Visual explanationBeing callable doesn't mean full access
01Operation request

What you want to read or modify

02Actual authorization scope

Account, service, and file permissions

03Allow or Deny

Execution results are constrained by the environment

Teaching diagram; actual capabilities and execution methods depend on the application used.

Permission: The scope of accessible resources and executable operations controlled by applications, services, and runtime environments.

First, Clarify What You Allow It to Do

Preparing materials requires reading specified resources; modifying original files and sending them to others are separate operations. It is unreasonable to interpret "helping with lesson preparation" as meaning access to all files or sending content externally.

Permissions are enforced by applications, services, and runtime environments. Prompts can express operational requirements, but they are not actual access controls themselves.

Three Operations, Evaluated Separately

OperationScope Requiring Confirmation
ReadWhich files, directories, or service records can be accessed
ModifyWhich content can be changed, and how to verify and restore
Send or PublishWhere to, to whom, and whether the final content is determined

Specific environments may bundle multiple capabilities together or grant them separately. Examine the actual operational scope, not just "connected" or "installed" status.

"Do Not Delete" Is Not a Read-Only Setting

Requiring "do not delete" in a prompt is guidance for system behavior. If the tool still has deletion capabilities, the actual permissions have not changed as a result.

Conversely, even if you request "please modify the file," the tool cannot complete a write operation if it only has a read interface. Task requirements and executable scope need to be consistent.

Understanding Boundaries with MCP Examples

The course materials service on this site only exposes reading of fixed materials by course ID, does not accept arbitrary file paths, and has no modification or sending tools. This defines the operations the service provides, but does not mean the entire Python process is read-only at the operating system level.

When switching to a different service, re-verify its capabilities and actual permissions. Do not assume the same access scope just because they all use MCP.

Practical Judgment When Using

Choose resources and operation scope according to task requirements. Confirm the target before operating and check results afterward; if the scope does not match the task, first adjust connections, tools, or settings. Specific authorization interfaces vary by application.

Next Steps

Read Tools and MCP to understand how requirements, capabilities, and access conditions work together.

Reflect

Does writing "do not modify files" in a prompt equal the tool being set to read-only?

Reference judgment: No. Actual read-only requires tool and environment restrictions on write operations; a prompt request is merely behavioral guidance.

Sources and Scope of Application

References OpenAI · Using tools, MCP · Tools. Technical specifications verified on 2026-09-09; cases and instructional organization are authored by this site. Specific product support scope and operational methods should be verified separately; this article makes no cross-product feature commitments.