Their release notes are not your permission change.
Apps ship updates on their own schedule. When one adds a tool, changes what a tool does, or drops one, that lands here as something to review — not as an agent that can suddenly do more than it could yesterday.
What happens to each tool when an update lands
The rule is the same every time: nothing widens without a person.
New tool
Nobody can pick it until an admin allows it.
Tool changed
It stops working until someone confirms the new behaviour.
Tool removed
It stops immediately — no silent failures.
Unchanged
Keeps working right through the review.
The description is part of the tool
An agent decides what to call based on what a tool says about itself. So a rewritten description is a behaviour change, not a typo fix — and it pauses the tool exactly like a changed input would. Nobody edits the instructions your agents read without going past a person first.
Same app, different reach
A connected app can be reached as more than one login, and each login carries its own list of allowed tools. A read-only support login and a write-capable escalation login are not the same thing, even though they point at the same app.
Every change goes through review — including the boring ones
Not the first change. Every change. A tool list is checked against the approved one on a schedule and on demand, and any difference re-enters review — even a version whose tools turn out to be identical. A review you can skip is not a control.
Checked without being asked
Every connected app is re-checked hourly, and on demand whenever you want to know now.
You see the difference, not a notice
What was approved, what arrived, and which tools each state applies to — side by side.
Approval is bound to a version
A session is bound to the exact approved list. A later change cannot reach into a session that is already open.
Where to go next
Two readers, two different next steps.