Permissions

Answering a permission request

You want to know exactly what the person using your application will be asked when an agent reaches for your tools, and what each answer does. There are two questions; here is every answer to both.

Two questions

  • The site-permission question comes first, when an agent in a chat first wants a site’s tools. It decides whether the agent may use the site’s tools at all, and how far.
  • The per-call confirmation comes when the agent calls a tool whose class is above what the person allowed. It is about that one call.

Both appear in the chat as a card, with the narrowest answer on the button’s face and wider answers behind its arrow; refusals sit to the right, laid out the same way.

The site-permission question

A permission card in the chat. It reads: An agent wants permission to use this site's page tools on xataworks.ca. Let the agent see and call the tools this website publishes to it. Requested by browser_list_webmcp_tools, in the tab “Hello, WebMCP” at http://xataworks.ca/developers/examples/hello/. Allowing this applies to xataworks.ca only. Under “What this site publishes”: say_hello, Read only. Buttons: Allow this call only and Deny this call, each with an arrow.
It names the site, what asked, from which tab, and every tool the site publishes with its class. (Captured from a local copy of this site, hence http://.)

Opening the arrow beside Allow this call only:

The same card with its approval menu open, listing three answers: Allow read-only tools on this website; Allow non-consequential read/write tools on this website; Allow all tools on this website.
The three wider answers: one per class.
Allow this call only
This call runs. Nothing is recorded, so the agent’s next call to the site asks again.
Allow read-only tools on this website
The agent may use the site’s tools, and read-only ones run without asking. Anything that changes things is confirmed per call.
Allow non-consequential read/write tools on this website
Read-only and mutating tools run without asking. Consequential ones are confirmed per call.
Allow all tools on this website
Every tool on the site runs without asking, consequential ones included. The only answer that turns per-call confirmation off.

And the arrow beside Deny this call:

The same card with its refusal menu open, showing one further answer: Deny for this chat.
Refusals are laid out like approvals, so the width of a “no” is as visible as the width of a “yes”.
Deny this call
This call is refused. Nothing is recorded.
Deny for this chat
This chat refuses the site; later calls to its tools are refused without asking.

Closing the card without answering counts as Deny for this chat. How long the recorded answers last, and who else they apply to, is how long an answer lasts.

The per-call confirmation

This one came from the Notes example, with the site allowed non-consequential read/write tools and the agent calling delete_note, which is consequential:

A confirmation card: delete_note [Consequential]; 1 argument, title: Old draft; a folded “What this site publishes”; buttons Allow this call only and Deny this call, each with an arrow.
The tool, its class, and the arguments it would run with.
The confirmation card with its approval menu open: Always allow “delete_note” on xataworks.ca; Allow all tools on xataworks.ca.
The wider approvals: this tool from now on, or every tool of its class and below.
Allow this call only
This call runs. Nothing is recorded.
Always allow “delete_note” on xataworks.ca
This tool runs without asking from now on, in this chat. Other consequential tools on the site are still confirmed.
Allow all tools on xataworks.ca
Widens what the site may do to this tool’s class and everything below it. For a mutating tool the answer reads Allow non-consequential read/write tools on … instead.
The confirmation card with its refusal menu open: Never allow “delete_note” on xataworks.ca; Deny all page tools on xataworks.ca.
The wider refusals: this tool, or the whole site.
Deny this call
This call is refused. Nothing is recorded.
Never allow “delete_note” on xataworks.ca
This tool is refused without asking until XataWorks is restarted.
Deny all page tools on xataworks.ca
Refuses the site altogether and withdraws whatever the chat had allowed it.

What the answers add up to

After answering the site question with…Read-only toolsMutating toolsConsequential tools
Allow read-only toolsRunConfirmed per callConfirmed per call
Allow non-consequential read/write toolsRunRunConfirmed per call
Allow all toolsRunRunRun

This is why honest hints matter to you as much as to the person: a lookup you forgot to mark read-only is confirmed every time for anyone who allowed read-only tools, and they will reasonably wonder why your application keeps asking.

Testing locally

Pages on localhost, 127.0.0.1 or ::1 are never asked the site-permission question, and the site-wide refusal is not offered for them. To see what your users will see, test on a real host name — or try it now on the hosted Notes example.