Backup software, product search, your thermostat, the United Nations, and your changelog walk into a week. That sounds like the setup to a joke. It is actually the week of September 14–18, 2026, when five vendors in five unrelated markets all shipped the same thing: a Model Context Protocol server that lets AI agents operate their product through a governed tool interface.
Each launch was defensible on its own. Together they are a pattern with a name: vendors no longer ask whether agents will touch their product, they ask through whose interface. And that pattern has one conspicuous missing row — the infrastructure that deploys and runs the apps those agents are building.
Five launches, five days
Here is the week, in order. Each row is a surface agents could not touch last week that they can touch now:
| Date | Vendor | What shipped | Status | What agents can now do |
|---|---|---|---|---|
| Sept 14 | ReleasePad | MCP server for changelog tooling | Live | Draft, publish, and analyze product release notes from a conversation with Claude, Codex, or Grok |
| Sept 15 | Rubrik | Rubrik MCP for Security Cloud | Announced, GA Sept 30 | Query backup, identity, and application intelligence — "last clean recovery point for this host, and the blast radius?" — through governed tools |
| Sept 15 | Algolia | Algolia MCP Server | Live, production-grade | Connect any leading LLM to product search and retrieval for agentic commerce, without rebuilding retrieval per model |
| Sept 16 | Home MCP | Early access, US-only | Read and control Nest and Matter devices, review camera summaries and event history, build dashboards — automations withheld for now | |
| Sept 18 | UN + Google | UN System Data Commons with MCP | Live | Query authoritative statistics from ~20 UN agencies in natural language, with provenance back to source |
Two details set the tone for everything below. Rubrik's launch was co-engineered with Anthropic and explicitly frames guardrails as part of the protocol layer, not the application around it. Google's launch gates agent access to your light bulbs behind a $20-a-month subscription tier — agent operability is now product surface worth paywalling, not a developer extra.
(One thing this table deliberately excludes: ServiceNow's AI Gateway v3.4, which added MCP runtime enforcement on September 10. That is the enforcement side of the same story — a gateway deciding which servers an agent may discover and which tools it may invoke — but it is a gateway, not a sixth vendor MCP server, so it belongs in the next section, not this table.)
The pattern isn't connectivity, it's governance
Five launches could be coincidence. What makes them a pattern is that every vendor converged on the same question — how does an agent prove it should be allowed to do this? — and answered it at the protocol layer rather than with a shared API key in an environment variable. But "converged" does not mean "identical": governance scales with capability, and the week's launches span the full range. Here is the matrix:
| Launch | Scoped, short-lived auth | Identity + RBAC parity | Runtime enforcement |
|---|---|---|---|
| ReleasePad | Present — remote MCP over Streamable HTTP with OAuth; first tool use opens a browser login | Partial — bound to the logged-in user, no distinct agent identity | Absent — nothing announced beyond OAuth |
| Rubrik | Present — per-tool-call tokens replace static API keys | Present — Agent Identity federates with Okta and Entra ID; agents inherit human RBAC | Present — OWASP MCP Top 10-aligned guardrails embedded in the protocol layer |
| Algolia | Partial — "production-grade foundation," auth mechanics not detailed in the launch | Partial — vendor-managed, per-application keys implied | Absent — nothing announced beyond the server |
| Google Home | Present — scoped OAuth via a configured Google Cloud project | Present — bound to the Google account that owns the home | Partial — availability gating (US-only, $20 tier) plus withheld capabilities (no automations yet) |
| UN Data Commons | Absent — public statistics need no auth | Absent — no identity layer at all | Absent — read-only data, nothing to enforce |
Read the matrix diagonally and the rule emerges: the more destructive the capability, the more governance ships with it. Public read-only statistics need none of the three primitives. Backup infrastructure — where a wrong tool call deletes the thing that saves you from ransomware — ships all three, co-engineered with the lab that wrote the protocol. Everything else lands in between, and the in-between is arguably the interesting part: ReleasePad and Google both put OAuth where a static key would have been easier, which tells you scoped auth is now the default expectation for a credible MCP server, not a premium feature.
The enforcement side crystallized the same week. ServiceNow's September 10 gateway release lets enterprises define which MCP servers an agent can discover, which tools it can invoke, and which resources it can reach — enforced at the gateway layer, with scoped short-lived OAuth tokens issued per connection, runtime pause controls, and PII checking. So the week's full picture is symmetric: vendors shipping governed servers on one side, enterprises shipping governed gateways on the other. The handshake both sides assume is the protocol.
Why vendors ship their own instead of letting the ecosystem do it
Every one of these vendors could have waited for the community to wrap their REST API in an MCP server — the community has already wrapped nearly everything else, with 10,000+ public servers indexed and SDK downloads past 110 million a month in 2026. They shipped their own anyway, and the launches state three distinct reasons:
1. Stop rebuilding the integration per model. Algolia's pitch is the clearest: developers connect ChatGPT, Claude, Gemini, or any MCP-compatible framework to the same retrieval foundation instead of rebuilding retrieval infrastructure for every AI experience. One server, every model. The vendor owns the hard part (commerce relevance over 1.75 trillion annual queries across 18,000+ businesses) and the protocol commoditizes the last mile.
2. Guardrails must live in the protocol layer. Rubrik's argument is that backup data is too dangerous to expose through an ungoverned wrapper: per-call tokens, federated identity, and OWASP-aligned guardrails are the product, not the packaging. A third-party wrapper could expose the same endpoints and none of the same safety — which, for cyber-resilience infrastructure, would be worse than no agent access at all.
3. Agent access is product surface. Google's $20-a-month gate says it plainly: operating your home through Claude or ChatGPT is a feature with a price, a tier, and a rollout plan. It is not a side effect of having an API.
The analyst numbers say this is now the default vendor move, not the adventurous one. Forrester expects 30% of enterprise app vendors to ship their own MCP servers in 2026; Gartner projects 75% of API gateway vendors and 50% of iPaaS vendors will have MCP features by 2026.
The protocol itself graduated to neutral governance — donated to the Linux Foundation's Agentic AI Foundation in December 2025 — and the July 2026 spec revision made servers stateless and production-shaped. The week of September 14 didn't start the trend. It is what the trend looks like at cruising speed: five vendors, five markets, one interface decision.
The missing row: deploy infrastructure
Now survey what the week covered: backup and recovery (Rubrik), product search (Algolia), the physical home (Google), release notes (ReleasePad), and public statistics (UN Data Commons). Data planes, all of them — places agents go to know things. The plane where agents go to do the thing developers most want them to do — ship the app, roll back the bad deploy, read the crash logs — has no first-party interface from any PaaS vendor. That is the missing row, and it is singular: no other weekly cadence of launches covers an operate-your-app surface, because no deploy vendor has shipped its own MCP server yet.
What should that interface be? The week's governance matrix writes the spec for free. A minimum viable deploy-MCP surface looks like this:
| Tool | What the agent does | Governance (per the week's matrix) |
|---|---|---|
| services.list / services.get | Inventory apps, read status and config | Read-only; scoped to the agent's project |
| deploys.trigger | Ship a commit or image | Scoped token + human approval gate for production |
| deploys.rollback | Revert to the last healthy release | Scoped token + human approval gate; the Rubrik row — destructive capability gets the most governance |
| logs.tail | Stream build and runtime logs | Read-only; PII/redaction rules like ServiceNow's gateway checking |
| metrics.get | Read CPU, memory, error rates, saturation | Read-only; scoped to the agent's project |
| envvars.get / envvars.set | Read config, rotate a non-secret value | Get masked for secrets; set scoped per variable, secrets excluded or approval-gated |
Nothing in this table is exotic — every PaaS already exposes these operations over REST. The point of the week's pattern is that REST is no longer the interface agents reach for first. Agents reach for tools, tools arrive over MCP, and the vendor that ships the server decides the permission model. A deploy vendor that skips this decision doesn't avoid it; it delegates it.
Ship it before someone else defines it
That delegation is already underway. While no PaaS vendor has shipped a first-party MCP server, third parties are defining the deploy interface unilaterally:
punkpeye/agent-deploy-dashboard-mcpoffers unified deployment management across Vercel, Render, Railway, and Fly.io through one community server — a single third-party abstraction deciding what "deploy" means on four vendors' infrastructure.adi4x4/offlocalai-mcpgives an AI coding agent onedeploytool that ships to Vercel, Railway, or Render, with each project environment mapped to a provider resource once.
Both are useful. Both also lock in interface choices — one generic deploy verb across vendors, credentials held by a middleman — that no vendor designed and no vendor governs.
Compare with the week's launches: Algolia decided retrieval semantics stay vendor-owned; Rubrik decided backup guardrails live in the protocol layer; Google decided home control is tiered product surface. Each vendor kept the decisions that encode its judgment. Deploy vendors, by waiting, are letting a generic verb and a middleman's credential store become the de facto agent interface to production infrastructure.
The week of September 14–18 will read, in retrospect, as the week the question flipped. It used to be "should we give agents a tool interface?" Now every vendor category answers that in the affirmative within the same five days, and the only remaining question is whose interface agents will use. For backup, search, smart homes, changelogs, and UN statistics, the answer is the vendor's own. For deploys, the answer is still up for grabs — and the longer vendors wait, the more of it gets defined by whoever shipped first.
Bex.co is the open-source, AI-native Render alternative — push a git repo, get a running HTTPS service on machines you own. Agents are first-class operators there, not an afterthought: a Render-compatible API over machine-readable infrastructure state. Star the repo on GitHub or deploy your first app today.



