Skip to main content
Confirmation is one protocol, learned once: a write past its risk threshold returns needsConfirmation: true with a single-use confirm_token, valid five minutes and bound to a hash of the arguments. A token issued for two recipients cannot be replayed for two hundred.
Response when confirmation is required
If your client supports MCP elicitation, the prompt is raised in your own interface and you answer there. If it doesn’t, replay the identical call with confirm_token added within five minutes.

Tiers

The threshold is set per action, not per toolmanage_leads alone spans “add a note” and “delete a lead”, three orders of magnitude apart in consequence. Confirming everything trains people to click through; confirming nothing eventually loses data.