Barr
Otto Jongerius is a senior backend engineer at Tempo by Forsyth Barr, in Wellington — building event-driven serverless systems for financial services.
He's the creator of Agent Receipts, an open-source protocol for tamper-evident audit trails of AI agent tool calls. With a background spanning networking, systems engineering, and security, he writes at jongerius.solutions about backend engineering, AI tooling, and the messy realities of shipping software.
