Morgan — Security & Compliance Lead

morgan

Type: Secondary Persona

Responsibilities

Problem Statement Context Impact Naftiko Today Naftiko Tomorrow Type
Need to Securely Enable MCP in Developer IDEs
Security teams must evaluate and approve MCP server usage within developer IDEs before enterprise-wide adoption can proceed.
Morgan (Security & Compliance Lead) — AI Context Delivery, Governance and Compliance, Agent-Ready Developer Experience
Need MCP Streaming to Work with Enterprise Security
HTTP streaming and SSE connections required by MCP and AI services conflict with existing corporate security policies and infrastructure.
Morgan (Security & Compliance Lead) — AI Context Delivery, Governance and Compliance
Need Agent-to-Agent Identity Propagation
Identity and authorization tokens must be properly propagated when AI agents call other agents or services in multi-hop scenarios.
Morgan (Security & Compliance Lead) — Governance and Compliance
Need Governance Review Tracking
Morgan needs to track and report on API governance reviews across the portfolio.
Morgan (Security & Compliance Lead) — Governance and Compliance
Need Centralized Credential Management
Morgan needs teams to obtain API tokens and keys from an internal gateway rather than directly from 3rd-party providers.
Morgan (Security & Compliance Lead) — Governance and Compliance
Need to Govern AI-Generated Code
Morgan needs to ensure AI coding assistants follow security policies when generating code, with attestation of compliance.
Morgan (Security & Compliance Lead) — Governance and Compliance
Need Explicit Agent Boundaries
Repositories need to explicitly declare what AI agents are allowed to change and what is off-limits.
Morgan (Security & Compliance Lead) — Governance and Compliance, Agent-Ready Developer Experience