Skip to content

INDUSTRY

What Wasabi MCP Changes for DevOps: Storage Governance You Can Ask For

August 24, 2026
Vilas BelagoduField CTO & VP of AI Strategy

Bucket configurations can drift over time, some buckets may never have the appropriate security policies applied, and permissions require ongoing review. These are the kinds of issues that create real operational risk for DevOps teams.

Within bucket configuration, one of the most critical risks is an incorrectly configured IAM policy that unintentionally grants a user access to data or resources they were never meant to have.

Capital One's 2019 breach traced back to exactly this: an over-permissioned IAM role that gave an attacker read access to more than 100 million customer records. Accenture's 2017 exposure came down to four S3 buckets left publicly accessible with no authentication at all, letting anyone with the URL pull API keys, decryption keys, and internal credentials. A cryptomining campaign AWS disclosed in December 2025 traced back to compromised IAM credentials that let attackers hijack EC2 and ECS resources across multiple organizations.

All of it falls under storage governance, the ongoing work of keeping buckets, policies, and permissions consistent across every team and environment.

DevOps teams traditionally handled this with a script for whatever problem came up, checking the console bucket by bucket, or building compliance tooling from scratch. Each approach worked for the specific problem it was built for and that’s it.

Wasabi MCP flips this paradigm by allowing an AI agent to handle these checks and actions conversationally, across storage, access, and multi-account monitoring. Governance becomes something DevOps can simply ask for and act on.

A quick primer on MCP

MCP stands for Model Context Protocol. It's an open standard that defines how AI agents connect to outside systems, including backend storage. It isn't tied to one AI vendor or model, so the same connection works whether the agent runs on Claude, Cursor, or something else. For Wasabi, that means one secure connection gives any AI agent immediate access to Wasabi storage through a standardized set of more than 150 tools.

What used to require custom scripts, hardcoded endpoints, and manual API calls for every new workflow is now a single natural language prompt. The agent builds a plan, works through it step by step, confirms before making any permanent change, and reports back, without anyone touching a console or writing integration code.

Wasabi MCP is available now as a beta feature, with capabilities still evolving.

What this means for DevOps

Here are six common scenarios where DevOps teams use Wasabi MCP. Each covers a different part of managing storage, from setting up a new environment to catching a misconfiguration after it happens, and shows what it looks like in practice.

Bucket provisioning and standardization

Traditionally: Setting up a new environment to match an existing storage template meant manually clicking through console settings, or writing vendor-specific automation in YAML or Terraform.

With MCP: New environments can match existing storage templates without the manual console work or custom scripting. 

"Audit all buckets created this month and flag any that don't match our standard naming convention."

"Apply a 90-day archive policy to all buckets tagged 'dev' or 'sandbox'." 

IAM policy enforcement

Traditionally: Finding buckets missing an IAM policy meant checking them one at a time, and old data didn't always get cleaned or archived on schedule.

With MCP: Buckets missing policies can be found and IAM policies applied at scale, so old data actually gets cleaned or archived on schedule.

"Find every bucket without an IAM policy configured and list them by team."

“Find all buckets without a secure IAM policy in my account.”

“Create a new bucket for a new employee; apply the following policy(s) to the bucket, once created; run a read/write/delete test and share the test output with me.”

"Create a new bucket for the staging environment with the same identity and access settings as production."

Access governance audits

Traditionally: Permission sprawl and least-privilege violations were typically caught only after a security incident, not before one.

With MCP: Least-privilege checks and permission sprawl detection can happen before an incident.

"List every IAM policy that grants write access to the production data bucket, and who holds each one."

"List any sub-user with read/write/delete access to more than 1 bucket in the account."

Offboarding and access revocation

Traditionally: When an employee leaves, removing their access meant going through their Wasabi accounts, buckets, and the account management platform separately.

With MCP: That access can be removed easily, across accounts, buckets, and the account management platform, in one step.

"Remove [employee]'s access to their Wasabi accounts, buckets, and account control management platform."

Multi-team oversight via WACM and Stats

Traditionally: Usage rollups and quota monitoring across sub-accounts meant compiling that data manually, sub-account by sub-account.

With MCP: Usage rollups and quota monitoring across sub-accounts can be pulled directly.

"Summarize storage usage and growth across every team's sub-account this month."

"Which sub-accounts are approaching their storage quota?"

“Pull usage rollups and quota monitoring across sub-accounts, and compare it to what was purchased and recorded in the CRM.”

Incident response

Traditionally: Config change errors were caught only by manual review or compliance tooling.

With MCP: Those changes can be flagged directly instead of waiting on the next review.

"Alert me to any bucket that had its public-access setting changed in the last 7 days."

How to get started

DevOps teams have always needed to know which buckets are missing policies, who still has access to what, who needs to lose that access the day they leave, and which sub-account is about to blow past its quota. Now, with Wasabi MCP, your team just has to ask using tools you’re already using today.

Explore the quick start guide to connect your first agent. Pick a use case, connect, and see what your storage can do when agents are running it. For a deeper technical walkthrough, the Wasabi MCP documentation has you covered.

Don’t have a Wasabi account yet? Start your free trial or buy now.

An open standard (Model Context Protocol) that gives AI agents standardized access to Wasabi storage through a single secure connection and more than 150 tools, instead of custom integration code.

Yes. Wasabi MCP isn't tied to one AI vendor or model; the same connection works whether the agent runs on Claude, Cursor, or something else.

Yes, it's live now as a beta feature, with capabilities still evolving.

The six scenarios covered here are bucket provisioning and standardization, IAM policy enforcement, access governance audits, offboarding and access revocation, multi-team oversight via WACM and Stats, and incident response.

Related article

ai cloud data storage
INDUSTRYAI storagemaxxing: The hottest AI strategy you’ve never heard of

Most Recent

The hidden tax on AI: Why storage is eating your AI ROI

AI training reads the same data 10-100x over. Egress and API fees turn that into a hidden tax on AI storage. See what's driving up your AI infrastructure costs.

Why Wasabi is the persistent data platform for production RAG

Production RAG applications need more than a vector database. See how Wasabi's persistent data storage keeps AI pipelines improving without costly rebuilds.

Spicy Bytes: Physical security edition, featuring Milestone Systems

From deleted footage to analytics-ready archives: how egress-free pricing and responsible AI are reshaping physical security's approach to data.

SUBSCRIBE

Storage Insights from the Storage Experts

Storage insights sent direct to your inbox.

Subscribe