MCP tool policy

MCP Tool Policy

Create MCP tool policy that decides which tools are allowed, require approval, or are blocked for each task.

Policy is the difference between a useful router and a dangerous pass-through. Teams need a clear rule for every selected tool.

Practical workflow

  1. Start with read tools allowed by default.
  2. Ask for write, open-world browser, external-message, and database tools.
  3. Block explicitly disallowed tools or servers.
  4. Review policy drift as new tools appear.

How ToolBudget Router helps

ToolBudget Router shows the policy decision beside every selected tool and includes it in the exportable budget report.

View MCP examples