Skip to content

Tool Approval Matrix Compiler

Compile cross-platform allow, ask, and deny decisions for tool capabilities across Codex, Claude, and managed MCP policies

Tool Approval Matrix Compiler

{
  "summary": {
    "totalTools": 4,
    "codex": {
      "allow": 1,
      "ask": 3,
      "deny": 0
    },
    "claude": {
      "allow": 1,
      "ask": 3,
      "deny": 0
    },
    "mcp": {
      "allow": 1,
      "ask": 2,
      "deny": 1
    }
  },
  "matrix": [
    {
      "tool": "docs-search",
      "risk": "low",
      "capabilities": [
        "read",
        "network"
      ],
      "codex": "allow",
      "claude": "allow",
      "mcp": "allow"
    },
    {
      "tool": "repo-writer",
      "risk": "medium",
      "capabilities": [
        "read",
        "write"
      ],
      "codex": "ask",
      "claude": "ask",
      "mcp": "ask"
    },
    {
      "tool": "shell-admin",
      "risk": "high",
      "capabilities": [
        "shell",
        "exec",
        "secrets"
      ],
      "codex": "ask",
      "claude": "ask",
      "mcp": "deny"
    },
    {
      "tool": "ticket-sync",
      "risk": "medium",
      "capabilities": [
        "network",
        "secrets"
      ],
      "codex": "ask",
      "claude": "ask",
      "mcp": "ask"
    }
  ],
  "snippets": {
    "codex_policy_json": "{\n  \"tools\": {\n    \"docs-search\": \"allow\",\n    \"repo-writer\": \"ask\",\n    \"shell-admin\": \"ask\",\n    \"ticket-sync\": \"ask\"\n  }\n}",
    "claude_policy_json": "{\n  \"tools\": {\n    \"docs-search\": \"allow\",\n    \"repo-writer\": \"ask\",\n    \"shell-admin\": \"ask\",\n    \"ticket-sync\": \"ask\"\n  }\n}",
    "mcp_managed_policy_json": "{\n  \"tools\": {\n    \"docs-search\": \"allow\",\n    \"repo-writer\": \"ask\",\n    \"shell-admin\": \"deny\",\n    \"ticket-sync\": \"ask\"\n  }\n}"
  },
  "rolloutChecklist": [
    "Apply policies in dry-run mode first and monitor denials.",
    "Escalate any deny decision touching production automation paths.",
    "Review policy diffs weekly for drift across Codex, Claude, and MCP environments."
  ]
}

Pair withAgent Tool Blast Radius Mapperto validate risk-tier assumptions before enforcement.

What this tool does

The Tool Approval Matrix Compiler produces a single allow, ask, or deny decision for each tool capability across Codex, Claude, and managed MCP policies. Define your rules once and it compiles the cross-platform matrix, so an agent's permissions stay consistent and least-privilege no matter which runtime enforces them. It runs entirely in the browser.

Updated . Provided as is. Check the output before you rely on it in production.

How to use Tool Approval Matrix Compiler

  1. 1

    Describe tool risk and capabilities

    Provide each tool's risk level and capabilities (read, write, network, shell, secrets) plus a default fallback action.

  2. 2

    Compile platform decisions

    Run the compiler to produce allow/ask/deny decisions for Codex, Claude, and managed MCP policy surfaces.

  3. 3

    Review summary distribution

    Check allow/ask/deny counts per platform to spot over-permissive defaults or overly restrictive enforcement before rollout.

  4. 4

    Copy policy snippets

    Use generated JSON snippets for codex policy, claude policy, and managed MCP policy as your deployment starting point.

  5. 5

    Deploy in dry-run first

    Apply policies in observation mode, monitor denials and escalation traffic, then promote to enforcement after clean telemetry.

Questions and answers

What does Tool Approval Matrix Compiler generate?
A tool approval matrix records, for each agent tool, whether a runtime may run it without asking, must ask a human first, or must refuse. From your tool list with risk levels and capabilities, this compiler sets allow, ask or deny separately for Codex, Claude and MCP, and outputs a JSON policy snippet per platform.
How are decisions computed?
Each tool's declared risk level is combined with three capability groups: shell or exec, write or filesystem-write, and secrets or credentials. Other capabilities such as network do not change the decision, and the same input always gives the same matrix.
Can I set my own default action?
Yes. Set defaultAction to allow, ask or deny. Rules override it in both directions: risky combinations such as shell with secrets become ask or deny, and low-risk tools without shell, write or secrets access become allow.
Should I enforce output immediately?
Start in dry-run or observation mode first, review denial and escalation telemetry, then move to enforcement once behavior is stable.
Is this a replacement for security review?
No. It accelerates policy drafting, but final approval should still include human security review for high-impact production tools.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/tool-approval-matrix-compiler/

For automation planning, fetch the canonical contract at /api/tool/tool-approval-matrix-compiler.json.