Call for Papers deadline extended —Submit your talk today →
All speakers
Workshop

Instrument your MCP server: audit, signing, and policy enforcement in half a day.

October 21 — Workshops Day · 9:00 AM · 3 hours · Auckland University of Technology

Most MCP setups in production have no audit trail, no policy enforcement, and no signed evidence of what the agent actually did. That's fine for prototypes — and it's exactly why security teams block these systems from going further.

This half-day workshop takes a working MCP setup and instruments it end-to-end: tamper-evident audit logs, Ed25519-signed receipts of every tool call, and a policy engine that blocks or allows at the proxy layer. You'll leave with a running pipeline you could demo to a security stakeholder on Monday.

We'll use agent-receipts (open-source, MIT) as the demo audit tool, but cover the alternatives — Pipelock, mcp-firewall — and discuss when each fits. The goal isn't to sell one tool; it's to give you a concrete, working starting point for the audit and policy conversation that's currently blocking your agentic features in production.

Facilitated by
Otto Jongerius

Otto Jongerius

Senior Backend Engineer

Tempo by Forsyth Barr

Otto Jongerius is a senior backend engineer at Tempo by Forsyth Barr, in Wellington — building event-driven serverless systems for financial services.

He's the creator of Agent Receipts, an open-source protocol for tamper-evident audit trails of AI agent tool calls. With a background spanning networking, systems engineering, and security, he writes at jongerius.solutions about backend engineering, AI tooling, and the messy realities of shipping software.