# Risk Tiers and Approvals — AI Agents and Tool Use

Source: https://www.geekswithgeeks.com/en/ai-agents-mcp/safety-risk-tiers

> Classify tools as read, write or destructive and require approval accordingly.

## Match friction to risk

Not every tool deserves the same care. **Read** tools can run freely. **Write** tools change state and often need logging or a confirmation. **Destructive or irreversible** tools (deleting data, sending money, emailing customers) should need explicit human approval. Unknown tools default to the strictest tier.

## Layers of defence

Assume mistakes and manipulation will happen, and limit what any single failure can do.

![Four layers: permissions, approvals, sandbox, monitoring.](assets/figures/ai-agents-mcp/section-5-map.svg) — Figure 5.1 — Permissions, approvals, sandbox and monitoring.

## An approval gate

This ran as shown. Reads pass; `send_payment` and the unknown tool both need approval, because unknown names fall to the strictest tier.

```python
RISK = {"get_balance": "read", "convert": "read",
        "send_payment": "write", "delete_account": "destructive"}

def needs_approval(name):
    return RISK.get(name, "destructive") != "read"

print([needs_approval(n) for n in ("get_balance", "send_payment", "unknown_tool")])
```

Output:

```
[False, True, True]
```

## Show the exact action

An approval prompt should show the tool and its real arguments ("send 5,000 INR to account 8841"), not a vague summary. People approve what they can see.

**Quiz:** How should an unknown tool be treated by default?

- [ ] As read-only
- [ ] As free to run
- [x] As the strictest tier needing approval
- [ ] Ignore the safety rules

*Answer:* As the strictest tier needing approval. Failing closed means a forgotten classification cannot silently allow a risky action.
