Safe MCP leave booking
Use this recipe when an AI client should help prepare a leave request without
silently changing HR data. Governed MCP writes are included on Standard and
higher plans without a HollyHR approval step. commit_api_write still requires
an explicit System Admin grant of mcp:write and time_off:write, the
production HOLLYHR_MCP_WRITE_MODE=enabled safety switch, and a host that
supports MCP form elicitation.
If any gate is missing, use the flow as a read-only planning assistant and ask a human to book the leave in HollyHR or through the REST API.
What it uses
whoamisearch_peoplelist_referencelist_time_offprepare_api_writecommit_api_write, only after the write gates above are satisfied
The underlying REST operation is createTimeOff on POST /time-off.
Scopes
Start read-only:
Code
For a Standard or higher tenant that needs this workflow, explicitly add:
Code
Do not add people:personal:read, payroll, document, or webhook-management
scopes for this workflow.
Prompt
Code
Preparation payload
prepare_api_write should freeze the createTimeOff request body:
Code
The server signs the frozen payload, captures the idempotency key, and returns a short-lived confirmation token. The model cannot change the person, dates, category, half-day flags, ETag, or idempotency key between preparation and commit.
Safety checks
- Confirm the person from work identity fields, not home or personal details.
- Check existing
list_time_offresults for the requested date window. - Use the public category id returned by reference data.
- Keep free-text reasons out of booking requests. Booking create/update does not
accept notes, approval comments, rejection reasons or health details. A
decline may include the bounded private
response_note; never put health or medical details in it. - Approval and decline use the separate
approveTimeOffanddeclineTimeOffoperation IDs. Prepare them only after reading the current request and showing the user the person, dates, category and proposed decision. Preparation freezes the current ETag; commit still requires the host's per-action human confirmation. Never use the decision operations for sickness records.
Failure modes
If prepare_api_write reports write mode disabled, missing mcp:write, or
missing time_off:write, show the proposed request and stop. A System Admin can
review plan eligibility and grant only the scopes the workflow needs.
If commit_api_write reports that the host cannot fulfil input_required
approval, switch the client to 2026-07-28 or use a human-run REST/in-app
flow. Stateless legacy clients can prepare but cannot commit. Do not ask the
model to "just do it" through call_api_operation; generic MCP calls are
read-only.