{"id":2034,"date":"2026-09-29T11:21:15","date_gmt":"2026-09-29T11:21:15","guid":{"rendered":"https:\/\/www.mogacode.ma\/?p=2034"},"modified":"2026-09-29T11:21:15","modified_gmt":"2026-09-29T11:21:15","slug":"agent-ia-mcp-confirmation-humaine","status":"publish","type":"post","link":"https:\/\/www.mogacode.ma\/en\/agent-ia-mcp-confirmation-humaine\/","title":{"rendered":"When an AI Agent Acts for You, Where Does the Human Say Yes?"},"content":{"rendered":"<p class=\"translation-block\"><em>Guest article by Arthur Teboul, founder of DokuTrak.<\/em><\/p>\n<p class=\"translation-block\">An AI agent that acts on your behalf has to ask before anything that matters. The real question is where the \"yes\" should sit, and what the person giving it needs to see. My answer fits in one rule: the further the consequence lands from you, the more the confirmation has to show, and the more carefully you have to choose who gives it. And some decisions should not be unlocked by any yes at all.<\/p>\n<p class=\"translation-block\">I run DokuTrak, software that handles document collection for accountants, lawyers and consultants who need paperwork from their clients. We opened it to AI agents through MCP, the protocol that lets Claude and other assistants call tools. MogaCode runs its clients' hosting (sites, DNS, mailboxes, databases) through an agent, using its <a href=\"https:\/\/github.com\/Mogacode-ma\/infomaniak-mcp-agent\" target=\"_blank\" rel=\"noopener\">Infomaniak MCP server<\/a>. Put the two practices side by side and you get three circles, plus one hard limit.<\/p>\n<h2>Three places a \"yes\" can live<\/h2>\n<p class=\"translation-block\">An agent connected over MCP can be stopped in three places, and each one sees something different.<\/p>\n<ul>\n<li class=\"translation-block\"><strong>In the conversation.<\/strong> The agent sums up what it is about to do and waits for your reply. It's where the action is described to you in plain language. But the model decides whether to pause.<\/li>\n<li class=\"translation-block\"><strong>In the MCP client.<\/strong> The app (such as Claude Desktop or Claude Code) shows a permission prompt before a tool runs. It appears no matter what the model decides, but it only shows what the app chooses to display.<\/li>\n<li class=\"translation-block\"><strong>On the server.<\/strong> The server validates the call, requires a second step, or refuses it outright. It is the one place that depends neither on the model nor on the app's settings.<\/li>\n<\/ul>\n<p class=\"translation-block\">The MCP specification asks apps to show users confirmation prompts for operations, \"to ensure a human is in the loop\" (<a href=\"https:\/\/modelcontextprotocol.io\/specification\/2026-07-28\/server\/tools\" target=\"_blank\" rel=\"noopener\">MCP specification, Tools<\/a>). That is a <em>SHOULD<\/em>, a recommendation each app implements its own way. So for every action, ask which of the three places actually carries the decision. The answer depends on how far the consequence lands from you. That distance draws three circles.<\/p>\n<h2>Circle 1: your own infrastructure<\/h2>\n<p class=\"translation-block\">In the first circle, the agent works on resources you own. A DNS record, a database, a site on your hosting plan. If something goes wrong, you bear the cost, and many of these actions can be reversed.<\/p>\n<p class=\"translation-block\">MogaCode's Infomaniak MCP server, with its 78 tools, shows the mechanism well, whether the resources are yours or a client's. Every tool is annotated as read-only or destructive. Anything that changes or deletes follows a two-phase commit. On the first call, the tool does nothing: it returns an exact preview of what will change, such as the full DNS record you asked it to delete, plus a single-use confirmation token that expires. Only a second call, with the same parameters and that token, runs the action.<\/p>\n<p class=\"translation-block\">Composite operations, like provisioning a site with its database and DNS record, produce a plan that lists every step; if something fails halfway, you can see which steps succeeded. And every destructive action in the session is logged, with an undo tool that is itself subject to the plan and the confirmation.<\/p>\n<p class=\"translation-block\">As MogaCode's own AI agent, which operates through this server, puts it: the confirmation is not a generic \"are you sure?\" but a verifiable preview of the real effect. \"The human (or the agent) validates a fact, not an intention.\"<\/p>\n<p class=\"translation-block\">In this circle, what the human needs to see is a plan: what, where, before, after. The right place for the lock is the server, because it guarantees that what runs is exactly what was shown.<\/p>\n<p class=\"translation-block\">What the token doesn't say is who read the preview. That reading happens in the conversation, when the human replies \"OK, go ahead.\" The server guarantees what runs; the conversation is where a person actually reads it. You need both.<\/p>\n<h2>Circle 2: what belongs to your client<\/h2>\n<p class=\"translation-block\">The second circle is specific to agencies: the agent acts on something that isn't yours. A client's website, their DNS, their mailbox. You manage it; you don't own it.<\/p>\n<p class=\"translation-block\">Here, the person who confirms is not always the person who bears the consequence. Deleting a mailbox also deletes every email stored in it. The plan can be accurate, the token valid, the agency's yes fully informed. The client's email is still gone.<\/p>\n<p class=\"translation-block\">At MogaCode, the rule is clear-cut: the agent never deletes data on its own initiative, because everything runs in production. Before writing to a database, the agent takes a timestamped backup, checks that production hasn't drifted (if it has, it stops rather than overwrite a client's work), runs a dry run by default, and keeps a one-command rollback.<\/p>\n<p class=\"translation-block\">That principle covers what the agent does on its own. It doesn't cover deletions the agency itself requests. I'd suggest a simple rule: the agency can sign off alone on anything reversible; anything irreversible needs the client's own yes, in writing, outside the agent's conversation. A message, a ticket, an archived email: the channel matters less than having the record before the action runs.<\/p>\n<h2>Circle 3: a real person who will read the message<\/h2>\n<p class=\"translation-block\">In the third circle, the action reaches a person. An email, a text, a WhatsApp message. This is the circle I work in every day.<\/p>\n<p class=\"translation-block\">DokuTrak handles <a href=\"https:\/\/dokutrak.com\/document-collection\" target=\"_blank\" rel=\"noopener\">client document collection<\/a>: the professional asks for documents, the client uploads them through a secure link, and follow-ups go out on their own, in the firm's name. With <a href=\"https:\/\/github.com\/Crackx17\/dokutrak-mcp\" target=\"_blank\" rel=\"noopener\">our open-source MCP connector<\/a>, the professional's agent can create a request. But creating a request means emailing the client. And that email cannot be recalled.<\/p>\n<p class=\"translation-block\">In this circle, a plan is no longer enough. The professional isn't approving parameters; they are proofreading words, the exact words their client will read. One vague document name or a badly phrased deadline, and the client relationship takes the hit.<\/p>\n<p class=\"translation-block\">So we added two safeguards. First, the tool's description tells the agent to show, before calling it, the recipient, the deadline, the message and each document as the client will read it, then to wait for confirmation, even when the request already looks complete. That last clause came from an internal test: given an instruction that seemed to cover everything, the agent had sent a real request with no recap. Second, the tool declares itself destructive in MCP terms and asks for user interaction: Claude Desktop then shows its permission prompt, and Claude Code asks again on every call.<\/p>\n<p class=\"translation-block\">Why both? Because that prompt shows the tool's name, not the recipient or the content. It guarantees a human saw the call go by; the recap tells them what they are approving. The recipient is an address the agent types in, so our server cannot check it: the recap puts that address in front of a human, and the prompt makes sure a human is there to look.<\/p>\n<p class=\"translation-block\">MogaCode got to the same place through experience: an instruction from Patrick, its founder, counts as permission to send, but the agent checks the recipient's exact identity before every outgoing message. The team has already been burned by a namesake. In this circle, a well-written message sent to the wrong person does as much damage as a badly written one.<\/p>\n<h2>What no approval should unlock<\/h2>\n<p class=\"translation-block\">That leaves a category of its own: decisions an agent does not make, even with your approval. For us, that is accepting or rejecting a document. The agent can create a request, re-request a rejected file and check where a request stands. It cannot say \"this document is fine.\"<\/p>\n<p class=\"translation-block\">The server enforces it. An acceptance or rejection that doesn't come from a human session fails with a dedicated error, and the attempt is written to our audit log, where rows can be neither edited nor deleted. Leaving the tool out of the list shown to the agent would not have been enough: the route exists, and an API key can reach it. The control is the server refusing the request.<\/p>\n<p class=\"translation-block\">OWASP states the same principle in its entry on Excessive Agency: \"Implement authorization in downstream systems rather than relying on an LLM to decide if an action is allowed or not\" (<a href=\"https:\/\/genai.owasp.org\/llmrisk\/llm062025-excessive-agency\/\" target=\"_blank\" rel=\"noopener\">OWASP GenAI, LLM06:2025<\/a>).<\/p>\n<p class=\"translation-block\">AI still has a job here, just upstream: our first-pass AI flags a file that isn't the document requested, or one that is too hard to read. It doesn't decide.<\/p>\n<h2>The grid in one table<\/h2>\n<p class=\"translation-block\">The column that matters is the third one: what a human needs in front of them for their yes to mean anything.<\/p>\n<figure class=\"wp-block-table\">\n<table>\n<thead>\n<tr>\n<th class=\"translation-block\">Case<\/th>\n<th class=\"translation-block\">Example<\/th>\n<th class=\"translation-block\">What the human needs to see<\/th>\n<th class=\"translation-block\">Where the yes belongs<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"translation-block\">Circle 1: your infrastructure<\/td>\n<td class=\"translation-block\">Deleting a DNS record<\/td>\n<td class=\"translation-block\">The plan: what, where, before, after<\/td>\n<td class=\"translation-block\">Lock on the server (preview and token); reading in the conversation<\/td>\n<\/tr>\n<tr>\n<td class=\"translation-block\">Circle 2: a client's asset<\/td>\n<td class=\"translation-block\">Deleting a client's mailbox<\/td>\n<td class=\"translation-block\">The plan, and what the client loses<\/td>\n<td class=\"translation-block\">Reversible: the agency alone. Irreversible: the client, in writing, before the action<\/td>\n<\/tr>\n<tr>\n<td class=\"translation-block\">Circle 3: a real person<\/td>\n<td class=\"translation-block\">Sending a document request<\/td>\n<td class=\"translation-block\">The exact words, and who they go to<\/td>\n<td class=\"translation-block\">A recap in the conversation, plus the MCP client's prompt<\/td>\n<\/tr>\n<tr>\n<td class=\"translation-block\">Hard limit: a judgment call<\/td>\n<td class=\"translation-block\">Accepting a document<\/td>\n<td class=\"translation-block\">The document itself, in the app<\/td>\n<td class=\"translation-block\">Only in a human session; the server rejects the agent<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2>For an agency that hands its operations to agents<\/h2>\n<p class=\"translation-block\">If your operations already run through agents, four moves are enough to start.<\/p>\n<ol>\n<li class=\"translation-block\"><strong>Put every tool in one row of the table.<\/strong> Whether an MCP server exposes a handful of tools or dozens, it has no more than four risk levels, the ones in the table, not counting read-only.<\/li>\n<li class=\"translation-block\"><strong>Check what your permission prompt really displays.<\/strong> If it only shows the tool's name, the recap has to carry the content.<\/li>\n<li class=\"translation-block\"><strong>Put the hard limits on the server.<\/strong> An instruction in a prompt is a preference; a refused request is a rule.<\/li>\n<li class=\"translation-block\"><strong>Log refused attempts<\/strong>, not just successes. That is where you see an agent trying something it shouldn't.<\/li>\n<\/ol>\n<p class=\"translation-block\">The agent does the work; the human keeps the decision. An agent acting on your behalf doesn't need your permission for everything. It needs to ask in the right place, and show you the right thing.<\/p>\n<hr \/>\n<p class=\"translation-block\"><em>Arthur Teboul is the founder of <a href=\"https:\/\/dokutrak.com\" target=\"_blank\" rel=\"noopener\">DokuTrak<\/a>, which takes client document collection off professionals' plates: the software, or their agent, asks and follows up, and they accept every file themselves.<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>O\u00f9 un agent IA doit-il demander votre accord ? Sur votre infrastructure, sur le bien d&rsquo;un client, avant un message. Et ce qu&rsquo;aucun oui ne d\u00e9bloque.<\/p>","protected":false},"author":1,"featured_media":2035,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[],"class_list":["post-2034","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ia"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.5 (Yoast SEO v28.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Agent IA et serveur MCP : o\u00f9 placer la confirmation humaine<\/title>\n<meta name=\"description\" content=\"O\u00f9 un agent IA doit-il demander votre accord ? Sur votre infrastructure, sur le bien d&#039;un client, avant un message. Et ce qu&#039;aucun oui ne d\u00e9bloque.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.mogacode.ma\/en\/agent-ia-mcp-confirmation-humaine\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Agent IA et serveur MCP : o\u00f9 placer la confirmation humaine\" \/>\n<meta property=\"og:description\" content=\"O\u00f9 un agent IA doit-il demander votre accord ? Sur votre infrastructure, sur le bien d&#039;un client, avant un message. Et ce qu&#039;aucun oui ne d\u00e9bloque.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mogacode.ma\/en\/agent-ia-mcp-confirmation-humaine\/\" \/>\n<meta property=\"og:site_name\" content=\"Mogacode\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/mogacode\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/mogacode\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-29T11:21:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mogacode.ma\/wp-content\/uploads\/2026\/09\/dokutrak-article-cover-1600x900-1.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Patrick\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@mogacode\" \/>\n<meta name=\"twitter:site\" content=\"@mogacode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Patrick\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"When an AI Agent Acts for You, Where Does the Human Say Yes?","description":"O\u00f9 un agent IA doit-il demander votre accord ? Sur votre infrastructure, sur le bien d'un client, avant un message. Et ce qu'aucun oui ne d\u00e9bloque.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.mogacode.ma\/en\/agent-ia-mcp-confirmation-humaine\/","og_locale":"en_US","og_type":"article","og_title":"Agent IA et serveur MCP : o\u00f9 placer la confirmation humaine","og_description":"O\u00f9 un agent IA doit-il demander votre accord ? Sur votre infrastructure, sur le bien d'un client, avant un message. Et ce qu'aucun oui ne d\u00e9bloque.","og_url":"https:\/\/www.mogacode.ma\/en\/agent-ia-mcp-confirmation-humaine\/","og_site_name":"Mogacode","article_publisher":"https:\/\/www.facebook.com\/mogacode","article_author":"https:\/\/www.facebook.com\/mogacode","article_published_time":"2026-09-29T11:21:15+00:00","og_image":[{"width":1600,"height":900,"url":"https:\/\/www.mogacode.ma\/wp-content\/uploads\/2026\/09\/dokutrak-article-cover-1600x900-1.webp","type":"image\/webp"}],"author":"Patrick","twitter_card":"summary_large_image","twitter_creator":"@mogacode","twitter_site":"@mogacode","twitter_misc":{"Written by":"Patrick","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[]}},"_links":{"self":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/2034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/comments?post=2034"}],"version-history":[{"count":1,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/2034\/revisions"}],"predecessor-version":[{"id":2036,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/2034\/revisions\/2036"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/media\/2035"}],"wp:attachment":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/media?parent=2034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/categories?post=2034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/tags?post=2034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}