Skip to main content

MCP scopes and permissions

Scopes must be narrow enough to sell safely and broad enough for agents to be useful.

Consumer scopes​

ScopeDefaultNotes
collection:readYesRead cabinet and public bottle metadata
collection:writeNoAdd, edit, or remove bottles
wears:readYesRead wear history
wears:writeNoLog wears and edits
wishlist:readYesRead wishlist and grail items
wishlist:writeNoAdd, rank, or remove wishlist items
notes:readYesRead private fragrance notes
notes:writeNoWrite private notes
partner:readNoRequires explicit linked-partner consent
share_cards:createNoCreates public artefacts
exports:createNoGenerates exports or reports

Commercial scopes​

ScopeUse
fragrance:searchSearch corpus records
fragrance:matchFuzzy match text to fragrance identity
fragrance:similarSimilarity and note-overlap queries
widget:gift_finderHosted or embedded Gift Finder calls
widget:fuzzy_searchStorefront search autocomplete
country:readCountry showcase and brand pack reads
brand:analyticsThresholded aggregate brand intelligence
feed:enrichCatalogue cleanup and export jobs

Audit requirements​

Every MCP call should record:

  • key or user token id
  • organisation id when commercial
  • tool name
  • scopes used
  • request id
  • target entity ids
  • outcome
  • error category
  • usage units
  • timestamp

No production write scope should ship without rollback or correction workflow.

Back to SniffopotamusReturn to the app