Tools, Resources, and Approvals
Tools
Every listed tool includes an input schema, annotations, action class, required capability, and an indication that no provider write is executed directly.
- Read tools return bounded workspace-scoped projections.
- Proposal tools create reviewable records only.
- Approval-gated handoff tools queue an approval and provider handoff; they do not execute GitHub, SQL, deployment, or notification writes in the MCP request.
The server validates required fields, allowed top-level fields, types, limits, and enumerations before dispatch.
Resources
Approved resources currently include:
batoi://workspace/contextfor compact authenticated workspace identity and readiness.batoi://workspace/capabilitiesfor the host-filtered capability catalog.
Use resources/list before resources/read. Resource content is bounded and contains no bearer credential.
Approvals
Approval-required work pauses at a review boundary. An approval is narrow, versioned, expiring, revocable, and independently evidenced. MCP discovery or a model request does not constitute approval.