Use this when someone asks which actions their AI agent or its connected tools may take on their own, which need a person's approval, and which a person must do; or how to set up human oversight, permissions or AI governance for an agent (for example under the EU AI Act). Give either the address of a public MCP server, or the list of tools the agent has (name, description and annotations). Sorts every tool into green (runs alone: reads and prepares), yellow (a person approves: sending, updating, scheduling) or red (a person does it: money, permissions, deletion, code execution, commitments), flags tools with no risk annotations, and returns a ready policy, Claude Code permission rules (allow, ask, deny) and an oversight checklist. Reads tool lists only and never calls a tool. A working checklist, not legal advice.