# Governing MCP: switches, presets, tool policy and the stop button

> Everything is off until an administrator turns it on, class by class and tool by tool; one button stops it all.

Section: Settings and administration · Canonical: https://intubu.intuitivecapital-dai.com/docs/mcp-governance

Settings → MCP connections → Governance, Tool policy, Call log. Owner or settings administrator only.

**Off by default.** Nothing connects until you switch the server on, and nothing is callable until a class of tools is on as well. Three classes, enabled separately:
- **Read** — search, reports, aging, statements, a business question. Returns what the person could open; nothing else.
- **Draft** — an invoice, bill, journal entry, task, note or email reply. Every one becomes a task in the AI graph awaiting review. Nothing posts.
- **Action** — approve a task, send an invoice. Off by default; each action tool must *also* be enabled individually, with an amount cap. Self-approval is always refused.

**Presets** apply a whole posture at once: *Off*, *Read-only analyst*, *Draft assistant*, *Full copilot*. The switches show exactly what each one set.

**Tool policy** is the closed catalogue. There is no way to add a tool; what is listed is everything an external AI can ever call, and the ledger-writing operations are not on it. Per tool: on/off, calls per hour, roles, and — for action tools — a cap above which the call is refused and the person is told to do it in IntuBu.

**Fields that never leave** are masked at serialisation — results, resources and error messages alike.

**The emergency stop** refuses every connection and every connected server, both directions, until cleared. It revokes nothing, so clearing it puts things back as they were; *Revoke all connections* is the separate, deliberate act.

**The call log** records every call in both directions with masked arguments: who, which tool, the outcome, and the reason for a refusal. The digest on the Governance tab counts the week.
