Capability controlNative WebMCP lifecycle

Approval should change
what agents can do.

Review one multi-step plan, then compile that exact decision into a 60-second, one-shot WebMCP tool. Before approval, the mutation capability does not exist.

MCJB

Launch control

Canonical board · v12

Canonical state untouched until capability call

Preview registry · 0 tools

toolchange events observed: 0

registering…

Shared live state

Friday launch

Backlog3
•••
OPS-31

Harden checkout retries

Infrastructure
UnassignedOverdue 1d
OPS-27

Remove duplicate analytics event

Analytics
Jon BellDuplicate
BILL-8Policy lock

Reconcile failed invoices

Billing
FinanceProtected
This week2
•••
OPS-22

Prepare release checklist

Launch
Maya ChenToday
OPS-19

Update incident runbook

Reliability
Jon BellTomorrow
Done1
•••
OPS-14

Verify rollback window

Launch
Maya ChenDone
01

Tool is absent

The agent can inspect and propose, but no mutation capability exists before review.

02

Approval compiles

The edited operations, base version, state hash, lifetime, and digest become one frozen capability.

03

Authority destroys itself

One empty-input call consumes commit_plan; a guarded compensation tool appears from its receipt.