# marchward_authorize

Check whether an action is allowed BEFORE the agent takes it. Call this first for any consequential or irreversible action (deploying, committing, publishing, deleting, moving money, calling an external API). Returns ALLOW, BLOCK, ESCALATE, or ALLOW_WITH_CONDITIONS, and writes a tamper-evident audit record. The agent and policy are resolved from your API key, so you usually only pass toolName.

Agent View of the PolicyLayer registry record for `marchward_authorize`. HTML page: https://policylayer.com/tools/ai-marchward-mcp-server/marchward-authorize

## Facts

- Tool: `marchward_authorize`
- Server: Mcp Server (`@marchward/mcp-server`) — https://policylayer.com/tools/ai-marchward-mcp-server.md
- Install: `npx -y @marchward/mcp-server`
- Homepage: https://github.com/marchward/marchward
- Risk category: Destructive (Critical risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Hidden

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "marchward_authorize",
    "arguments": {}
  }
}
```

## Why marchward_authorize is rated Critical

An AI agent that decides to call marchward_authorize doesn't hesitate, doesn't double-check, and doesn't stop at one. Whatever it removes from Mcp Server is gone. There is no undo for destructive operations.

## Use case

AI agents call marchward_authorize to permanently remove resources in Mcp Server, typically in cleanup and lifecycle workflows. It does its job in a single call, and there is no undo.

## Recommended policy (PolicyLayer)

Verdict: **Hidden**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Mcp Server:

```json
{
  "version": "1",
  "default": "deny",
  "hide": [
    "marchward_authorize"
  ]
}
```

## Other tools on Mcp Server (6)

- `marchward_execute` — Execute — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-execute.md
- `marchward_check_coverage` — Read — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-check-coverage.md
- `marchward_get_decisions` — Read — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-get-decisions.md
- `marchward_list_agents` — Read — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-list-agents.md
- `marchward_bind_policy` — Write — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-bind-policy.md
- `marchward_register_agent` — Write — https://policylayer.com/tools/ai-marchward-mcp-server/marchward-register-agent.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=ai-marchward-mcp-server · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/ai-marchward-mcp-server
