MCP wants a human in the loop: Sume gates for unattended agents
MCP says a human SHOULD be able to deny tool calls. For unattended agents, Sume adds scopes, idempotency keys and a required Agent Completions cap.

The MCP 2025-11-25 tools page says that for trust and safety there SHOULD always be a human in the loop with the ability to deny tool invocations, and that clients SHOULD show confirmation prompts. A scheduled or CI agent has no one at the keyboard, so the prompt is gone. What is left is what the server enforces, and for Sume that is scope, a retry key and, on one surface, a required spend cap.
What the spec asks of clients
Clients SHOULD make exposed tools clear, show indicators when tools run, and prompt for confirmation on operations. It also tells clients to show tool inputs before calling and to log tool usage for audit. None of that exists in an unattended run unless you build it.
What Sume enforces without a person
OAuth mcp:read hides write and paid tools; calls return insufficient_scope. Write and paid calls need an idempotency_key, which is dedup, not approval. max_spend_usd is optional and enforced only when you send it. API-key sessions see all tools.
Agent Completions is stricter. The docs say an interactive spend-approval prompt protects the chat UI, a backend caller does not get one, and so generation_spend_cap_usd is required with no default. The cap replaces the prompt.
| Surface | Human prompt | Server-side stand-in |
|---|---|---|
| Hosted MCP, OAuth | Client's own prompt | mcp:read default, Write toggle |
| Hosted MCP, API key | None | idempotency_key; optional max_spend_usd |
| Agent Completions | None | Required generation_spend_cap_usd |
| Scheduled run | None | Schedule cap, $1.00 if unset |
What to add yourself
Run unattended jobs on the narrowest surface: read-only OAuth for look-ups, Agent Completions with a cap for work that spends. Send max_spend_usd on every paid MCP call. Log request ids, never signed URLs or keys.
Sources
Related posts
More in Agents
- Auditing agent tool calls: MCP log advice, Sume script_run journal
The MCP spec tells clients to log tool usage for audit. For Sume's script_run, the response includes a calls[] journal and child jobs[] to use with jobs_wait.
- Scheduled or Format API: does the clock or your user start the run?
A Sume Scheduled run fires on a cron; a Format run fires when your backend calls it. Same agent, same receipt, new trigger. How to choose without dupes.
- Three ways to run the Sume video agent from code
Format runs, Scheduled runs and Agent Completions all start the same Sume agent. Pick by how often your task changes, then read the receipt the same way.
- A video agent run takes 15 to 30 minutes: design the waiting
Long-form video from an agent is minutes of work, not seconds. Email-me-when-ready, saved drafts and honest limits for a Sume Format run in your product.
Written by Sume