╭────────────────────────────────────────────╮
       ╱   raw catalog      brokered surface         ╲
      │   provider tools -> Hub -> governed execute  │
      │   legitimacy happens before the call runs    │
      ╰───────────────────────────────────────────────╯
           Control the boundary, not just the route.
Architecture

The MCP Hub as Brokered Control Plane

The Hub becomes important when it stops being a convenience layer and starts being the place where a tool call has to prove it should happen. This paper explains why flat MCP catalogs break down, why the brokered flow is search then describe then execute, and how that flow gives CREATE SOMETHING one house surface for identity, authorization, budget posture, and traceability before downstream execution. It also keeps the maturity line honest: as of March 16, 2026, the Hub is a strong control-plane implementation, not yet a fully closed fleet-scale governance layer for hundreds of tools.