cap_table_import_rsa
Imports a signed Restricted Stock Purchase/Award Agreement (RSA) from an uploaded PDF and stores the document in S3. USE THIS (not ExtractRsaTermsOcr + CreateCapTableAgreement, and not RecordCapTableInvestment) whenever the user provides or uploads a signed RSA PDF. The grantee (founder/employee/...
This record as markdown: /tools/lovieco-lovie-company-formation-mcp-npx/cap-table-import-rsa.md
What cap_table_import_rsa does on Lovie Company Formation MCP
AI agents use cap_table_import_rsa to create or update resources in Lovie Company Formation MCP, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Lovie Company Formation MCP environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
preview | boolean | — | |
companyId | object | Yes | UUID value wrapper. |
sourceS3Uri | string | — | |
stakeholderId | object | — | UUID value wrapper. |
consentToAiRead | boolean | — | |
rsaTermsOverride | object | — | |
newStakeholderName | string | — |
Parameters from the server's own tool schema.
Why cap_table_import_rsa is rated Medium
An AI agent can call cap_table_import_rsa faster than any human can review: one bad instruction and it creates or modifies resources in Lovie Company Formation MCP by the hundred, each call as confident as the last.
Risk signalsHigh parameter count (29 properties)
Attacks that exploit this kind of access
The rule that runs cap_table_import_rsa safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Lovie Company Formation MCP, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For cap_table_import_rsa, this is the rule to start with:
cap_table_import_rsa stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Lovie Company Formation MCP, apply this rule, and every cap_table_import_rsa call is checked against it from then on.
Questions about cap_table_import_rsa
Imports a signed Restricted Stock Purchase/Award Agreement (RSA) from an uploaded PDF and stores the document in S3. USE THIS (not ExtractRsaTermsOcr + CreateCapTableAgreement, and not RecordCapTableInvestment) whenever the user provides or uploads a signed RSA PDF. The grantee (founder/employee/advisor) MUST already exist as a cap-table stakeholder — this tool matches the document to an existing stakeholder by name and does NOT create one; if there is no match the import is rejected, so add the stakeholder first. Mandatory two-step human-in-the-loop flow: (1) call GetOcrUploadUrl with kind=RSA and mime_type=application/pdf, then upload the PDF bytes to the returned PUT URL; (2) call ImportRSA with preview=true and that source_s3_uri — this runs OCR and returns the extracted founder/company names and terms (shares, vesting, price_per_share, grant_date, 83b status, acceleration) plus the resolved grantee (matched_stakeholder_id; when it is empty no stakeholder matched, the response carries a warning, and the import will be refused until the grantee is added) WITHOUT persisting anything; (3) PRESENT those terms to the user as a table, let them correct any value, and get explicit confirmation; (4) call ImportRSA again WITHOUT preview and the SAME source_s3_uri; pass rsa_terms_override with any user-corrected terms (omit it to accept the extracted terms as-is), and stakeholder_id to pin the matched grantee. This creates the common-stock holding with its vesting schedule (or updates the grantee's existing holding), records a signed RSA agreement, and links the PDF — atomically. Never skip the preview + confirmation step; never persist unreviewed OCR output. Empty string / 0 / false in the extracted terms means the value was not stated in the document — never fabricate. It is categorised as a Write tool in the Lovie Company Formation MCP MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
cap_table_import_rsa accepts 7 parameters: preview, companyId, sourceS3Uri, stakeholderId, consentToAiRead, rsaTermsOverride, newStakeholderName. Required: companyId. The full parameter table on this page comes from the server's own tool schema.
Register the Lovie Company Formation MCP server in PolicyLayer and add a rule for cap_table_import_rsa: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Lovie Company Formation MCP. Nothing to install.
cap_table_import_rsa is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the cap_table_import_rsa rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for cap_table_import_rsa. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
cap_table_import_rsa is provided by the Lovie Company Formation MCP server (lovie). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Lovie Company Formation, and thousands of servers like it.
This server
Across the catalogue