formation_update_formation
UpdateFormation applies a FieldMask-scoped patch to a formation. The caller supplies update_mask.paths to select the fields to replace. The roster is not patchable here — use AddShareholder, UpdateShareholder or RemoveShareholder. A patch whose shareholders carry ssn_last4 is refused with INVALID...
This record as markdown: /tools/lovieco-lovie-company-formation-mcp-npx/formation-update-formation.md
What formation_update_formation does on Lovie Company Formation MCP
AI agents use formation_update_formation to create or update resources in Lovie Company Formation MCP, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Lovie Company Formation MCP environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
formation | object | Yes | |
updateMask | string | Yes | Comma-separated field paths. |
formationId | object | Yes | UUID value wrapper. |
Parameters from the server's own tool schema.
Why formation_update_formation is rated Medium
An AI agent can call formation_update_formation faster than any human can review: one bad instruction and it creates or modifies resources in Lovie Company Formation MCP by the hundred, each call as confident as the last.
Risk signalsAccepts file system path (formation.einDocument.fileName) · Accepts raw HTML/template content (formation.conversationHistory[].content) · High parameter count (361 properties)
Attacks that exploit this kind of access
The rule that runs formation_update_formation safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Lovie Company Formation MCP, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For formation_update_formation, this is the rule to start with:
formation_update_formation stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Lovie Company Formation MCP, apply this rule, and every formation_update_formation call is checked against it from then on.
Questions about formation_update_formation
UpdateFormation applies a FieldMask-scoped patch to a formation. The caller supplies update_mask.paths to select the fields to replace. The roster is not patchable here — use AddShareholder, UpdateShareholder or RemoveShareholder. A patch whose shareholders carry ssn_last4 is refused with INVALID_ARGUMENT and writes nothing: those four digits are recorded only by SetShareholderTaxIdentifier, after the whole identifier has reached the secret store. Accepting them here would report a saved number that nothing holds. It is categorised as a Write tool in the Lovie Company Formation MCP MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
formation_update_formation accepts 3 parameters: formation, updateMask, formationId. Required: formation, updateMask, formationId. The full parameter table on this page comes from the server's own tool schema.
Register the Lovie Company Formation MCP server in PolicyLayer and add a rule for formation_update_formation: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Lovie Company Formation MCP. Nothing to install.
formation_update_formation is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the formation_update_formation rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for formation_update_formation. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
formation_update_formation is provided by the Lovie Company Formation MCP server (lovie). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Lovie Company Formation, and thousands of servers like it.
This server
Across the catalogue