Tool governance
permissions: default: deny tools: github.read: allow: true github.write: allow: true production.deploy: allow: false network: egress: deny allowHosts: - mcp.example.com secrets: - GITHUB_TOKENallow: falsewins overallow: truewithin one object; severalpermissionsobjects combine as an intersection.resourcesrestricts an allowed action to specific targets. If the target cannot be determined, the call is denied.- Permissions grant, policies restrict. Without a
permissionsobject every action of the exposed tools is allowed by permissions;awp lintwarns about this.
Normative text: Tool governance: permissions.