confirm_mcp_approval
Confirm a pending MCP capability approval by spoken (or chat) yes/no. Pass approval_id from the approval_required tool result. decision: approve | reject | later. Runs the SAME process-approval pipeline as tapping Approve on the card — does not bypass integrity rails. Use on voice when the operat...
This record as markdown: /tools/com-getfreedomos-freedom-mcp/confirm-mcp-approval.md
What confirm_mcp_approval does on Freedom Mcp
AI agents use confirm_mcp_approval to create or update resources in Freedom Mcp, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Freedom Mcp environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
decision | string | Yes | approve | reject | later (yes/no/go also accepted) |
companyId | string | Yes | FreedomOS company id to act within (you must be a member). Required for company-scoped tools. |
grant_mode | string | — | approve only: 'once' runs without standing grant (default for spoken path); 'standing' also grants future calls |
approval_id | string | Yes | UUID of the pending mcp_tool_call approval card (from approval_required.approval_id) |
voice_session_id | string | — | Optional voice session id if known (audit only) |
utterance_snippet | string | — | Optional short quote of what the operator said (audit; ≤200 chars) |
Parameters from the server's own tool schema.
Why confirm_mcp_approval is rated Medium
This tool modifies approval records and triggers downstream approval workflows, making it a Write operation (reversible state change to approval entities). Severity is medium because approvals unlock capabilities whose actual impact depends on what those downstream capabilities do; the tool itself doesn't directly execute financial transactions or delete data, but it gates access to other tools.
From the tool's definition Confirms and processes pending MCP capability approvals by modifying approval state (approve | reject | later). Description states it 'Runs the SAME process-approval pipeline as tapping Approve on the card,' indicating state modification.
Attacks that exploit this kind of access
The rule that runs confirm_mcp_approval safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Freedom Mcp, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For confirm_mcp_approval, this is the rule to start with:
confirm_mcp_approval stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Freedom Mcp, apply this rule, and every confirm_mcp_approval call is checked against it from then on.
Questions about confirm_mcp_approval
Confirm a pending MCP capability approval by spoken (or chat) yes/no. Pass approval_id from the approval_required tool result. decision: approve | reject | later. Runs the SAME process-approval pipeline as tapping Approve on the card — does not bypass integrity rails. Use on voice when the operator says approve/yes or reject/no after a capability ask. Do NOT invent an approval_id. [write-tier — first use may require a manager's approval; a from-now-on approval makes future calls seamless, a just-once approval re-asks next time.]. It is categorised as a Write tool in the Freedom Mcp MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
confirm_mcp_approval accepts 6 parameters: decision, companyId, grant_mode, approval_id, voice_session_id, utterance_snippet. Required: decision, companyId, approval_id. The full parameter table on this page comes from the server's own tool schema.
Register the Freedom MCP server in PolicyLayer and add a rule for confirm_mcp_approval: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Freedom Mcp. Nothing to install.
confirm_mcp_approval is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the confirm_mcp_approval rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for confirm_mcp_approval. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
confirm_mcp_approval is provided by the Freedom MCP server (https://twuluxmoognlwtmaoqgo.supabase.co/functions/v1/freedom-mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Freedom, and thousands of servers like it.
This server
Across the catalogue