MCP & AI Assistants

MonoDuty MCP permissions: why read access cannot create or manage resources

MonoDuty DocsSep 30, 2026 2 min read

Four different permission choices

PermissionWhat it enables
ReadInspect workspace context, active alerts and supported monitoring information.
ProposalsSave an instrumentation proposal for administrator review.
Resource creationCreate supported services, public HTTP(S) Monitors, Heartbeats and Webhook alert sources.
ManagementPerform supported updates, pause/resume/delete operations, cancel pending plans and resolve incidents.

A proposal is not active monitoring. An administrator still needs to review it, claim its credentials and activate it in the dashboard. Creation permission follows a different workflow and can activate monitoring directly.

“I approved the tool, but creation is denied”

There are two permission decisions: what the client allows the assistant to call, and what the MonoDuty OAuth connection allows. Client approval does not add MonoDuty permissions. Existing read or proposal connections do not automatically receive creation or management access. Reconnect through OAuth and explicitly select the additional permissions you need.

Direct creation is not supported through local stdio connections using customer API tokens; use native OAuth for those tools.

Before changing a resource

Ask the assistant to inspect the current resource first. Supported management operations use the returned revision to protect against overwriting concurrent changes. If another change occurred, inspect again and review the desired update against the new state.

Permissions do not override workspace ownership or plan limits. Resolving an incident does not repair the source of the failure. Revoke the connection from the dashboard when it is no longer needed.

References

MonoDuty MCP setup and permissions · MonoDuty MCP overview

Reviewed against MonoDuty documentation on September 30, 2026.

MonoDuty Docs

Official MonoDuty documentation and support guides.

MonoDuty MCP permissions: why read access cannot create or manage resources