Permissioned write actions for assistant and MCP
Supported changes moved into one guarded action catalog shared by the in-product assistant and external MCP connections.
A change is exposed only when the connected user’s role permits the underlying job.
Company settings choose between review proposals and immediate execution; destructive actions remain identifiable.
Every requested change creates a proposal record so authorship and outcome remain traceable.