This is a crucial distinction that often gets lost in MCP discussions. Server admission is about trust at the connection layer, whereas tool-call permission is about runtime authorization scoped to specific capabilities. One pattern that addresses this cleanly is binding tool-level grants to session keys with finite lifetimes, so each connection carries its own permission set rather than inheriting blanket access from the admission handshake. That way you admit a server once but still enforce per-invocation constraints on which tools it can actually call.