{"slug": "centaur-2-0-permissions-context-and-mcp", "title": "Centaur 2.0: Permissions, Context, and MCP", "summary": "Centaur 2.0, announced by Paradigm, introduces company-wide context archival, granular permissions, and MCP support, enabling agents to access tools and data across platforms. Over 80% of Centaur sessions now occur in shared channels, and the update ships on a smaller Rust core. MCP support allows querying Centaur from local agents like Amp, Claude Code, or Codex, with cross-client handoff expected in coming weeks.", "body_md": "# Centaur 2.0: Permissions, Context, and MCP\n\nAI models change quickly, but a company’s tools, data, permissions, and shared history shouldn’t have to change with them. To address that, today we're announcing Centaur 2.0, giving every agent the same permissioned access to a company's tools and context, wherever people choose to work.\n\nCentaur 2.0 introduces:\n\nCompany-wide context archival, so that your Centaur can quickly search across all configured data sources including Gmail, Granola, Slack and more.\n\nGranular permissions, so that you can configure who has access to what resources, allowing you to give Centaur access to sensitive data without worrying about unauthorized access from its users.\n\nMCP, so that you can query Centaur from your local agent, whether it is Amp, Claude Code, Codex, or your custom harness.\n\nTwo months ago, [we open-sourced Centaur](https://www.paradigm.xyz/writing/open-sourcing-centaur-multiplayer-self-hosted-secure-agents), our self-hosted runtime for secure, multiplayer agents. We believed agents would become shared infrastructure: present where decisions happen, equipped with a team's tools, and able to build context across an organization.\n\nThat thesis is playing out. More than 80% of Centaur sessions now happen in shared channels rather than DMs, and questions that once meant digging through years of messages, notes, emails, and databases get answered in minutes.\n\nPutting an agent in a shared channel was the easy part. But making it useful inside a real organization requires access to sensitive systems, an understanding of company context, and the ability to carry those capabilities across models and interfaces. 2.0 ships the permissions and MCP support today, on a smaller, more reliable Rust core.\n\n# Permissions that follow the conversation\n\nThe previous version of Centaur assumed one organization-wide set of credentials. Companies don't work that way. Teams have shared systems, and access changes depending on where a conversation happens.\n\nCentaur 2.0 derives access from the context in which it's invoked. A DM can use a person's connected accounts; a shared channel gets only the credentials and data sources granted to that team. Each sandbox receives its own identity, and grants are enforced at the network boundary without ever exposing credentials to the agent.\n\nYou can now connect systems that would be unsafe to place behind a single organization-wide credential. We use this ourselves: in a DM, Centaur can query your personal Granola notes and email; tagged into a channel, the same agent switches to the documents shared with that team. An engineer never sees a partner's meeting notes. The same rules apply to workflows, which receive only the access appropriate to their context.\n\n# Use Centaur’s tools anywhere\n\nSwitching models or clients shouldn't mean leaving your tools, permissions, and context behind.\n\nMCP support ships today. You can use Centaur's tools and context from Claude, ChatGPT, or any other MCP client, under the same identities and grants used inside Centaur. We can ask Claude about a portfolio company, and it will pull the same meeting notes and documents Centaur would surface in Slack.\n\nMCP support also lays the groundwork for cross-client handoff, which should ship in the coming weeks. Start a task in Claude, send it to Centaur, then close your laptop while the work continues. Long-running tasks will no longer depend on one device or client, and you can resume them without losing context or progress.\n\nThe same principle applies to Centaur itself. Claude Code, Amp, Codex, and nanocodex all run behind one harness interface. Slack remains Centaur's primary multiplayer interface, but teams have also contributed integrations for Linear, GitHub, Discord, and Microsoft Teams. We're also building a richer web console for persistent workspaces, files, traces, approvals, and long-running executions that don't fit inside a chat thread.\n\nThese are different ways to inspect and steer the same underlying work, not separate products with separate context and permission models.\n\n# Organizational context that compounds\n\nThe next step is helping agents understand not only what is stored in company systems, but how it all fits together.\n\nWe've shipped permission-aware organizational memory internally. Centaur can retain prior decisions, relationships, and projects while respecting the boundaries between a person, a channel, a team, and the company. We'll open-source it once we're confident in its guarantees and retrieval quality.\n\nLonger term, we want to index the entire company under the same permission model. Workflows will ingest context from wherever work lives, while classifiers categorize what comes in, extract metadata, and connect related artifacts. At Paradigm, that can mean recognizing a meeting as a new investment opportunity or a portfolio catch-up, extracting the company's stage, and linking the note to its data room and any prior conversations.\n\nEvery organization will classify its work differently; what's common is the infrastructure that turns scattered artifacts into connected context and makes it available to agents without bypassing the permissions of the underlying systems. Centaur already indexes Slack, Granola, Google Drive, Google Calendar, Linear, and Attio, with more integrations on the way.\n\n# A smaller Rust control plane\n\nBuilding these capabilities exposed a problem. Centaur's original API had accumulated everything from sandbox management to Slack rendering, and each new feature added more ways to fail. We rewrote it in Rust as `api-rs`\n\n, a control plane that exposes only four operations: create or reuse a session, append a message, execute a turn, and stream events. The rewrite matters practically: Fewer responsibilities mean fewer failures, and a simpler API means we can more rapidly develop new integrations. Since the 2.0 rollout, over 99% of daily Centaur sessions complete successfully.\n\n# Get started\n\nModels will change quickly. A company's tools, data, permissions, and shared history shouldn't have to change with them. Centaur 2.0 is available today at [github.com/paradigmxyz/centaur](https://github.com/paradigmxyz/centaur). If you're new to Centaur, the quickest path is [centaur.run](https://centaur.run); if you're upgrading from 1.0, start with the [migration guide](https://github.com/paradigmxyz/centaur/blob/main/contrib/MIGRATING_TO_RS.md).\n\n# Come build with us\n\nWe're hiring engineers to work on Centaur full-time:\n\nThe work spans distributed systems, agent runtimes, security, developer tools, and product. Apply through the postings above, or if you'd be an asset to the team in a role that isn't listed, email [mslipper@paradigm.xyz](mailto:mslipper@paradigm.xyz).", "url": "https://wpnews.pro/news/centaur-2-0-permissions-context-and-mcp", "canonical_source": "https://www.paradigm.xyz/writing/centaur-2-0-permissions-context-and-mcp", "published_at": "2026-08-10 16:29:02+00:00", "updated_at": "2026-08-10 16:42:40.081110+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "ai-infrastructure", "developer-tools"], "entities": ["Paradigm", "Centaur", "Amp", "Claude Code", "Codex", "MCP", "Slack", "Granola"], "alternates": {"html": "https://wpnews.pro/news/centaur-2-0-permissions-context-and-mcp", "markdown": "https://wpnews.pro/news/centaur-2-0-permissions-context-and-mcp.md", "text": "https://wpnews.pro/news/centaur-2-0-permissions-context-and-mcp.txt", "jsonld": "https://wpnews.pro/news/centaur-2-0-permissions-context-and-mcp.jsonld"}}