Some MCP actions require explicit user approval before they can run. This is part of the MCP safety model and is designed to prevent irreversible, destructive, or spending actions from happening silently.
The Search Atlas MCP includes metadata on certain tools that marks them as approval-required. In the source, this is described as a flag marking the tool as approval-required in the MCP tool metadata. Clients that support human-in-the-loop confirmation will surface a confirmation prompt before executing those actions.
Note: The MCP approval model described in this article applies specifically to MCP tool calls. Content publishing approval (for example, article publishing in Website Studio or other linked workflows) is a separate mechanism with its own controls and is covered in its own documentation.
This article explains which actions require approval, how the approval flow works, what to expect in supported clients, and how this safety layer interacts with your plan permissions and billing.
🧠 Why Approval Exists
The approval system exists to protect users from actions that:
- spend money
- delete or destroy data
- trigger irreversible operations
- publish or execute something with real-world consequences
The source makes this especially clear for:
purchase_credits(buying additional credits, which spends money or consumes balance)- destructive OTTO operations such as
otto_delete_project(deleting an OTTO project, which removes all associated configurations and cannot be undone)
In practical terms, this means MCP does not simply execute every tool call the assistant proposes. For certain high-impact actions, the assistant can prepare the action — meaning it determines the correct parameters and presents them for your review, but does not submit or execute anything — and the user must still explicitly confirm before it proceeds.
🔍 What “needs approval” Means
When a tool is marked with the approval flag:
- the assistant can identify the action
- the client can show a confirmation prompt
- execution pauses until the user approves it
⚙️ Step-by-Step: How the Approval Flow Works
Step 1
You ask your AI assistant to perform an action.
Examples could include:
- purchasing credits
- deleting a project
- running another action that is destructive or spend-related
Step 2
The assistant interprets your request and selects the appropriate MCP tool.
At this stage, the assistant is still planning the action — determining the correct parameters and preparing them for your review. It has not submitted or executed the action yet.
Step 3
The MCP checks the tool’s metadata.
If the tool is marked as approval-required, the execution path changes. Instead of running immediately, the client must interrupt and request confirmation from the user.
Step 4
Your MCP client displays a confirmation prompt.
In supported clients, this is where you are asked to explicitly approve the action before it can continue. The source names:
- Claude Desktop
- Claude.ai
- Claude Code
Step 5
You review the action and choose whether to proceed.
At this point, one of two things happens:
- Approve → the action executes
- Do not approve → the action does not run
Step 6
If approved, the MCP executes the action using your Search Atlas account, permissions, and available quota or credits.
If the action involves spending or account changes, those effects occur only after approval has been granted.
📌 Actions Most Likely to Require Approval
The source explicitly calls out two broad categories:
1. Spending actions
These are actions where money or premium credits are being consumed.
Examples from the source include:
purchase_credits(buying additional credits, which spends money or consumes balance)
2. Destructive actions
These are actions that delete or irreversibly change data.
Examples from the source include:
otto_delete_project(deleting an OTTO project — removes all associated configurations and cannot be undone)- other destructive OTTO operations (anything that removes, overwrites, or irreversibly changes project data)
The source also makes a broader principle clear: approval is used where execution should not happen silently because the effect is meaningful, costly, or not easily undone.
🔐 Step-by-Step: What to Do When a Prompt Appears
Step 1
Read the action carefully.
When your client surfaces an approval request, confirm what the assistant is about to do. This is especially important if the action affects billing, deletes data, or changes a live system.
Step 2
Check whether the action is expected.
Ask yourself:
- Is this the action I intended?
- Is this a spending action?
- Is this destructive or irreversible?
- Am I ready for it to happen now?
The source’s safety model is designed precisely so you can stop here if the action is not what you want.
Step 3
Approve only if you want the action to execute.
If you approve it, the MCP continues and runs the tool. If you do not approve it, execution stops.
Step 4
If needed, revise your request and try again.
If the assistant prepared the wrong action, do not approve it. Instead, provide a clearer instruction and let the assistant re-plan the workflow. This keeps control in your hands before any high-impact tool runs.
🧩 How Approval Interacts with Permissions
Approval does not override permissions.
Even if you approve an action, the action still must satisfy all normal access controls:
- your plan must include the product area
- your account must have the necessary entitlement
- your quota or balance must be sufficient
So approval is not a bypass. It is an additional safety layer on top of the normal Search Atlas access model.
Example
A user could approve a PPC-related action, but if their plan does not include OTTO PPC, the action still cannot execute successfully because entitlement checks happen separately.
💳 How Approval Interacts with Billing
Approval is especially important for actions that involve direct spending.
The source explains that money-spending actions and premium actions can involve:
- Search Atlas quotas
- Hyperdrive Credits
- Stripe checkout for top-ups or purchases
For those cases, approval ensures:
- nothing is purchased silently
- the user sees the action before it runs
- the user remains in control of when money is spent
This is why the source specifically mentions purchase_credits as an approval-required action.
Note that credit-purchase approvals are still subject to your plan’s quota rules. Plan upgrades, promotional credits, or quota changes may affect which actions you can take or how much is available to spend. For full details on quotas, plan limits, and available credits, refer to the billing and quota documentation.
🛑 Cancellation, Project Deletion & Other Workflows Outside MCP Approval
Some actions that users might expect approval controls to govern are actually handled outside the MCP approval flow. In particular:
- Plan cancellation does not automatically delete OTTO projects or remove on-page integrations. Those artifacts persist until they are explicitly cleaned up.
- Project deletion is its own workflow, separate from the MCP approval prompt.
- Pending or queued destructive actions initiated through other parts of the platform are not retroactively held by the MCP approval layer.
If you are cancelling a subscription, removing on-page integrations, or deleting a project, follow the dedicated offboarding and project-deletion documentation for those workflows rather than relying on the MCP approval prompt to surface them.
🧪 What Happens in Clients That Support HITL
The source names three clients that support human-in-the-loop confirmation:
- Claude Desktop
- Claude.ai
- Claude Code
In these clients, when an approval-required tool is invoked, the client displays a confirmation prompt with the action details, and execution pauses until you approve or decline.
Clients that do not support confirmation prompts
In clients that do not implement human-in-the-loop confirmation, approval-required tools cannot be safely executed. In those environments, those tools will either return an error or be unavailable, rather than running silently. If you encounter this, use one of the supported clients listed above to complete the action.
🔄 Related Approval Flows in Search Atlas
Other Search Atlas products have their own approval-style queues that are distinct from the MCP tool approval model described in this article. These are surfaced in their own product UIs, not through MCP confirmation prompts.
- OTTO PPC — Pending Review queue: The
auto_pause_low_quality_keywordsfeature surfaces auto-paused low-quality keywords in a Pending Review queue where you can approve or reject the pause. This is a separate, product-level approval flow and is not governed by the MCPneeds_approvalmechanism. - Content publishing approvals: Article publishing in Website Studio and linked content workflows have their own publishing controls, separate from MCP tool approvals.
If you are looking for a particular approval experience and it is not appearing as an MCP confirmation prompt, check whether it lives in one of these product-level queues instead.
⚠️ Known Issues
Content Genius — context loss after content plan approval: After approving a content plan in Content Genius, the agent may lose prior conversation context in some sessions. This is a known issue currently being resolved. If this occurs, re-provide your topic, keywords, and domain to continue the workflow.
This callout will be removed once the fix ships.