Approvals
10 min read
How to require human approval for MCP tool calls
Where to put the approval gate for MCP tool calls, what Claude Code and Cursor can do natively, and how a shared Ask holds the real call for a person.
Read articleApprovals
10 min read
Where to put the approval gate for MCP tool calls, what Claude Code and Cursor can do natively, and how a shared Ask holds the real call for a person.
Read articlePolicy
10 min read
A method and a starter policy matrix for MCP tool permissions, using real Linear, GitHub and Postgres tools, including the ones a name cannot classify.
Read articleArchitecture
9 min read
An MCP gateway is one endpoint between agents and the servers they would call directly. What the spec says about proxies, and when direct is enough.
Read articleData access
8 min read
Read-only MCP access stops writes, not disclosure. Two 2025 incidents, read-only in GitHub, Linear, Supabase and Postgres, and when a read needs an Ask.
Read articleWorkflows
7 min read
Linear read-only MCP options, the real tool names, Claude Code and Cursor rules for read-then-approve, and a shared policy that holds each write.
Read articleAgent access
11 min read
Follow one MCP tool call through the four decisions that can stop it: OAuth sign-in, token scopes, tool policy, and a human's yes. Each fails differently.
Read article