Alexander Groman
Contributing Writer, Explore Agentic
About Alexander
Alexander writes the implementation side of the Model Context Protocol: the MCP pillar, the MCP glossary entry, and the MCP gateway vendor-selection guide. The material is the spec and what production does to it — Anthropic's November 2024 release, the move to the Linux Foundation, mandatory PKCE, Client ID Metadata Documents, and the March 2026 revision that made RFC 8707 resource indicators mandatory so a token minted for one server cannot be replayed against another.
The gateway auth work covers the everyday failures: repeated logins, mid-task token expiry, lost context after consent, and the elicitation, silent-refresh, and deep-link-resume patterns that fix them. Security runs parallel, with a hardening checklist that treats every tool-calling agent as a confused deputy holding real credentials — prompt injection, tool poisoning, token replay — plus the AWS Agentic AI Security Scoping Matrix mapped to NIST AI RMF and ISO 42001 controls. Cost is the third thread: prompt caching on Bedrock and the Anthropic API, and what MCP tool definitions do to a context window.
Pieces written or reviewed by Alexander
19 pieces across 4 formats on this site — 10 written by Alexander and 9 reviewed. A written byline means Alexander researched and drafted the piece; a reviewed byline means Alexander read it against its cited sources and could defend its claims before it published. Every row below is labelled either way.
- Pillar · Written Model Context Protocol, sixteen months in
- Glossary · Written Model Context Protocol (MCP)
- Comparison · Reviewed MCP vs RAG: two protocols for two different problems
- Comparison · Written Glean vs Microsoft 365 Copilot: the bundled-vs-federated question
- Insight · Written Prompt Caching on Bedrock and the Anthropic API: The Cost Lever That Actually Moves Agent Bills
- Insight · Reviewed AI-DLC Explained: What AWS's AI-Driven Development Lifecycle Changes — and What It Breaks in Your Governance Model
- Insight · Written The AWS Agentic AI Security Scoping Matrix, Mapped to Controls You Can Actually Deploy
- Insight · Reviewed Claude for Enterprise: The Three Buying Paths (Anthropic API, Amazon Bedrock, Team/Enterprise Seats) and What Each Really Costs
- Insight · Written Claude on Amazon Bedrock: The Token Economics of Agentic Workloads
- Insight · Written What I Learned About Using MCP Tools Without Burning Money or Getting Bad Answers
- Insight · Written Glean FlexCredits, explained: how Enterprise Flex meters agent actions and what a credit actually costs
- Insight · Reviewed Glean Skills and Adaptive Reasoning: is the "enterprise AI coworker" an agent runtime, a workflow runner, or a relabel?
- Insight · Reviewed AWS AgentCore vs Azure AI Foundry: Lessons from Shipping MCP Servers and Agents on Both Clouds
- Insight · Written When MCP Gateway Auth Breaks: Practical Patterns for a Developer-Friendly Experience
- Insight · Written MCP Server Security: The Threat Model and a Hardening Checklist for Tool-Calling Agents
- Insight · Reviewed Multi-Agent Orchestration Patterns: Supervisor, Swarm, and Pipeline
- Insight · Reviewed Building an Eligibility-Verification Agent on MCP: A Reference Architecture from Clearinghouse API to Audit Log
- Insight · Reviewed Best MCP Gateways in 2026: Ten Scored Criteria and Five Disqualifiers
- Insight · Reviewed Agent Gateway vs. API Gateway: What Your Existing Gateway Cannot Enforce
Other contributors
- Ryo HangEditor-in-Chief
- Kelvin YuContributing Writer
- Soraya ZhengContributing Writer
- Cynthia ZhangContributing Writer
- Tommy TaoContributing Writer
- Chandler BensonContributing Writer
- Elias SaljukiContributing Editor
- Ginny CasuccioContributing Editor
- Gloria Qian ZhangContributing Editor
- Laura Bradley McCoyContributing Writer
- Merve TengizContributing Editor
- Michael CloughEditorial Advisor