Terms used precisely, or not at all.
Plain definitions for the words used on this site. Each one says what the term is — and, as often, what it is not.
The state a person puts an agent in: allowed to make specific calls inside one session, and nothing more. Authorization never widens on its own.
A person saying yes to one specific call, as opposed to a rule that runs automatically.
An approval covers one call, not a categoryThe account an agent acts as inside a connected app. Different identities reach different tools.
App updates can never widen accessThe record written around a call: an intent before dispatch, a receipt after. A call that cannot be recorded does not run.
No record, no callThe window an agent works inside: a set of tools and a clock, opened by a person and scoped to one organization.
One connection, one approvalThe session-specific permission issued from a profile when a session opens: exact identities, exact tools, a fixed duration.
The controls wrapped around an MCP connection — scoped grants, guardrails, approvals, and receipts — as distinct from simply running an MCP server.
The rule that a session's access can shrink mid-session but never silently grow.
A permission set never grants access by itselfA reusable starting point: which identities, which tools, how long. It grants nothing by itself.
A permission set never grants access by itselfA versioned record of a connector's tool list. An update changes nothing an agent can reach until a person reviews the new snapshot.
App updates can never widen accessNo terms match that filter.
Where to go next
Two readers, two different next steps.