WI-065 · Platform & Contracts · mcp-approval-actions

MCP proposal/approval & controlled actions (proposal+grant+automation-policy, policy evaluator, domain-mapped actions, bulk-as-frozen-plan, live e2e)

queued P2 medium risk   Owner: Paul   Reviewer: Mark Hilleary   0% · 0/1 tasks complete

Gates: P7 Requirements: Updated: 2026-06-22

At a glance

CodeWI-065
PhasePlatform & Contracts
Order26 of 93
Story points8
Primary surfaceMCP proposal/approval layer + controlled-action tools
Retires
Depends onGoverned MCP read/candidate surface (client registration, tool registry+schemas, permission-aware reads, P5 candidate tools, idempotency, audit, rate limits, injection safety)
Blocks
Evidence
queued (P7 approval)

Goals

Add the canonical-action governance to the MCP surface: immutable proposals, scoped/expiring approval grants (human surface or bounded automation policy, never agent self-approval), controlled-action tools mapped to existing P6 domain functions, and a proven live end-to-end.

Implementation — what to build

Build (approval)

  • action_proposal (immutable, hashed) + approval_grant (scoped/expiring/single-use) + automation_policy (bounded, default-off) contracts; policy evaluator + approval resolver; approval-decision outcomes.

Controlled actions

  • proposal + execute tools mapped to P6 functions (promote_inventory_candidate, publish_item/sale, append_inventory_status_event, bind/release identity, apply_disposition_action, notify_matched_buyers); bulk-as-frozen-plan; paid-research gating via P8.

Test

  • No proposal / no approval / wrong-proposal / expired / revoked / consumed / modified / stale-target; agent self-approval grants nothing; promotion + publication e2e with full proposal->approval->domain->plugin-event chain; idempotent replay.

Checklist

  • P7 MCP tool surface exposes read/search/candidate tools first, with approval gates on publish/bulk/delete tools, wrapping existing ingestion functions.

Gates & testing

  • P7 MCP tool surface exposes read/search/candidate tools first, with approval gates on publish/bulk/delete tools, wrapping existing ingestion functions.
    CODE TEST HITL QA

Requirements

No linked requirements.

Verify (done when)

Controlled action tools produce/reference immutable proposals (hash covers targets+versions+changes); approval grants are scoped/expiring/single-use, issued only by an approved human surface or a bounded automation policy (agent cannot self-approve); actions call P6 domain functions (promote/publish/status/bind/disposition) — no parallel writers; bulk operates on a frozen target snapshot that can't expand post-approval; publication/notifications/paid-research not auto-approved by default (paid routes through P8 budget); idempotent execution; live MCP client e2e (blocked-without-approval -> approved promotion + publication). Per spec section 14-19, 41, 44 (action rows).

Cost triggers

No paid API / infra spend triggered by this item.

Status & editing

queued   Sprint: P&C Wave 4: Data & Surfaces

Edit status / sprint on the ★ Live Board → — changes are logged live with who / when / why.

Human-in-the-loop

No human tasks linked.

Findings

None recorded yet.

Concerns

None recorded yet.

Risks

None recorded yet.

Tech debt

None recorded yet.

Tools used

No tool calls recorded.

Files & artifacts

No files / artifacts recorded.

Update log

No log entries yet.