2 Comments
User's avatar
Peter Cranstone's avatar

This is a great proof of what becomes possible once context travels — but it also quietly shows where friction creeps back in. Once users are approving recursive tool calls and managing permissions per agent, it stops being a product problem and starts looking like an execution-layer problem. Feels like the natural next step is pushing permission down into the runtime so users don’t have to keep showing up just to let things happen.

Eeshita Pande's avatar

Exactly, currently most MCP tool calls need to be manually approved especially in consumer products like ChatGPT. Our agents need more agency.