# Least Privilege, Allow-Lists and Human Approval — MCP & Agent-to-Agent Protocols

Source: https://www.geekswithgeeks.com/en/mcp-a2a/s-privilege

> Enforce policy in the host, outside the model.

## The model proposes, code decides

Never rely on the model alone to enforce rules. Put a **policy layer in the host** between "the model wants to call X" and "X runs": an **allow-list** of tools, **argument checks** (ranges, patterns, allowed hosts and folders), **risk levels** with **human approval** for writes, deletes, payments and external messages, **rate and cost limits**, and an **audit log** of every call. Give each server only the **credentials and scopes** it needs, prefer **read-only** tools, and use separate servers or accounts for risky powers. Show the user exactly what will happen ("Send email to X with body Y?"), not a vague summary.

## A policy layer, run

I ran this with plain Python 3 (standard library only). Reads pass. An unknown tool is refused. A refund needs approval; once approved it is allowed within the 0 to 5000 range, and an approved 90,000 refund is still blocked by the argument check.

```python
ALLOWED = {
    "get_order_status": {"risk": "read",  "approval": False},
    "propose_refund":   {"risk": "write", "approval": True},
}

def authorize(tool, args, approved=False):
    spec = ALLOWED.get(tool)
    if spec is None:
        return False, "tool not on the allow-list"
    if spec["approval"] and not approved:
        return False, "needs human approval"
    if tool == "propose_refund" and not (0 < args.get("amount", 0) <= 5000):
        return False, "amount out of policy range"
    return True, "ok"

for call in [("get_order_status", {"order_id": "481516"}, False),
             ("delete_all", {}, False),
             ("propose_refund", {"amount": 300}, False),
             ("propose_refund", {"amount": 300}, True),
             ("propose_refund", {"amount": 90000}, True)]:
    print(call[0], call[1], "->", authorize(*call))

```

Output:

```
get_order_status {'order_id': '481516'} -> (True, 'ok')
delete_all {} -> (False, 'tool not on the allow-list')
propose_refund {'amount': 300} -> (False, 'needs human approval')
propose_refund {'amount': 300} -> (True, 'ok')
propose_refund {'amount': 90000} -> (False, 'amount out of policy range')
```

**Quiz:** Where should policy such as approvals be enforced?

- [ ] Nowhere
- [ ] Only in the system prompt
- [ ] Only by asking the model nicely
- [x] In the host's code, outside the model

*Answer:* In the host's code, outside the model. Code-enforced rules cannot be talked around by injected text.
