Every AI tool has a right of its own. That right is necessary but never sufficient: the user must also hold the ordinary functional right that belongs to the same act. Someone who may not create bookings cannot create them through AI either.
The chain
tool_use— the master switch. Without this right the tool list is empty.tool_<name>— one right per tool, so AI access can be granted tool by tool.- The functional right behind the tool (
entity_…oraction_…) — the very same right the screens use. - For rescheduling, changing and cancelling an existing reservation: the caller's one-time verification code.
Who holds these rights?
Nobody, by default. On a fresh install all tool rights sit in the MCP group. On an environment that was upgraded the rights do exist, but they belong to no group at all — deliberately: had they been handed out automatically, everyone who already holds the functional right would gain AI access to it overnight.
The license owner sets the group up in one go with the Set up MCP group button on Configuration → AI settings → Tools. After that, adding a user to the group is the only step left.
The AI widget and the phone assistant
Those two have no logged-in user, so there is nobody whose rights could be checked. A fixed list of visitor tools applies to that door instead: checking availability, booking, forms, events, verification, changing one's own reservation after a one-time code, and handing over to a colleague. The timesheet and billable tools are not on that list — those are staff data and there is no visitor question they answer.
tool_filter_customers
Search customers through AI, by exact e-mail address or phone number.
tool_add_customer
Create a customer through AI.
tool_add_booking
Create a booking through AI, for an existing customer.
tool_add_booking_with_customer
Create a booking together with a new customer through AI.
tool_reschedule_reservation
Reschedule a reservation through AI.
tool_change_participants
Change the number of participants on a reservation through AI.
tool_cancel_reservation
Cancel a reservation through AI.
tool_get_cancellation_policy
Retrieve the cancellation policy through AI.
tool_search_events
Search events through AI.
tool_get_event
Retrieve an event's details through AI.






