Many teams discuss MCP as if the protocol itself solves the hard parts of production agents. It does not. MCP is valuable because it forces a boundary: tools, resources, prompts, and context become explicit interfaces rather than hidden application glue.
That boundary is only useful if the surrounding system is disciplined. Tool schemas need versioning. Resources need access control. Session state needs traceability. Memory needs scope. Without those controls, MCP can make unreliable systems easier to connect, but not safer to operate.
The production question is not whether an agent can call a tool. It is whether the organization can explain what the agent saw, why it selected that tool, what state changed, and how the result can be audited.