/tools · agent oversight

What may an AI agent do on its own?

As agents start to send, update and pay, the question moves from “what may we give the tool” to “what may the tool do for us”. Map every tool an agent has into three levels, using the risk labels the MCP standard defines.

We read the server’s public tool list only. No tool is ever called.

Three levels

Each tool lands on one of them. The map writes them down as a policy, and as rules an agent can follow.

The agent acts alone

It reads, collects and prepares. Nothing changes for anyone else, so no one needs to watch each step.

The agent prepares, a person approves

An email to a customer, an update to the CRM, a meeting booked in someone’s calendar. The draft is ready; a person says yes.

A person does it

Money, permissions, deletion, and anything signed or promised in the business’s name. The agent may get it ready; a person completes it.

The map reads the labels the MCP standard lets a server publish for each tool (read-only, destructive, open world) and what each tool’s name and description say it does. Where they disagree, it says so. It is a working checklist inspired by Article 14 of the EU AI Act, not legal advice.