published-canonicalconceptmaha-epistemic/1.0

Human denial control for tool invocations

Tool deny by default is represented as one reviewable unit in the Agentic systems and MCP graph. Its source, locator, scope, uncertainty, and prohibited inference remain attached to the claim rather than being generalized across the domain.

Bounded definition

A source-bounded concept record for the human denial control the Model Context Protocol recommends for tool invocations, within agentic systems and MCP.

What the cited work establishes

The specification defines client, server, and host roles and capability-negotiated protocol primitives.

Limited to Architecture, lifecycle, capabilities, resources, prompts, and security sections. in “Model Context Protocol specification”; this candidate records the concept boundary and does not pool results from uncited systems or studies.

Claims: urn:maha:claim:agentic-systems-mcp-tool-deny-by-default

What remains a separate question

Tool deny by default does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.

A protocol primitive does not prescribe an organization’s allowlist, identity, retention, or approval policy.

Claim ledger

Every proposition keeps its own evidence state.

empirical-claimsingle-study

The Model Context Protocol specification recommends, as a normative SHOULD for implementors rather than a protocol mandate, that a human remain in the loop with the ability to deny tool invocations, and states that the protocol itself does not mandate any specific user interaction model.

Scope
Limited to the User Interaction Model warning and the Security Considerations list on the Tools page of the Model Context Protocol specification, version 2024-11-05. It records what the specification recommends to implementors and does not describe any organisation’s allowlist, identity, retention, or approval policy.
Boundary
A recommendation addressed to implementors is not a protocol requirement, is not evidence that any deployed system denies tools by default, and establishes no system-level performance, safety, scalability, economic advantage, or deployment readiness.
Uncertainty
No cross-source quantitative interval is asserted. Definitions, operating conditions, samples, instruments, and outcome measures must be checked against the exact cited locator during review.
Replication
Independent replication and cross-platform transfer have not been compiled for this candidate; the evidence maturity refers only to the bounded source contract.

Primary sources

Citation, locator, rights, and boundary travel together.

  1. Source 1 · Model Context Protocol

    Model Context Protocol specification

    Model Context Protocol contributors

    Exact locator
    Tools page, version 2024-11-05: the "User Interaction Model" warning block and the "Security Considerations" list.
    Establishes
    The Tools page states that for trust, safety and security there SHOULD always be a human in the loop with the ability to deny tool invocations, that the protocol itself does not mandate any specific user interaction model, that servers MUST implement proper access controls and validate tool inputs, and that clients SHOULD prompt for user confirmation on sensitive operations.
    Boundary
    The specification recommends implementor behaviour and mandates server-side input validation and access control. It does not prescribe an organisation’s allowlist, identity, retention, or approval policy, and it expressly does not mandate a user interaction model.
    Rights basis
    citation with paraphrase · The candidate uses original boundary language and a short paraphrase linked to the cited source. No source passage, figure, or table is reproduced.