MCP 2026 roadmap lists audit trails: what Sume records for agents
The MCP 2026 roadmap names audit trails as an enterprise priority. Here is what Sume records for an agent's paid work today: jobs, receipts, the usage ledger.

For an agent that spends money, Sume records the work as jobs, receipts and a usage ledger today, and each paid MCP call carries an idempotency_key that ties a retry to one job. That is a trail you can reconcile. The docs list no separate audit-log product, so build the trail from these three records and your own client logs.
What the roadmap says
The MCP project's 2026 roadmap, published on March 9, 2026, names four priorities: transport scalability, agent communication including Tasks, governance, and enterprise readiness. The enterprise item lists audit trails, SSO-integrated authentication and gateway behavior. It is a direction for the protocol, not a feature of any one server, so each server still needs its own answer.
Where the records are
Sume answers at the level of the work, not the chat. The hosted server exposes read tools for jobs: jobs_list, jobs_get, jobs_status, jobs_result and jobs_events. Each paid or write tool call requires an idempotency_key, and dry_run=true previews cost before it is charged. Separately, GET /v1/usage returns the usage ledger, and the docs call it the authoritative billing record.
| Roadmap item | What Sume ships today | What you add |
|---|---|---|
| Audit trails | jobs_list, jobs_get, jobs_events, usage ledger, receipts | A log of which agent session made which call |
| SSO-integrated auth | OAuth for the hosted server, with mcp:read and mcp:write scopes | Your identity provider's sign-in policy |
| Gateway behavior | Plain HTTPS, Authorization header on every request | Your gateway's allow list and logging |
| Spend governance | dry_run, max_spend_usd, wallet admission, plan concurrency | Alerts on your own budget |
A trail you can reconcile
The practical pattern is to give each agent run a stable business key and carry it everywhere. Use the same key in the idempotency_key, in your own log line, and in the label you store next to the job id. A retry then maps to one job, and a ledger line maps back to a decision.
Read the ledger
The script below reads the usage ledger and prints the first part of it. It assumes SUME_API_KEY is set, and it calls only the read endpoint, so it spends nothing.
import os, urllib.request
req = urllib.request.Request(
"https://api.sume.com/v1/usage",
headers={"Authorization": "Bearer " + os.environ["SUME_API_KEY"]},
)
with urllib.request.urlopen(req) as r:
print(r.status)
print(r.read(800).decode())What a record cannot tell you
Be honest in your own review about what is missing. A job record does not tell you which prompt in which chat triggered it, unless your agent wrote that into the request. If you need that link for an audit, put your session id in a field you control, and keep your client logs as long as you keep the ledger.
Two limits are worth stating plainly. Wallet admission is the real spend gate on Sume, and max_spend_usd is enforced only when you send it. A read-only OAuth session cannot call write tools at all, which is the cheapest control of the lot.
Short version
The roadmap is a signal that auditors will ask for these records. Sume already gives you the job, the receipt and the ledger. Start logging the link between them now.
Sources
Related posts
More in Developers
- RFC 9207 iss validation in the 2026-07-28 MCP spec, and Sume OAuth
The 2026-07-28 MCP spec adds RFC 9207 iss validation (SEP-2468). Sume's OAuth issuer is the MCP origin, so a client should expect mcp.sume.com and nothing else.
- MCP SEP-2352: credentials bound to issuer, re-register on a new host
MCP SEP-2352 binds client credentials to the issuer and deprecates DCR for Client ID Metadata Documents. Re-register if the Sume host changes.
- MCP subscriptions/listen and tasks versus Sume's pull-based job events
The 2026-07-28 MCP spec adds subscriptions/listen and a tasks extension. Sume has no SSE or WebSocket: poll job events, or use jobs_wait with a 55-second cap.
- MCP timeline_create provider_fields_not_accepted: no ffmpeg fields
Sume's timeline_create refuses model, filtergraph, ffmpeg_args, codec, preset and crf with provider_fields_not_accepted. Describe the edit, not the encoder.
Written by Sume