What may an AI agent do on its own?
As agents start to send, update and pay, the question moves from “what may we give the tool” to “what may the tool do for us”. Map every tool an agent has into three levels, using the risk labels the MCP standard defines.
Checking
Three levels
Each tool lands on one of them. The map writes them down as a policy, and as rules an agent can follow.
It reads, collects and prepares. Nothing changes for anyone else, so no one needs to watch each step.
An email to a customer, an update to the CRM, a meeting booked in someone’s calendar. The draft is ready; a person says yes.
Money, permissions, deletion, and anything signed or promised in the business’s name. The agent may get it ready; a person completes it.
The map reads the labels the MCP standard lets a server publish for each tool (read-only, destructive, open world) and what each tool’s name and description say it does. Where they disagree, it says so. It is a working checklist inspired by Article 14 of the EU AI Act, not legal advice.