# Illustrative Case Study: coding-agent production access

Illustrative example based on a hypothetical pilot. This is not an actual customer, testimonial or financial result.

## Initial risk

A hypothetical five-developer SaaS team exposes repository, database, refund and internal-browser tools to coding agents. The initial control gap is a shared credential without a per-call review surface.

## Agent and MCP workflow

Five sample coding-agent identities use HTTP MCP routing and a command-mode local fixture over a 14-day evaluation (2026-08-10–2026-08-23 UTC). Client names describe protocol roles, not vendor certification.

## Control model

The teaching model denies destructive shell actions, denies production writes and reviews sensitive access, and allows low-risk reads. The actual production pack continues to deny database writes. Request binding, expiry and audit exports are demonstrated separately against the runnable fixture stack.

## Quantified sample outcome

| Metric | Before evaluation | Hypothetical pilot |
|---|---|---|
| Unique calls reviewed | No per-call evidence in the scenario baseline | 1240 |
| High-risk calls | Not measured in baseline | 160 (12.90%) |
| Initial denials | Not measured in baseline | 60 |
| Approval-required | No centralized review in baseline | 100 |
| Approval outcomes | Not applicable | 70 approved / 20 denied / 10 expired |
| Permitted fixture executions | Not measured in baseline | 1150 |
| Requests remaining blocked | Not measured in baseline | 90 |

## Operational result

The example rollout decision is read-only production access with one owner for policy and one for approval review. The design accounts for every sample call but does not imply measured savings, prevented incidents or customer endorsement. Publication is safe as an explicitly illustrative example; a real case study requires its own evidence and customer permission.
