Read-only, actions, and agent-resident describe three levels of product integration—not formal categories in the Model Context Protocol (MCP). They help teams decide how much capability an AI agent should receive: query product data, change product state, or operate as a first-class product user with its own identity and state. The right level is the one the product can secure and support, not necessarily the most ambitious one.
What do the three MCP embedding types mean?
The labels are a product-strategy framework used by Launch Day Advisors, not MCP protocol primitives. MCP’s architecture instead describes hosts, clients, and servers, with servers exposing tools, resources, and prompts. The labels are useful for comparing an integration’s capabilities and operational demands; they do not tell you how a server is deployed or which MCP primitive it uses.
| Embedding level | What the agent can do | Typical fit | Example effort and cost estimate |
|---|---|---|---|
| Read-only | Query product data without changing it. | Answering questions about customer records, tickets, inventory, or documents. | About one quarter and $100,000–$300,000, estimated by Launch Day Advisors; figures last reviewed June 2026. |
| Actions | Read data and make changes, such as creating, updating, deleting, or sending. | Workflows where an agent can carry out product operations under defined permissions and safeguards. | About two quarters and $300,000–$700,000, estimated by Launch Day Advisors; figures last reviewed June 2026. |
| Agent-resident | Participate as a first-class product user, with an identity and accumulated state. | A product strategy built around agents as ongoing participants rather than occasional integrations. | A multi-quarter rebuild and $1 million or more, estimated by Launch Day Advisors; figures last reviewed June 2026. |
These delivery and cost figures are advisory estimates, not MCP requirements, measured market averages, or independently verified benchmarks. Treat them as illustrative planning ranges, not a forecast for a particular organization.
What does read-only mean in an MCP integration?
A read-only integration lets an agent retrieve information but not alter the connected product’s state. It can answer questions using records or other data the user is authorized to access, while leaving creation, updates, deletion, and sending to a person or another workflow.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
- More for the money with this high quality Product
- Offers premium quality at outstanding saving
- Excellent product
- 100% satisfaction
Read-only is a property of actual server behavior and permissions—not a label alone. OpenAI’s tool guidance says the readOnlyHint annotation should be true only when a tool cannot change state, and annotations do not replace authorization or validation. A query tool must remain unable to write even if a model calls it unexpectedly.
What changes when MCP tools can take actions?
Action-capable integrations can perform mutations as well as queries. That can make an agent useful for completing work, but also makes errors consequential: the agent may change or delete records, or send something externally. The permitted action set should be defined per operation rather than treated as a blanket “write access” switch.
Design controls around the operation
- Authorize on the server: enforce the requesting user’s permissions for every request. Do not rely on the model to decide who may access data or perform an operation.
- Use least privilege: give the agent identity only the access required for its task, and separate permissions where different operations carry different consequences.
- Make changes inspectable: show an intent preview before consequential actions where appropriate, and keep per-action audit logs.
- Plan for retries and recovery: use idempotency keys to reduce duplicate effects when a request is retried; consider reversibility or a compensating action for operations that can be undone.
- Review high-impact actions: require human approval when the consequences justify it. Approval reduces some risks but cannot eliminate mistakes or misuse.
Google Cloud distinguishes human-in-the-middle operation, where a person approves each action, from agent-only operation, where the agent proceeds without waiting. Human approval can still fail through error; agent-only operation relies on the agent’s programming and can be vulnerable to prompt injection, insecure tool chaining, and naive error handling. Neither mode makes the rest of the security design optional.
What does agent-resident mean?
In this framework, agent-resident means the agent is treated as a first-class user of the product: it has an identity, can accumulate state, and participates in the product’s internal mechanisms. It is a deeper integration strategy, not a named MCP capability or a feature that follows automatically from exposing a server.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Rank #3
- Product type: Screw kit
- Made by Super Micro
- Manufacturer part number: MCP-410-00005-0N
- Supermicro MCP-410-00005-0N Screw Bag(100PCS) and Label for 24x Hot swap
- Mfr Part Number: MCP-410-00005-0N
This approach can make sense when a company is deliberately building an agent-first product experience. It also raises identity and state-management requirements. Official security guidance supports using agent identities and isolating state between users, tenants, or agents; an implementation must define those boundaries rather than letting one agent’s context bleed into another’s.
How do MCP primitives relate to these levels?
MCP’s server primitives describe what a server offers, not the product’s overall embedding level. A read-only experience may use resources, query-only tools, or both. An action-capable experience can expose tools that mutate state. A prompt provides a reusable interaction template; it does not itself grant permissions or determine whether an operation writes.
Rank #4
- Tools are executable functions an application can invoke, such as API calls or database queries.
- Resources provide context from sources such as files, database records, or API responses.
- Prompts are reusable templates for interactions.
Inspect the operation, authorization checks, and server-side enforcement behind each primitive. The name “tool,” “resource,” or a read-only annotation cannot by itself establish what the integration is allowed to do.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How does deployment differ from embedding level?
MCP architecture separates the host (the AI application), clients (connections managed by the host), and servers (programs providing context to clients). The architecture documentation describes local servers using STDIO as typically serving one client, while remote servers using Streamable HTTP typically serve many. Those are deployment patterns, not a progression from read-only to actions or agent-resident; a deployment choice does not imply a particular capability level.
How should a team choose an embedding level?
- Start with the job: if the agent only needs to answer questions from product data, a query-only design may be enough.
- List each proposed mutation: identify what can be created, changed, deleted, or sent, who may authorize it, and what recovery would look like.
- Match safeguards to consequences: decide where least-privilege access, previews, audit logs, idempotency, reversibility, and human review are necessary.
- Assess the operating model: determine whether the product can support agent identities, isolated state, and ongoing participation before choosing an agent-resident direction.
- Expand deliberately: add capability when the security and operational model can defend it, rather than assuming every integration should begin with write access.
Launch Day Advisors’ recommendation is to ship at the level the product can defend, then expand as the safety story becomes ready; it presents agent-resident integration as a consideration for companies pursuing an agent-first strategy. That is the framework author’s advice, not a universal MCP rule. As Jonathan Blessing, founder and managing partner of Launch Day Advisors, puts it: “The level you ship at is not a measure of ambition. It is a measure of what the product can defend, and what the company is committed to becoming.”
Quick Recap
Sources and version context
- Launch Day Advisors, “MCP Embedding Types,” last updated May 10, 2026; its figures were last reviewed in June 2026.
- MCP architecture documentation, version 2026-07-28.
- OpenAI MCP server building guidance.
- Google Cloud guidance on choosing an agentic AI system design pattern.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




