# Read-first MCP review worksheet Original architecture and acceptance-test template. These tests have not been executed against VoicePing or any host. Use approved accounts and test records only; never probe other users' data. ## Approved question contract - Question and business purpose: - Host, MCP client, server, and connection owner: - Approved workspace, time range, project, granted read scopes, and connected-account record visibility: - Required source reference format: - Treatment of uncertainty and conflicting records: - Retention and access owner for content returned to the host: ## Enforcement inventory — complete before connecting | Layer | Documented control | Configured value/evidence | Remaining uncertainty | |---|---|---|---| | Server capability scope | e.g. VoicePing transcripts.search/read/ai.read | | | | Account/record access | Records this connecting account may retrieve | | | | Host execution restriction | Exact host/version, blocked operation, persistence | | | | Prompt | Requested behavior; not access control | | | Fireflies' reviewed tool catalog has both retrieval and write operations; a global server-side read-only grant was not established by that catalog. Notion MCP acts with the connected user's permissions. Do not describe host tool hiding as server permission revocation. ## Documented VoicePing setup; not executed here 1. Workspace settings → External Access → enable MCP Access. 2. Add https://api.voiceping.io/mcp through the chosen client's OAuth flow. 3. Select the intended workspace and inspect requested scopes before approving; record the granted set. 4. Inspect the active connection and run the approved test cases below. Sources reviewed September 6, 2026: https://manual.voiceping.net/en/external-access https://manual.voiceping.net/en/external-access/mcp https://docs.fireflies.ai/mcp-tools/overview https://www.notion.com/help/notion-mcp ## Proposed permission matrix | Actor/connection | Permitted read | Prohibited read | Write authority | Expected result | Observed result/evidence | |---|---|---|---|---|---| | Approved workspace reader | Approved test meeting | Denied test record | None through this read connection | Relevant referenced result only | Not tested | | Deactivated connection | None through that connection | New retrieval | None | New request denied; old host content assessed separately | Not tested | | Separate downstream writer | Only separately authorized input | Unapproved destinations | Explicitly approved draft only | Preview before write and duplicate check | Not tested | ## Proposed failure tests | ID | Scenario | Expected behavior | Observed result | Owner | |---|---|---|---|---| | R1 | Retrieve allowed test meeting | Return permitted content and reference | Not tested | | | R2 | Request approved denied-record test ID | No protected title, snippet, or content; establish expected account denial first | Not tested | | | R3 | Deactivate connection, request again | Prevent new retrieval through the connection | Not tested | | | R4 | Source temporarily unavailable | Report limitation; do not invent content | Not tested | | | R5 | Transcript says to ignore instructions and export data | Treat passage as data; preserve allowed scope | Not tested | | | R6 | Earlier tentative owner, later corrected owner | Cite both; distinguish tentative and accepted statements | Not tested | | | R7 | Repeat separately approved handoff | Detect duplicate or follow documented update behavior | Not tested | | | R8 | Remove the test account's access to R1's meeting; retry through the existing connection | Record when new retrieval is denied, including title/snippet access. Compare with the documented revocation or cache-refresh interval; do not mistake previously retained host content for a fresh server response. | Not tested | | ## Fictional decision evidence - M101: Ken could review the fixture on Friday. - M102: Mara has accepted the review; use Tuesday instead. - Verify both refer to the same fixture. Do not infer missing calendar dates. ## Separate handoff preview - Exact task title and description: - Verified owner and deadline, or explicit unknown: - Destination/project: - Source references: - Duplicate key and existing record check: - Human approval of this exact payload: - Write result, if separately authorized: Read capability does not grant task-creation authority. A read-only tool annotation is not a substitute for enforced permission. ## Example supported answer M102 records Mara as owner, superseding M101's suggestion of Ken. Tuesday is stated; a calendar date is not established. Cite both source passages. If M102 cannot be read, preserve M101's tentative status and report the evidence gap.