Source record · tier 2 current vendor documentation
Admin Approval Guide for Agentic Apps
- Publisher
- Cisco Systems, Inc. (Webex for Developers)
- URL
- https://developer.webex.com/mcp/docs/admin-approval-guide-for-agentic-apps
- Published
- unknown
- Updated
- unknown
- Accessed
- 2026-09-05
- HTTP status
- 200
- License
- Cisco proprietary documentation, all rights reserved; no-redistribution; short excerpts and locators only
Claims citing this source
- Webex exposes a per-tool setting named Allow signature change which an administrator sets for each tool. fact in context
- The endpoint named listFunctions through which drifted tools are filtered is a Webex construct and appears in none of the Model Context Protocol specification pages read in this tranche. inference in context
- A server metadata change is defined as a developer edit to the description the server URL the authentication type the publish data or the submission status and Cisco advises re-review on URL or authentication type changes. fact in context
- Cisco states that Webex automatically detects changes in server metadata enablement state and tool schema signatures and surfaces them in the administrator's views so that the administrator does not need to poll. fact in context
- The post-approval monitoring table lists 6 signals: tool signature change server metadata change enablement change unusual usage patterns user complaints and server downtime each with the mechanism that detects it. fact in context
- Cisco lists 6 triggers for a full re-review: a signature change when the policy is Off a major version bump a reported security incident a change in organisational security policy a user report of unexpected behaviour and more than 6 months since the last review. fact in context
- An administrator revokes approval by toggling the app to Blocked in Control Hub which Cisco states takes immediate effect. fact in context
- When a tool's live signature differs from the stored signature and Allow signature change is Off the tool is filtered out of listFunctions results and is not delivered to the client SDK. fact in context
- When a tool's live signature differs from the stored signature and Allow signature change is On the tool is still delivered to the client SDK and carries unsecure set to true so that client SDKs and agent user interfaces can surface a warning to end users. fact in context
- A cosmetic description update with no semantic change is rated a low risk signature change with the recommended action of review and re-approve. fact in context
- A new optional input field is rated a medium risk non-breaking schema expansion with the recommended action of verifying the field's purpose and re-approving. fact in context
- Adding or removing a required field is rated a high risk breaking schema change requiring a full re-review. fact in context
- A tool rename changes the signature is rated high risk and is described as effectively a new tool requiring full review. fact in context
- A change to input validation whether constraints are tightened or loosened is rated medium to high risk with the recommended action of assessing the security impact. fact in context
- Cisco does not publish the algorithm the hash function the field set or the field ordering used to compute a Webex tool schema signature nor the monitoring interval nor where the signature is stored. fact in context
- When a tool's current signature differs from the version the administrator previously approved Webex flags the tool as possibly modified since the last review. fact in context
- The Webex tool signature can be inferred to cover at least the tool name its description its input schema the required or optional status of fields and validation constraints because the published scenario table treats a change to each of these as a signature change. inference in context
- Cisco's stated best practice is to default Allow signature change to Off for new or unfamiliar servers and to switch it On only after establishing trust with the publisher through multiple successful review cycles. fact in context
- Cisco recommends setting Allow signature change to Off for sensitive operations and regulated environments and notes the trade-off that users lose access until the administrator re-reviews. fact in context
- Cisco describes Allow signature change set to On as acceptable for read-only tools and trusted publishers with a good track record and states that it accepts the risk of unreviewed changes. fact in context
- The client visible drift flag is spelled unsecure and the spelling insecure does not appear in the Webex documentation. fact in context
- Webex computes a schema signature for each tool and continuously monitors it for changes. fact in context
- The Webex signature and approval mechanism goes beyond what the Model Context Protocol requires because the protocol defines only an optional announcement of tool list changes while Webex stores an approved signature compares it at runtime and withholds or flags the tool. inference in context
- Cisco's admin approval guide documents an enablement audience of either the entire organisation or selected user groups, with group membership resolved from the organisation's identity provider at request time. disputed in context
- The admin approval guide describes 4 authentication types under machine names including an organisation-scoped token and a user-scoped token, which do not match the 5 method names the provisioning page uses. fact in context
- The admin approval guide describes the authentication configuration as belonging to something it calls Agent Central, a name that appears nowhere on the Control Hub provisioning page or in any other source read. fact in context
- 2 Cisco documents give different Control Hub navigation paths for the same surface, 1 naming Apps and then Agentic Apps and the other naming Management, then Apps, then Agentic Servers. fact in context
- Cisco describes the federated through registry badge as covering apps imported from an external registry with no Cisco manual review, and assigns it the lowest assurance of the 5. fact in context
- Cisco defines 5 App Hub identity badges for agentic apps: Cisco official, Cisco onboarded, partner onboarded, developer onboarded and federated through registry, in descending order of assurance. fact in context
- Cisco advises assessing tool risk from the tool's name, description, input schema and stated side effects, and recommends restricting delete operations, financial transactions, sending email and modifying user data to specific groups. fact in context
- Cisco states that tools carry no formal risk class field, so a tool's risk level must be assessed by the administrator's judgement rather than read from a property of the tool. fact in context
- The admin approval guide describes a per-tool assignment mode in which each tool can be enabled for a different set of groups, overriding the server-level audience. disputed in context
- Cisco computes a schema signature for each tool and continuously monitors it, flagging the tool when its current signature differs from the version an administrator previously approved. fact in context
- When the allow signature change setting is off and a tool's live signature drifts, the tool is filtered out of the list functions result and is not delivered to clients. fact in context
- When the allow signature change setting is on and a tool's signature drifts, the tool is still delivered and carries an unsecure flag set to true so that clients and agent interfaces can warn the user. fact in context
Cite this source record
APA
WarmTransfer. (2026, September 5). Admin Approval Guide for Agentic Apps. WarmTransfer. https://warmtransfer.net/knowledge/sources/webex-dev-admin-approval-agentic-apps
BibTeX
@misc{warmtransfer-webex-dev-admin-approval-agentic-apps,
title = {Admin Approval Guide for Agentic Apps},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/webex-dev-admin-approval-agentic-apps},
note = {Cisco Systems, Inc. (Webex for Developers), accessed 2026-09-05}
}