What the demo shows
- Per-model read, create, update, delete, and method controls.
- Human approval as a separate gate for write operations.
- Short-lived tokens, rate limits, and attributable audit events.
MCP is a protocol, not a permission system. The server and Odoo must enforce the boundary. Read the full Odoo MCP security checklist, or review the Odoo MCP product and live sandbox.