Skip to main content
Sunday

Spend controls for AI agents: approvals, budgets and permissions in Sunday MCP

MCP security best practices for teams letting AI agents near spend: OAuth sign-in, quote-then-approve, human-confirmed shipments and how Sunday MCP does it.

Niels VandecasteeleNiels Vandecasteele
8 min read
Spend controls for AI agents: approvals, budgets and permissions in Sunday MCP
AI and MCP

Letting an AI assistant near your merch budget sounds risky until you see where the controls sit. Here's how Sunday MCP handles sign-in, approvals and shipments, plus the general MCP security habits worth adopting for any connector.

Part of our complete guide to Sunday MCP: manage your merch from Claude, ChatGPT or Gemini.

Sealed kraft shipping box with the Productsup logo and 'Empowering commerce' printed on the side, on a white background

MCP security for a business team comes down to three questions: who the agent signs in as, what it can do without asking, and where a person has to say yes. In Sunday MCP, the agent signs in with your own Sunday account through OAuth, cannot place orders, and needs a human to approve every quote and confirm every shipment.

The first question finance asks about AI agents is a fair one: can it spend money? For Sunday MCP the answer is no. It can prepare almost everything, and a person still commits every euro. This article explains how that works, and covers the security habits worth applying to every MCP connector you add.

What's actually risky about giving an AI agent access to spend?

Three things, in rising order of cost. The agent reads data it shouldn't. The agent misunderstands a request and prepares the wrong thing. The agent commits money or ships goods based on that misunderstanding.

The first is an access problem, solved by how the connector signs in. The second will happen, the same way a colleague occasionally misreads an email. The third is the one that hurts, and it's the one a well-designed connector should make impossible without a person in the loop. Merch makes this concrete. A wrong reorder of 500 hoodies is a production run, not a refundable click.

How does MCP authorization work?

MCP is the open standard that lets assistants like Claude, ChatGPT and Gemini talk to other software. If that's new, our plain-English guide to MCP servers covers the basics. For authorization, most remote MCP servers use OAuth: you're sent to the vendor's own login page, you sign in, and the assistant receives permission to act through your account. You never paste a password into the chat.

Sunday MCP works this way. You add Sunday as a custom connector using the URL you receive when access is granted, then sign in with your own Sunday account. The assistant works through that login, so it sees what your Sunday account can see. There's no shared key floating around a team channel. The setup guide walks through the steps.

Access to Sunday MCP itself is on request, and included on every Sunday plan. Sunday rolled it out internally first, and is now opening it to partners and agencies and to teams with large merch programs.

Why is quote-then-approve the core spend control?

Because it moves the commitment out of the conversation. In Sunday MCP, an agent can suggest products, calculate prices, build a budget split and generate a quote. It can show you the quote or send it. What it cannot do is turn that quote into an order. A person approves it personally, through a link.

You, in ChatGPT · Illustrative example: Reorder 300 T-shirts like last time and ship them to the Lisbon office.
Sunday MCP: I've prepared a quote for 300 T-shirts matching your last order. I can't place the order myself. Once someone approves the quote through this link, I'll plan the shipment to Lisbon for you to confirm.

That design means the agent can be fast and occasionally wrong without anything expensive happening. You review a document, not a receipt.

The agent can prepare everything. It can't commit anything. Orders, shipments and design sign-off all need a person. There are no automatic orders in Sunday MCP today.

What still needs a human in Sunday MCP?

ActionWhat the agent doesWhat a person does
Product and kit ideasSuggests products and pre-made kits that fit your audienceChooses
Prices and budgetsCalculates prices, proposes a budget split, builds a shareable wish listDecides the budget
Quotes and reordersGenerates the quote and shows or sends itApproves it through a link
OrdersCannot place themApproving the quote is the order step
DesignsRequests designs on selected productsSigns off against brand guidelines
ShipmentsPlans themConfirms them
Stock and reportingAnswers data questions, requests reportsReads them

Merch involves designs, approvals and brand guidelines. Sunday's position is to automate as much of the preparation as possible and keep a person confirming that the brand is respected and the spend is right.

Hand pushing a flat kraft mailer printed with 'We got you a little present' into the slot of a metal letterbox

A real Sunday mailer going through a letterbox. Before a parcel like this ships through Sunday MCP, a person has approved the quote and confirmed the shipment.

How should you handle budgets with an agent?

Assembling budgets is one of the best jobs to give an assistant. Say you have 20,000 euros and a target audience: one prompt can search the catalog, weigh what's popular and propose a split. That's a suggestion, not a spend.

The hard limit in Sunday MCP is the approval. No money is committed until a person approves a quote, so your budget control is whoever holds that approval. A few habits help:

  • State the budget in the prompt, so suggestions and quotes come back inside it.
  • Keep the approver the same person who approves merch spend today.
  • Check each quote against the budget before approving, the way you would a supplier quote.
  • Share the wish list with colleagues before anyone asks for a quote, so the discussion happens early.

Other vendors place the limit elsewhere. Goody's gifting MCP, for example, launched in June 2026 with daily budget limits alongside a review of each gift. We compare the approaches in Sunday MCP vs Goody and Sendoso.

An agent that prepares, and a person who decides

Quotes, stock checks and reorders from Claude, ChatGPT or Gemini. Nothing is ordered until your team approves it.

Request Sunday MCP access

Included on every Sunday plan · Works with Claude, ChatGPT and Gemini · You approve every order

MCP security best practices for non-technical teams

These apply to every connector you add to Claude, ChatGPT or Gemini, whether it's Sunday, a CRM or a payments tool.

  • Use official servers. Connect with the URL the vendor gives you, not one copied from a forum. Our roundup of the best MCP servers for marketing, HR and ops sticks to official ones.
  • Sign in as yourself. Prefer OAuth with your own account over shared logins or pasted API keys.
  • Start read-only. Spend the first week asking questions before you ask for actions.
  • Keep a human on money and shipping. Check what each connector can do without a confirmation step before you rely on it.
  • Watch what else is in the conversation. Mixing an inbox, the web and a spending tool in one chat is where injection risk lives.
  • Remove what you don't use. Disconnect connectors after a pilot or when someone changes roles.
  • Write it down. A short internal policy beats a long one nobody reads.

What about prompt injection?

Prompt injection is when text the assistant reads, in an email, a web page or a shared document, contains instructions aimed at the AI rather than at you. It's a known risk for every AI tool that both reads outside content and takes actions.

You reduce it by keeping untrusted content and spending tools in separate conversations where you can, and by choosing connectors where actions need confirmation. With Sunday MCP, the worst a manipulated agent can do on the spending side is prepare a quote. That quote still lands in front of a person who has to approve it.

What should a simple internal policy say?

Half a page is enough. Who may connect Sunday MCP. Who approves quotes, and up to what amount without a second approver. Which other connectors may share a conversation with it. Who confirms shipments. When to review the setup.

If your company already routes merch through procurement, SSO or an HR system, our post on swag store integrations covers how those fit around Sunday. For the finance and procurement view of AI agents, including accountability and audit questions, read the agentic commerce FAQ for procurement and finance. And if you're not on Sunday yet, you can create a free account first.

About this article

Category: AI and MCP · Read time: 8 min · Published October 6, 2026 · Primary topic: MCP security best practices · Also covers: MCP authorization, AI spend controls · Evidence: Sunday MCP controls as confirmed by Sunday on 6 October 2026; general MCP security guidance · Reviewed by the Sunday team

Frequently asked questions

Can an AI agent place a merch order through Sunday MCP?
No. The agent can prepare a quote and show or send it, but it cannot place an order. A person approves the quote through a link. Shipments also need human confirmation, and design sign-off against your brand guidelines stays with your team.
How does MCP authorization work in Sunday MCP?
You add Sunday as a custom connector using the URL you receive when access is granted, then sign in with your own Sunday account through OAuth. The assistant works through that login, so it acts as you rather than through a shared key.
What are the most important MCP security best practices for business teams?
Use official servers with the URL the vendor gives you, sign in with your own account, start with read-only questions, keep a human approval step on anything that spends money or ships, be careful with untrusted content in the same conversation, and remove connectors you no longer use.
Can I set a budget limit for the agent?
In Sunday MCP the hard limit is the approval itself: no money is committed until a person approves a quote. You can also give the assistant a budget in your prompt and ask it to build a budget split, but the decision to spend stays with whoever approves the quote.
What is prompt injection and does it matter for merch?
Prompt injection is when text from an email, web page or document contains instructions aimed at the AI rather than at you. It matters for any connected tool. With Sunday MCP, the worst a manipulated agent can do on the spending side is prepare a quote, which still needs a person to approve it.
Who should approve quotes created by an AI agent?
The person who owns the budget, or whoever already approves merch spend in your team today. Keep the approver the same as before the agent arrived, so the assistant changes how quotes get prepared but not who decides.

More Stories

Try Sunday