Plan MCP permissions
Where does your server run, what may it do, and which content will it read? Build a checklist for your first bounded test.
This is a planning aid, not a security scan. No server is contacted and no credentials are needed. The result describes checks for you to carry out.
Three layers of access
- Account and data source
- Which repositories, files or records can the account actually reach?
- Server and tools
- Which operations does the server expose, and which limits does it enforce?
- Client and approval
- Which calls require your review before they run?
A label in one layer does not establish the limits of another. Record all three in your test plan.
tracevero · https://tracevero.com/werkzeuge/zugriffsplan