Tool catalog
This is the full list of registry tools exposed over the NexSpace MCP surface — 100 tools across nine categories. Use it to work out what a scope grant actually unlocks before you connect, and to review the surface you are about to hand to an agent. You need this list becausetools/list is not filtered by your credential’s
scopes: it advertises the whole governed catalog regardless of what you were
granted, so it cannot tell you what scheduling:write or crm:write will
unlock. See
What tools/list actually returns.
These are the registry tools only. The 19 named workforce verbs
(
fillShift, runPayroll, searchStaff, …) are a separate layer with their own
scopes — see MCP → Named workforce verbs.
Connected-app actions are a third layer, gated on apps:read / apps:write and
listed per caller. Five in-app tools are deliberately withheld from MCP
entirely; see
Not available over MCP.How scopes are derived
Every registry tool’s required scope is mechanical:- a read-only tool requires
<category>:read - any other tool requires
<category>:write
<resource>:* wildcard). Getting the
category right is the whole game.
Category summary
analytics
19 read-only tools. All requireanalytics:read.
calendar
4 read-only tools. All requirecalendar:read.
communications
Read + write. 1 read tool and 6 write tools.
Writes (each returns
pending_approval when governance requires sign-off):
compliance
4 read-only tools. All requirecompliance:read. The category is read-only,
so its write tools (including run_batch_exclusion_check) are unreachable over
MCP.
crm
Read + write. 13 read tools and 7 write tools.
Writes:
The legacy
update_deal_stage is not on this surface — use
move_deal_stage. Note also that the named verbs searchLeads and
qualifyLead require the literal scope crm:*, which crm:read does not
satisfy. See the crm:* trap.facility
3 read-only tools. All requirefacility:read — not facilities:read,
which is the verb scope for listFacilities / getFacility.
general
7 read-only tools. All requiregeneral:read.
marketing
12 read-only tools. All requiremarketing:read.
scheduling
Read + write. 7 read tools and 17 write tools — the largest category, and the one whose:write grant covers the most surface.
Shift writers:
Schedule-settings writers:
How this list is maintained
The exposed set is pinned in CI. A newly registered tool in an exposed category fails the build until someone classifies it — either adding it to the pin or adding it to the denylist — so this page cannot drift silently, and the surface cannot grow by accident.A live
tools/list on your own credential is still the runtime source of truth.
It reflects tools promoted since this page was published and, unlike this page,
includes your connected-app tools. Use this catalog to plan scopes; use
tools/list to drive a client.See also
- MCP — the named verbs, the four tool layers, and the error model.
- Tenant isolation — how
facilityIdis rewritten or rejected on every tool here. - Governance — why a write may return
pending_approvalinstead of a result. - Model tier gate — why a tool you are scoped for
can still return
-32003.

