What an agent may do
An agent connected to Brenzuri over MCP can do what a writer can do in the interface: create a brief, start a run, read the source list, read the confidence report, add a source to a flagged claim and keep a flag with a note. It does those things inside a credit budget its owner set, and every one of them is written into the article's version history under the agent's name.
It cannot approve, and it cannot see the workspace's credit balance. It is told whether a run is affordable, not how much is left. Those two limits are not settings; there is no tool for either, so no prompt can reach them.
Why approval stays with a person
Approval is the moment a company's name goes on the text.
The practical consequence is that an agent can bring an article to the point of approval and then stop. The person who approves sees the source list, the flags and what the agent changed.
The cases that shaped it
The permission set was not designed in the abstract.
So the rule is short. Write, read, fix: yes. Approve, publish, spend beyond the budget: no. The MCP scopes intersect with the owner's role and never exceed it.
Frequently asked questions
No. Scopes intersect with the owner's role and there is no approve tool, so nothing an agent holds can grant approval.
- Model Context Protocol — Specification: authorization and tools
- Partnership on AI — Guidance for foundation model deployment in newsrooms
- The Verge — A publisher pauses its AI-written series after errors
- Reuters Institute — Digital News Report 2025
- Associated Press — Standards around generative AI
- Nieman Lab — Agents in the newsroom
- Press Gazette — How publishers govern AI tools
Generated with sources, reviewed by a human: yes. Version 3, approved 22 Aug 2026 by A. Reyes.