---
title: "MCP Roles, App Scopes and Receipts"
description: "Delegate bounded MCP operations while keeping app access and the agent’s OS permissions separate."
url: "https://tslink.md/docs/mcp-scopes"
locale: "en"
product_version: "0.1.1"
source: "https://github.com/anydoor7/tslink/blob/v0.1.1/docs/mcp-scopes.md"
---

> Documentation index: https://tslink.md/llms.txt · Installed binary is authoritative: `tslink manifest`.

Local `tslink mcp` defaults to owner authority. Reduce the session when delegating:

```bash
tslink mcp --scope viewer --apps photos
tslink mcp --scope app-operator --apps photos --max-duration 8h
tslink mcp --scope people-manager --apps finance --max-duration 2h
tslink mcp --scope viewer --inventory
```

These limits govern TSLink MCP operations. They do not sandbox the agent's shell/filesystem; another process running as owner can launch an owner session. Configure those capabilities separately. Inventory permission does not grant permission to open an app.

| Role           | Available operations                                                                                  | Boundary                                                                     |
| -------------- | ----------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------- |
| viewer         | Read inventory, health, URLs, people and explicit-app access history; static recipe/template catalogs | Explicit apps, or explicit inventory for all app inventory                   |
| app-operator   | Viewer plus `app_restart`, `people_grant`, `people_revoke`, person `extend`                           | Listed apps; positive maximum grant duration                                 |
| people-manager | Viewer plus one-app grants/revokes/extensions and request tools                                       | Listed apps and finite limits; request authority has additional owner checks |
| owner          | All 44 shipped tools, including guest/public mutations and `mcp_audit`                                | No app/duration restrictions; binding expiry can still apply                 |

Current viewer sessions expose 12 tools; people-manager sessions expose 18. Use [live `tools/list`](https://tslink.md/docs/mcp-server.md#tools-and-complete-input-fields) for your session; tool visibility depends on role. Operator/manager local `max_duration` defaults to 24h. Reduced sessions cannot widen their scope through arguments or create unknown people.

`people_grant` changes one pre-existing person's private HTTP/file app grant; `people_revoke` affects one app. They preserve other grants and cannot undo a whole-person revocation. TCP and ungated public Funnel are unsupported; private people checks remain valid on a guest-gated app. New people records need owner authority (`mcp_person_owner_required`). Protected portal owner/admin records cannot be changed by reduced roles.

`app_restart` queues a restart of the TSLink gateway node, preserves enrolled identity and does not restart the backend app or prove completion. Poll `status`/`health`; reduced operators cannot restart an existing public Funnel app.

## Remote binding

Keep your own owner login and add the exact delegate login in `config.json`:

```json
{"mcp":{"enabled":true,"allow":["you@example.com"],"bindings":[{"principal":"family@example.com","role":"viewer","apps":["photos"]}]}}
```

Restart the daemon after editing. Connect from a permitted tailnet device to the actual remote MCP URL. Legacy `mcp.allow` entries retain owner authority; remove a login there before assigning it a reduced binding. Duplicate principals and invalid/unknown bindings fail closed. Explicit logins take precedence; multiple matching tag principals deny access. Owner tags grant broad authority to devices carrying them.

Operator/manager remote bindings need positive `max_duration`. Use an actual `issued_at` with relative `for`, or `expires_at` RFC3339, to limit the binding itself; these forms are exclusive. Restart does not extend the binding. New grants obey audience policy, `max_duration` and remaining binding lifetime. Expiry denies new calls and cancels admitted remote requests, without rolling back committed effects.

Remote request listing/approval/denial additionally requires the current untagged, unrevoked human portal owner. An unrelated manager or portal admin cannot approve. Owner local CLI/stdio supplies trusted host recovery; reduced local scopes still limit role, app and duration. Guest tools, portal management, original whole-person mutations, global logs/invites and owner receipt tools remain owner-only. The global `/events` stream is owner-only; reduced roles poll tools.

## Audit and denials

Recognized mutations record bounded intent/completion receipts. No raw arguments, targets, credentials or bearer links enter the journal. Missing completion means unknown outcome; history can have drops and crash gaps. Read [access history](https://tslink.md/docs/access-history.md) before using receipts as evidence. Scope denials use `mcp_scope_denied`; hidden tools behave as unknown tools.

Related: [Full MCP reference](https://tslink.md/docs/mcp-server.md) · [Portal and requests](https://tslink.md/docs/portal-requests.md) · [Durations](https://tslink.md/docs/durations.md).

Sources: [TSLink mcp-scopes.md](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/mcp-scopes.md) · [TSLink remote-mcp.md](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/remote-mcp.md) · [TSLink agent-quickstart.md](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/agent-quickstart.md)
