New One-call approvals are live in the console
Rollout

A rollout that survives its own security review.

Adopting MCP is usually the easy part. Making it defensible — to a reviewer, six months later, about a call nobody remembers — is the part that fails. This is the order that works.

01 Rollout order

The order, in four steps

Each step earns the next one. Widen only when the last conversation was boring.

01 · Qualify the supply

Connect one app. Review the tools it offers. Decide which tools are reachable at all before anyone can select them.

02 · Group the permissions

Write permission sets for the two or three real jobs. Keep them narrow enough that consent is a formality, not a negotiation.

03 · Set the rules

Deny destructive tools outright. Route writes and money movement to a named approver. Leave reads alone.

04 · Prove it before you scale

Pull a week of receipts and walk them with your security reviewer. Widen only once that conversation is boring.

02 Chain of command

One call, end to end

The same seven stages apply no matter which client made the request.

Someone asks
Permission set
Login
Tool
Rules
Outcome
Receipt
01 Someone asksA person asks an agent to do something, starting from a permission set.
Next step

Where to go next

Two readers, two different next steps.

Start here

Free is open at no cost: 3 members, 2 connected apps, 7 days of history.

Everyone else

Start with the words: permission set, session, approved tool list, receipt.