MCP is an API endpoint. If your MCP endpoints are auditable, and the rest of your APIs are not, you're doing something wrong