Skip to content

Plan MCP permissions

Where does your server run, what may it do, and which content will it read? Build a checklist for your first bounded test.

This is a planning aid, not a security scan. No server is contacted and no credentials are needed. The result describes checks for you to carry out.

Three layers of access

Account and data source
Which repositories, files or records can the account actually reach?
Server and tools
Which operations does the server expose, and which limits does it enforce?
Client and approval
Which calls require your review before they run?

A label in one layer does not establish the limits of another. Record all three in your test plan.

tracevero · https://tracevero.com/werkzeuge/zugriffsplan