the two gates framing is right. from the other end: building grunz (coding agent on open models) we originally shipped with a handful of MCP servers switched on by default and ended up turning all of them off, because they were causing weird glitches we couldn't trace back to anything the user actually asked for. deny by default at admission would have saved us the trouble. the tool-call gate also matters more with open or abliterated models, since prompt level "don't call X" instructions are exactly what those follow less reliably. is the allowlist per project or per user in your setup?