Skip to content
MCP Permissions·2 min·English

Check permissions before you connect an MCP

A short checklist that separates read, propose, write and outbound action before an agent touches a real system.

Check permissions before you connect an MCP

What you get

A permissions check before you connect a tool to a live system

Who it is for

For anyone connecting agents to WhatsApp, customers, a database, payments, or any system with real damage on the line.

1. Map the tool

  • Which tool is connected.
  • Which system it touches.
  • What it can read.
  • What it can change.
  • Which action goes outside, to a customer or to money.

2. Four levels of action

  • Reads: sees information only.
  • Proposes: prepares a draft or a recommendation.
  • Writes: changes an internal system.
  • Acts outward: sends, deletes, charges, publishes, or reaches a customer.

3. Approval rules

  • Reading is allowed only inside the scope of the task.
  • Writing needs before-and-after evidence.
  • An outward action needs the text, the destination, and explicit approval.
  • Money and deletion always stop for a human.

4. Check template

Copy box
Tool: [tool name]
System: [what it connects to]

Allowed to read:
- [sources]

Allowed to propose:
- [drafts / recommendations]

Allowed to write:
- [only if approved]

Forbidden without approval:
- sending to a customer
- deletion
- charging
- changing permissions
- publishing

Completion check:
- show what changed
- show how to roll back

How to use this now

A good MCP connection is not a wide one. It is a predictable one.

AI-native products, workshops, and automations. Built from everywhere.

© 2026 Daniel Goldman