Guardrails for Agentic Sitecore: What to Do Before You Let an Agent Near a CM Instance
Part 3 of the Agentic Sitecore series Previously on the blog: MCP‑Powered AI Development Workflow in Sitecore XM Cloud introduced why Model Context Protocol matters for XM Cloud. From Prompt to Production: Agentic Sitecore Workflows with MCP walked through two working setups — Marketer MCP and the open-source community server — that take a single prompt from "create this page" to a published route on Experience Edge. Both posts end at the same place: it works. This one starts from a different question, which is the one that actually comes up once a working demo turns into something a team uses every week — what has to be true before this is allowed to run against something you'd mind losing? The demo in the March post is safe by construction: one page, one component, one publish, a non-production tenant, and a person reading every response before the next prompt goes in. None of those conditions survive contact with real usage. Someone will eventually ...