post_workroom_message

Post an internal message from an AI colleague into a Workroom thread. Use this to report findings, ask the owner for approval, or share source links after reading CRM/Inbox data. This does not send anything to customers.

SERVERFavCRM SOURCEhttps://api.favcrm.io/mcp
Medium RISK CLASS
Category Write
Parameters 43 required
Recommended Rate-limitedsee the rule below
Registry record Grade F, identity unverified Pull the record →

This record as markdown: /tools/io-favcrm-favcrm/post-workroom-message.md

What post_workroom_message does on FavCRM

AI agents use post_workroom_message to create or update resources in FavCRM, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your FavCRM environment.

ParameterTypeRequiredDescription
agentId string Yes AI colleague ID that is a participant in the thread
content string Yes Message to show in Workroom. Markdown is allowed.
metadata object Optional generic metadata, e.g. {sourceRefs:[{type:"inbox_conversation",id:"..."}]}
threadId string Yes Workroom thread ID

Parameters from the server's own tool schema.

Why post_workroom_message is rated Medium

This tool creates new data (messages) within an internal communication system. It is categorized as Write rather than Execute because it performs a simple, bounded content creation action without triggering external operations or side effects. The internal-only nature and reversibility keep severity low. No customer communication, financial impact, or destructive operations are involved.

From the tool's definition Tool description states 'Post an internal message' to 'Workroom thread' with explicit note 'This does not send anything to customers.' The action is to create/add a message, which is reversible (messages can be edited or deleted).

Risk signalsAccepts raw HTML/template content (content)

Questions about post_workroom_message

What does the post_workroom_message tool do? +

Post an internal message from an AI colleague into a Workroom thread. Use this to report findings, ask the owner for approval, or share source links after reading CRM/Inbox data. This does not send anything to customers. It is categorised as a Write tool in the FavCRM MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.

What parameters does post_workroom_message accept? +

post_workroom_message accepts 4 parameters: agentId, content, metadata, threadId. Required: agentId, content, threadId. The full parameter table on this page comes from the server's own tool schema.

How do I enforce a policy on post_workroom_message? +

Register the FavCRM MCP server in PolicyLayer and add a rule for post_workroom_message: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches FavCRM. Nothing to install.

What risk level is post_workroom_message? +

post_workroom_message is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.

Can I rate-limit post_workroom_message? +

Yes. Add a rate_limit block to the post_workroom_message rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block post_workroom_message completely? +

Set action: deny in the PolicyLayer policy for post_workroom_message. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides post_workroom_message? +

post_workroom_message is provided by the FavCRM MCP server (https://api.favcrm.io/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

More on FavCRM, and thousands of servers like it.

// THE MCP REGISTRY

PolicyLayer tracks 44,603 MCP servers and 515,000+ tools.

Every server has a live record: who publishes it, whether it answers without auth, its risk grade, every tool classified, the recommended policy. This page is one line of FavCRM's. Pull the full record:

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.