All guidesMCP
MCP Permissions·2 min·English
Check permissions before you connect an MCP
A short checklist that separates read, propose, write and outbound action before an agent touches a real system.

What you get
A permissions check before you connect a tool to a live system
Who it is for
For anyone connecting agents to WhatsApp, customers, a database, payments, or any system with real damage on the line.
1. Map the tool
- Which tool is connected.
- Which system it touches.
- What it can read.
- What it can change.
- Which action goes outside, to a customer or to money.
2. Four levels of action
- Reads: sees information only.
- Proposes: prepares a draft or a recommendation.
- Writes: changes an internal system.
- Acts outward: sends, deletes, charges, publishes, or reaches a customer.
3. Approval rules
- Reading is allowed only inside the scope of the task.
- Writing needs before-and-after evidence.
- An outward action needs the text, the destination, and explicit approval.
- Money and deletion always stop for a human.
4. Check template
Copy box
Tool: [tool name]
System: [what it connects to]
Allowed to read:
- [sources]
Allowed to propose:
- [drafts / recommendations]
Allowed to write:
- [only if approved]
Forbidden without approval:
- sending to a customer
- deletion
- charging
- changing permissions
- publishing
Completion check:
- show what changed
- show how to roll backHow to use this now
A good MCP connection is not a wide one. It is a predictable one.