Agent Builder: approve tool calls, keep the Sume session read-only

OpenAI says to enable approvals for reads and writes. A Sume MCP session with mcp:read only can't run paid or mutating tools.

5 min readSume
All posts

OpenAI's guide to building agents safely tells you to always keep tool approvals on for MCP tools, for reads as well as writes, so you can review what data is being shared. That protects you from a bad call getting through unseen. For a Sume connection it is worth adding a second layer that does not depend on a person clicking: authorize the session with mcp:read only, so paid and mutating tools cannot run at all.

Guidance is from OpenAI's Agent Builder safety page, read on 2026-10-03; Sume's scopes are in MCP OAuth and API keys.

What does OpenAI recommend?

The page lists prompt injection and private-data leakage as the main risks when agents use tools and untrusted input, and says not to put untrusted variables into developer messages. It recommends keeping tool approvals on and using structured outputs between nodes. It also says built-in guardrails are not foolproof, so approvals remain the human check.

What does Sume add on the server?

Hosted MCP lives at https://mcp.sume.com/mcp with OAuth scopes mcp:read, which is required, and mcp:write, which is opt-in. On the consent screen read is locked on and write is off by default. With mcp:read only, the session sees read-only tools, and mutating or paid calls return insufficient_scope. Paid and write tools also require an idempotency_key.

Approval layers for an Agent Builder run (read 2026-10-03)
LayerWho enforces itStops a paid call?
Tool approval in Agent BuilderA person reviewing each callOnly if they decline
mcp:read OAuth sessionSume serverYes, insufficient_scope
max_spend_usd on the callSume server, when sentOver the cap, yes

How should I set it up?

  • Connect the MCP server with read access first. Look up jobs and results with that.
  • Add mcp:write only for the workflow that must create things, and keep approvals on there.
  • Ask the agent to send dry_run=true first on any expensive create.
  • Never pass user-supplied text through developer messages; use user messages, as OpenAI advises.

What does the OpenAI page not cover?

It does not describe any one vendor's scopes, so the table above is the Sume half. Read the consent screen when you connect: Read is locked on and Write is off, and you must turn Write on yourself. An API key, by contrast, sees the full tool set, so prefer OAuth for an Agent Builder connection that a person approves.

When do approvals still matter?

On a write session, an approval is the only thing that reads the arguments before a paid create runs. Keep it on. The scope limits what kinds of tools exist; the approval lets you see which one is about to run and with what spend cap.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume