# Bedrock + Odoo JSON-2 tool boundary

Companion to **Amazon Bedrock Odoo Integration: Order and Stock Reads on AgentCore and JSON-2**.

This folder is a worksheet. It is not a client engagement, not a benchmark, and not a runnable database. There are no Odoo API keys here.

## Use it

1. Open [`tool-boundary.md`](tool-boundary.md).
2. For your operations agent, leave week-one rows at **Allow** or **Deny** as written. Change a Deny only when a named user, with record rules, is allowed to make that write, and a person still confirms it.
3. Do not register `action_confirm`, invoice create, or picking validation on the week-one allow-list.
4. Do not register a tool that accepts `model` and `method` from the prompt.
5. Leave official `{database}/mcp` off Gateway while any write server action is ticked Available in MCP.

Checked against Odoo's External JSON-2 API (19.0), the External RPC deprecation notice, the July 2026 Odoo 19.4 release notes, and the saas-19.4 AI MCP server page, on **8 October 2026**.
