MCP scopes and permissions
Scopes must be narrow enough to sell safely and broad enough for agents to be useful.
Consumer scopes
| Scope | Default | Notes |
|---|---|---|
collection:read | Yes | Read cabinet and public bottle metadata |
collection:write | No | Add, edit, or remove bottles |
wears:read | Yes | Read wear history |
wears:write | No | Log wears and edits |
wishlist:read | Yes | Read wishlist and grail items |
wishlist:write | No | Add, rank, or remove wishlist items |
notes:read | Yes | Read private fragrance notes |
notes:write | No | Write private notes |
partner:read | No | Requires explicit linked-partner consent |
share_cards:create | No | Creates public artefacts |
exports:create | No | Generates exports or reports |
Commercial scopes
| Scope | Use |
|---|---|
fragrance:search | Search corpus records |
fragrance:match | Fuzzy match text to fragrance identity |
fragrance:similar | Similarity and note-overlap queries |
widget:gift_finder | Hosted or embedded Gift Finder calls |
widget:fuzzy_search | Storefront search autocomplete |
country:read | Country showcase and brand pack reads |
brand:analytics | Thresholded aggregate brand intelligence |
feed:enrich | Catalogue cleanup and export jobs |
Audit requirements
Every MCP call should record:
- key or user token id
- organisation id when commercial
- tool name
- scopes used
- request id
- target entity ids
- outcome
- error category
- usage units
- timestamp
No production write scope should ship without rollback or correction workflow.