The effective catalogue is an intersection
Tool availability depends on identity, grants, connection state and the execution surface. For Tasks, the selected harness adds its capabilities and restrictions. A tool listed in the product inventory is not automatically available to every agent.
Filter tools before execution
The model receives the effective catalogue, with only the capabilities available in that context. Configuration pages show the underlying tools and connections. Inspect both the granted connection and the resolved catalogue when an expected action is unavailable.
Match permission to the actual effect
A label such as read or write is useful only if it reflects what the provider really does. Consider recipient, destination, resource scope and side effects. Approval-sensitive mail uses its own explicit review path; arbitrary connected tools must be assessed on their actual contracts.
Configure the minimum useful scope
Start with the sources needed for one deliverable. Add write access only for an identified destination. Test a forbidden operation and an unavailable connection. Recheck the catalogue after changing a role, connection or Task harness.
Keep sensitive settings under administration
An enforced global setting cannot be overridden by a connection. Function rules distinguish enabled and denied capabilities; discovery happens after filtering. Conversational Tool availability is a separate choice from Task access.
Each agent can expose a unified MCP endpoint to external clients. A named token per client makes revocation practical. Clients receive that agent’s scope, not general administration rights.
Separate mandatory services from access choices
Galaris, Conversation, Memory and File Sharing are mandatory and protected. Per-function settings apply to optional tools. These services bypass neither document permissions nor context limits. Galaris Admin inspections recheck their administrative connection at call time, even when the catalogue was loaded earlier.
Document applications: each reader gives consent
A page may contain interactive code, but Dataset access is denied by default. The reader’s current rights to the page and data are combined with personal consent, given through Application permissions for that content version. Neither the code nor the authoring agent can grant this access to itself.
Consent does not transfer to another reader or document. Editing or restoring content requires new consent; changing only the title does not. Revocation blocks subsequent calls without removing data already read or undoing completed writes.
Write access allows appending and full replacement, potentially as soon as the page opens. Review sources and destinations together: an authorised application can move data between Datasets. Isolation blocks direct access to the parent DOM, Galaris cookies and storage, and ordinary network loads. It does not cap JavaScript CPU or memory consumption.


