Permissions and Security Boundaries
| Scope | Allowed capabilities | Recommended use |
| Read-only | Query and read data only | Balance, Budget, card status, transaction, and reconciliation queries |
| Read-write | Read data plus the create or update operations that have been exposed | Controlled business operations under human confirmation and enterprise control policies |
Important: The available materials confirm only the Read-only and Read-write scopes. No formal per-tool permission matrix has been provided. The complete tool-to-permission mapping should be based on tools/list after connecting to MCP and the technical release list.