Medium Risk

purchasing.orders.add_line

Voeg een orderregel toe aan een bestaande inkooporder (purchase order) in Exact Online. Verplichte velden: orderNumber (inkoopordernummer) en itemCode (artikelcode) en quantity (aantal). Optioneel: notes (notities). Gebruik search_purchase_orders om eerst het ordernummer te vinden en search_items...

Part of the Exact Online server.

purchasing.orders.add_line can modify Exact Online data, with no limits today. PolicyLayer puts allow, deny, and rate-limit rules on every call. Live in minutes.

SECURE EXACT ONLINE →

Free to start. No card required.

AI agents use purchasing.orders.add_line to create or modify resources in Exact Online. Write operations carry medium risk because an autonomous agent could trigger bulk unintended modifications. Rate limits prevent a single agent session from making hundreds of changes in rapid succession. Argument validation ensures the agent passes expected values.

Without a policy, an AI agent could call purchasing.orders.add_line repeatedly, creating or modifying resources faster than any human could review. PolicyLayer's rate limiting ensures write operations happen at a controlled pace, and argument validation catches malformed or unexpected inputs before they reach Exact Online.

Write tools can modify data. A rate limit prevents runaway bulk operations from AI agents.

policy.json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "purchasing.orders.add_line": {
      "limits": [
        {
          "counter": "purchasing.orders.add_line_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}

See the full Exact Online policy for all 50 tools.

Get this rule live on your own Exact Online server in minutes. PolicyLayer enforces it on every call, before it runs.

ENFORCE ON MY EXACT ONLINE →

View all 50 tools →

These attack patterns abuse exactly the kind of access purchasing.orders.add_line gives an agent. Each links to the full case and the policy that stops it:

Browse the full MCP Attack Database →

Every attack above starts with a tool call. PolicyLayer checks each one against your policy first, so purchasing.orders.add_line only ever does what you allow.

SECURE EXACT ONLINE →

Other write tools across the catalogue. The same approach applies to each: rate-limit and validate the arguments.

What does the purchasing.orders.add_line tool do? +

Voeg een orderregel toe aan een bestaande inkooporder (purchase order) in Exact Online. Verplichte velden: orderNumber (inkoopordernummer) en itemCode (artikelcode) en quantity (aantal). Optioneel: notes (notities). Gebruik search_purchase_orders om eerst het ordernummer te vinden en search_items om de artikelcode te vinden. Geef in de context parameter aan waarom je deze tool aanroept en wat de gebruiker vraagt. | Add an order line to an existing purchase order in Exact Online. Required: orderNumber, itemCode and quantity. Optional: notes. Use search_purchase_orders to find the order number and search_items to find the item code first.. It is categorised as a Write tool in the Exact Online MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.

How do I enforce a policy on purchasing.orders.add_line? +

Register the Exact Online MCP server in PolicyLayer and add a rule for purchasing.orders.add_line: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Exact Online. Nothing to install.

What risk level is purchasing.orders.add_line? +

purchasing.orders.add_line is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.

Can I rate-limit purchasing.orders.add_line? +

Yes. Add a rate_limit block to the purchasing.orders.add_line rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block purchasing.orders.add_line completely? +

Set action: deny in the PolicyLayer policy for purchasing.orders.add_line. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides purchasing.orders.add_line? +

purchasing.orders.add_line is provided by the Exact Online MCP server (IndustrialIT/LedgerBotje). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

Enforce policy on every Exact Online tool call.

Deterministic rules across all 50 Exact Online tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Free to start. No card required.

4,600+ MCP servers and 31,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.