Which operations need approval?
Read-only tools execute after access checks. Write and unclassified tools require approval for each operation. Permission to request writes only allows your client to submit a request.
1. Submit the exact operation
Ask your agent to specify the resource, complete arguments, and intended change. If the result contains approval_pending, approval_id, and approval_url, the operation has not executed. Keep the ID and open the returned link.
2. Have an authorized reviewer confirm it
- Check the requester, target service, and resource.
- Review all arguments and any available preview.
- Complete required step-up authentication, then approve or reject.
- If two reviewers are required, two different authorized people must review independently.
The requester may not have approval permission and may need to give the link to a designated reviewer. Approvals expire. If no reviewer is available, authentication requirements are unmet, or the request expired, contact your administrator or submit a new request as directed.
3. Resume from the original client
After approval, the original client calls mcphub_resume_approval with:
{ "approval_id": "the actual returned approval ID" }
Approval does not execute the operation automatically. Do not use a different client entry or a replacement grant to resume the original request. If authorization became invalid, confirm business status first and follow your administrator's guidance.
Check status or cancel
| Action | Tool |
|---|---|
| Check status | mcphub_approval_status |
| Cancel before execution | mcphub_cancel_approval |
| Resume after approval | mcphub_resume_approval |
Each uses the original approval_id. If current tools and permissions allow it and the administrator configured a read-only status tool, add query_upstream: true to check the business system. This option is unavailable without that configuration.
Timeouts or uncertain results
Check approval and business status first, then give your administrator the approval ID, request ID, and time. Do not repeatedly create or resume the same write. Cancellation and revocation cannot undo a write already accepted upstream.
If resource versions, configuration, or permissions changed, check the target and arguments again and request approval as directed. Undo business results through the business system's formal rollback process.