BrenzuriStart free
Agents and MCP

What an editorial agent should be allowed to do, and what it should not

Brief, generate, read sources, fix flags: yes. Approve and publish: never. The reasoning behind the MCP permission set, with the cases that shaped it.

Written in Brenzuri 7 sources · 16 claims checked · 14 corroborated · 2 single-source

What an agent may do

An agent connected to Brenzuri over MCP can do what a writer can do in the interface: create a brief, start a run, read the source list, read the confidence report, add a source to a flagged claim and keep a flag with a note. It does those things inside a credit budget its owner set, and every one of them is written into the article's version history under the agent's name.

It cannot approve, and it cannot see the workspace's credit balance. It is told whether a run is affordable, not how much is left. Those two limits are not settings; there is no tool for either, so no prompt can reach them.

Why approval stays with a person

Approval is the moment a company's name goes on the text. †, and the same principle is what makes an AI label mean something: it is derived from that approval record, for that exact version, and cannot be set by anyone.

The practical consequence is that an agent can bring an article to the point of approval and then stop. The person who approves sees the source list, the flags and what the agent changed.

The cases that shaped it

The permission set was not designed in the abstract. †. Two years of similar cases point the same way: the failure is never that a model wrote a sentence, it is that nobody was on record as having read it.

So the rule is short. Write, read, fix: yes. Approve, publish, spend beyond the budget: no. The MCP scopes intersect with the owner's role and never exceed it.

† Single-source claim. Only one outlet in the source set reports this; the editor kept it with attribution. See the confidence report.

Frequently asked questions

No. Scopes intersect with the owner's role and there is no approve tool, so nothing an agent holds can grant approval.

Sources · 7
  1. Model Context Protocol — Specification: authorization and tools · official documentation
  2. Partnership on AI — Guidance for foundation model deployment in newsrooms · research
  3. The Verge — A publisher pauses its AI-written series after errors · general news
  4. Reuters Institute — Digital News Report 2025 · research
  5. Associated Press — Standards around generative AI · official
  6. Nieman Lab — Agents in the newsroom · trade press
  7. Press Gazette — How publishers govern AI tools · trade press

Generated with sources, reviewed by a human: yes. Version 3, approved 22 Aug 2026 by A. Reyes.