{"schemaVersion":"maha-epistemic/1.0","evidencePolicyVersion":"mps/0.1","recordId":"urn:maha:record:agentic-systems-mcp-tool-deny-by-default","canonicalPath":"/knowledge/agentic-systems-mcp/concepts/agentic-systems-mcp-human-denial-control-for-tool-invocations","contentHash":"sha256:fb08cfa074d0a89224e0050ea660ef99110e42e5faf48ee9fc425bbc598e6444","generatedAt":"2026-08-27T15:27:02.023Z","publicationDecision":{"recordId":"urn:maha:record:agentic-systems-mcp-tool-deny-by-default","publicEligible":true,"evaluatedAgainst":"maha-epistemic/1.0","reasons":[]},"claims":[{"id":"urn:maha:claim:agentic-systems-mcp-tool-deny-by-default","scope":"Limited to the User Interaction Model warning and the Security Considerations list on the Tools page of the Model Context Protocol specification, version 2024-11-05. It records what the specification recommends to implementors and does not describe any organisation’s allowlist, identity, retention, or approval policy.","boundary":"A recommendation addressed to implementors is not a protocol requirement, is not evidence that any deployed system denies tools by default, and establishes no system-level performance, safety, scalability, economic advantage, or deployment readiness.","claimKind":"empirical-claim","sourceIds":["source-agentic-systems-mcp-mcp-core"],"statement":"The Model Context Protocol specification recommends, as a normative SHOULD for implementors rather than a protocol mandate, that a human remain in the loop with the ability to deny tool invocations, and states that the protocol itself does not mandate any specific user interaction model.","replication":{"asOfDate":"2026-08-24","assessment":"Independent replication and cross-platform transfer have not been compiled for this candidate; the evidence maturity refers only to the bounded source contract.","independentReplicationCount":null},"uncertainty":{"kind":"qualitative","statement":"No cross-source quantitative interval is asserted. Definitions, operating conditions, samples, instruments, and outcome measures must be checked against the exact cited locator during review."},"evidenceMaturity":"single-study"}],"sources":[{"id":"source-agentic-systems-mcp-mcp-core","url":"https://modelcontextprotocol.io/specification/2024-11-05/server/tools","title":"Model Context Protocol specification","rights":{"note":"The candidate uses original boundary language and a short paraphrase linked to the cited source. No source passage, figure, or table is reproduced.","basis":"citation-with-paraphrase","quotationUsed":false},"authors":["Model Context Protocol contributors"],"boundary":"The specification recommends implementor behaviour and mandates server-side input validation and access control. It does not prescribe an organisation’s allowlist, identity, retention, or approval policy, and it expressly does not mandate a user interaction model.","publisher":"Model Context Protocol","establishes":"The Tools page states that for trust, safety and security there SHOULD always be a human in the loop with the ability to deny tool invocations, that the protocol itself does not mandate any specific user interaction model, that servers MUST implement proper access controls and validate tool inputs, and that clients SHOULD prompt for user confirmation on sensitive operations.","identifiers":[{"value":"https://modelcontextprotocol.io/specification/2024-11-05/index","scheme":"url"}],"publishedAt":"2024-11-05","exactLocator":"Tools page, version 2024-11-05: the \"User Interaction Model\" warning block and the \"Security Considerations\" list."}],"reviewEvents":[{"scope":"source-fidelity","verdict":"approve","reviewId":"epireview_26690d6ae09e4fefa4152b86397658fe","rationale":"The cited artifact is the Model Context Protocol specification at version 2024-11-05, and the record's source title names that artifact rather than a single page. The stable identifier resolves to the version root while the url resolves to the Tools page inside it, which is coherent citation practice: identify the artifact, locate within it. The establishes statement reproduces four distinct specification statements and overstates none of them. The claim asserts exactly two things the page states: a normative SHOULD addressed to implementors that a human remain able to deny tool invocations, and an express statement that the protocol does not mandate any specific user interaction model. It converts neither into a MUST, and it attributes the recommendation to implementors rather than to the protocol. The claim boundary then removes the three readings the evidence cannot carry.","reviewedAt":"2026-08-27T15:26:56.614Z","reviewerId":"expert_maha-internal-repaired-v1","reviewMethod":"Exact-revision internal editorial review derived from the preserved ten-dimension decision ledger after source-alignment and citation-identity audits. No external endorsement is claimed.","reviewerKind":"internal-editorial","reviewerRole":"Publisher-operated source-fidelity and epistemic-boundary checklist","targetSha256":"sha256:bc3682ef4b4613b4cff9c468953c218fb20ebad8786ab8c6cc4bbcc8dccb1a66","supersedesReviewId":null,"reviewerProfileVersion":1},{"scope":"domain-fidelity","verdict":"approve","reviewId":"epireview_8c5f1239ba7748eeb01fc0de23ef610c","rationale":"The record stays inside agentic systems and MCP, describing a protocol specification's guidance to implementors. It does not migrate into organisational security policy, into zero-trust architecture, or into any claim about a named runtime's behaviour. The scope sentence explicitly disclaims describing an organisation's allowlist, identity, retention, or approval policy. Concept is correct. The artifact defines a recommended control and reports no comparison between exposure postures, so comparison is unavailable; it reports no measured quantity, so measurement is unavailable; and it prescribes no procedure for the reader to execute, so method would overstate. Concept records the bounded existence and force of the recommendation, which is what the page supports.","reviewedAt":"2026-08-27T15:26:56.956Z","reviewerId":"expert_maha-internal-repaired-v1","reviewMethod":"Exact-revision internal editorial review derived from the preserved ten-dimension decision ledger after source-alignment and citation-identity audits. No external endorsement is claimed.","reviewerKind":"internal-editorial","reviewerRole":"Publisher-operated source-fidelity and epistemic-boundary checklist","targetSha256":"sha256:bc3682ef4b4613b4cff9c468953c218fb20ebad8786ab8c6cc4bbcc8dccb1a66","supersedesReviewId":null,"reviewerProfileVersion":1},{"scope":"boundary-adequacy","verdict":"approve","reviewId":"epireview_4821fb7925d34bb7a45177a0a2faef6e","rationale":"Uncertainty is declared qualitative, which is right: the page states a recommendation and asserts no interval, rate, or measurement, so a quantitative interval would be fabricated. The replication assessment records that independent replication and cross-platform transfer have not been compiled, and the audit records independentlyReproduced and externallyReviewed as false. Three prohibitions are carried, and the third is the one this record specifically needs: do not read a recommended human ability to deny an invocation as a requirement that tools be denied unless explicitly permitted. That closes precisely the overclaim the superseded record made. The general prohibitions on proven, safe, scalable and commercially available readings are also retained. Read as a public page, the wording cannot be mistaken for a security mandate. It says \"recommends\", names SHOULD explicitly, attributes the recommendation to implementors, and states in the same sentence that the protocol does not mandate a user interaction model. The honest negations survive in the boundaries and prohibited inferences rather than being trimmed for readability.","reviewedAt":"2026-08-27T15:26:57.264Z","reviewerId":"expert_maha-internal-repaired-v1","reviewMethod":"Exact-revision internal editorial review derived from the preserved ten-dimension decision ledger after source-alignment and citation-identity audits. No external endorsement is claimed.","reviewerKind":"internal-editorial","reviewerRole":"Publisher-operated source-fidelity and epistemic-boundary checklist","targetSha256":"sha256:bc3682ef4b4613b4cff9c468953c218fb20ebad8786ab8c6cc4bbcc8dccb1a66","supersedesReviewId":null,"reviewerProfileVersion":1},{"scope":"rights-and-locator","verdict":"approve","reviewId":"epireview_34570f9986854301af021227651f35a8","rationale":"The locator names the \"User Interaction Model\" warning block and the \"Security Considerations\" list on the Tools page of version 2024-11-05. Both headings exist verbatim on the inspected page, and both carry the exact language the claim relies on. The locator is section-level, not whole-document, so a reader can reach the supporting text directly. citation-with-paraphrase against a publicly served specification page. The record reproduces no block of specification prose, no schema, and no diagram; the establishes statement and the claim are original paraphrase. The normative keyword SHOULD is reproduced as a single word because its capitalisation carries the meaning, which is fair citation rather than reproduction.","reviewedAt":"2026-08-27T15:26:57.478Z","reviewerId":"expert_maha-internal-repaired-v1","reviewMethod":"Exact-revision internal editorial review derived from the preserved ten-dimension decision ledger after source-alignment and citation-identity audits. No external endorsement is claimed.","reviewerKind":"internal-editorial","reviewerRole":"Publisher-operated source-fidelity and epistemic-boundary checklist","targetSha256":"sha256:bc3682ef4b4613b4cff9c468953c218fb20ebad8786ab8c6cc4bbcc8dccb1a66","supersedesReviewId":null,"reviewerProfileVersion":1}]}