company_update_company
UpdateCompany patches mutable company fields in a single call: name, logo_url, aliases, and — for a company Lovie did not incorporate — its entity type, state, formation date, EIN and principal address. Every field is left untouched when unset, the five profile fields included: send only what you...
This record as markdown: /tools/lovieco-lovie-company-formation-mcp-npx/company-update-company.md
What company_update_company does on Lovie Company Formation MCP
AI agents use company_update_company to create or update resources in Lovie Company Formation MCP, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Lovie Company Formation MCP environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
company | object | Yes | |
companyId | object | Yes | UUID value wrapper. |
clearFields | array | — |
Parameters from the server's own tool schema.
Why company_update_company is rated Medium
An AI agent can call company_update_company faster than any human can review: one bad instruction and it creates or modifies resources in Lovie Company Formation MCP by the hundred, each call as confident as the last.
Risk signalsAccepts freeform code/query input (company.code) · High parameter count (30 properties)
Attacks that exploit this kind of access
The rule that runs company_update_company safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Lovie Company Formation MCP, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For company_update_company, this is the rule to start with:
company_update_company stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Lovie Company Formation MCP, apply this rule, and every company_update_company call is checked against it from then on.
Questions about company_update_company
UpdateCompany patches mutable company fields in a single call: name, logo_url, aliases, and — for a company Lovie did not incorporate — its entity type, state, formation date, EIN and principal address. Every field is left untouched when unset, the five profile fields included: send only what you are changing, and the rest keeps its stored value. The app removes a stored entity type, state, formation date or EIN by naming it in clear_fields; an empty value never removes one. address cannot be cleared, and is replaced whole when sent, so send every line of it. The profile fields, and clearing them, are REFUSED for a company whose source is LOVIE_FORMATION. Its formation is the filing of record, and letting the two disagree would mean the certificate says one thing and the dashboard another, with nothing to say which is right. Name and logo stay editable there, as they always were; a request mixing them with profile fields is refused whole, with nothing written. MCP-exposed so a founder can correct their own company by asking. It writes and is not idempotent. You cannot remove a value (clear_fields from an assistant is refused with PERMISSION_DENIED), and you may fill in a profile fact only where none is stored: changing a stored one, or sending any ein once one is on file, is refused the same way. Re-sending a stored value you read is not a change. For any refusal, tell the user to make it in Lovie. It is categorised as a Write tool in the Lovie Company Formation MCP MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
company_update_company accepts 3 parameters: company, companyId, clearFields. Required: company, companyId. The full parameter table on this page comes from the server's own tool schema.
Register the Lovie Company Formation MCP server in PolicyLayer and add a rule for company_update_company: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Lovie Company Formation MCP. Nothing to install.
company_update_company is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the company_update_company rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for company_update_company. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
company_update_company is provided by the Lovie Company Formation MCP server (lovie). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Lovie Company Formation, and thousands of servers like it.
This server
Across the catalogue