# Least Privilege for Tools and MCP Servers — OpenAI Agent Builder Workflows

Source: https://www.skillbyai.com/en/openai-agent-builder/s-perm

> Limit what an agent can do, not only what it says.

## Scope, approve, log

The damage an agent can do is bounded by its **tools**. Give each agent the smallest set of tools, use credentials with the **narrowest permissions** (read-only where possible), restrict MCP servers to the tools the workflow needs, and require **approval** for actions that write, send, pay or delete. Log every tool call with its parameters and result. Review third-party MCP servers like any dependency: who maintains it, what data it sees, and what it can do.

## A tool permission review

Fill one row per tool.

```text
tool                 access        approval needed   data exposed
get_order_status     read          no                order id, status
issue_refund         write, money  yes (> 100)        order, amount
send_email           external      yes                customer email
crm (MCP server)     read only     no                 name, plan
file search          read          no                 public policy docs
```

## Separate read and write tools

Split update_order into get_order and change_order so most agents only receive the read tool.

**Quiz:** Which action should usually require approval?

- [x] Issuing a refund or sending an external email
- [ ] Reading a public FAQ
- [ ] Looking up order status
- [ ] Formatting a reply

*Answer:* Issuing a refund or sending an external email. Gate actions that change the world.
