Define the user intent
Owner role · Administrator
Evidence: The approved operation is a task-context read, not creation/update.
Illustrative case: an operator wants an agent to summarize tasks only, but the server exposes creation and update tools.
| Boundary | Evidence needed | Decision if missing |
|---|---|---|
| User intent | Specific read purpose and workspace | No extra writes implied |
| Client exposure | Only needed tools selected where supported | Do not treat selection as server enforcement |
| Server boundary | Deployment-specific enforcement evidence | Do not claim a verified read-only guarantee |
Owner role · Administrator
Evidence: The approved operation is a task-context read, not creation/update.
Owner role · Operator
Evidence: Available and selected tools are checked against that purpose.
Owner role · Product operator
Evidence: The actual deployed permission boundary is tested rather than inferred from token scopes.
Decision to make: Bound the requested workflow to reads and verify server enforcement before claiming writes are impossible.
Invented planning text. Adapt it to your evidence and confirmed owners.
The illustrative read-only request needs a task summary, while the source server exposes both reads and writes. The reviewer restricts the requested operations and records that token write-scope enforcement has not been established. A workflow instruction is therefore not presented as a server-enforced security boundary.
The inspected source does not establish that guarantee; write guards remain pending.
No. Use only the context tools needed by the bounded workflow.
No. The brief is a manual planning resource. Use the product access link to check onboarding and the workflows available in your account.
From a useful outline to team work
Review the source-backed TeamBoost MCP guard limitations and actual workspace authority before permitting writes; a token label alone is insufficient. Confirm the workflows available in your account before adopting this outline.
Opens the current invite-request page. Access is subject to approval; this example is not imported automatically.