Leave Management System MCP Tools
Leave Management System MCP tools support employees and departments, leave types, annual-leave accrual, start-date pro-rating, carry-forward, public holidays, mobile requests, sick-leave proof, balances, team rosters, conflict checks, manager approvals, TOIL, monthly payroll exports, notifications, and audit logs.
Read leave units, approval mode, calendar, notification, payroll export, permission, and audit settings.
Governance
Read-only; returned according to HR permissions.
Safety
Must not expose payroll or sensitive employee permission settings.
List employees, departments, managers, start dates, work patterns, and assigned leave policies.
Read first
leave.config.get
Governance
Read-only; employee private data is role-masked.
Safety
Returns only the minimum employee data needed for leave decisions.
Read one employee's leave policy, start date, manager, workdays, balances, and request history summary.
Read first
leave.employees.list
Governance
Read-only; limited to self, manager, or HR.
Safety
Sick proof and payroll fields are not shown in normal reads.
leave.departments.list
readList departments, managers, minimum staffing requirements, and leave approvers.
Read first
leave.config.get
Governance
Read-only; used for team coverage checks.
Safety
Staffing requirements are internal operational data and require management visibility.
leave.leave_types.list
readRead annual, sick, TOIL, maternity, paternity and other leave types, units, and proof requirements.
Read first
leave.config.get
Governance
Read-only; used for request forms and policy checks.
Safety
Leave type settings should reflect company policy and Hong Kong rules.
Read company leave policies, assigned employees, carry-forward, payout, probation, proof, and approval rules.
Read first
leave.config.get
Governance
Read-only; policy versions need traceability.
Safety
Must not mix policies across different employee groups.
leave.accrual_rules.list
readRead accrual rules for start-date pro-rating, monthly accrual, caps, carry-forward, and expiry.
Read first
leave.policies.list
Governance
Read-only; used for balance calculation and previews.
Safety
Accrual rules must be versioned to avoid corrupting historical balances.
leave.public_holidays.list
readRead Hong Kong public holidays, statutory holidays, bank holidays, company holidays, and non-working-day rules.
Read first
leave.config.get
Governance
Read-only; used for leave day calculation.
Safety
Holiday data should be fixed by year and policy version.
List used, remaining, pending, expiring, and carried-forward balances by employee, department, and leave type.
Read first
leave.employees.list, leave.leave_types.list
Governance
Read-only; employees see self, managers see teams, HR sees company-wide.
Safety
Normal employees must not read other employees' balances.
Read one employee/type balance, calculation basis, pending deductions, and expiry dates.
Read first
leave.balances.list
Governance
Read-only; scoped by employee, manager, or HR permission.
Safety
Must separate actual balance from pending-request impact.
leave.balance_movements.list
readList leave ledger movements for accrual, deductions, TOIL, adjustments, carry-forward, expiry, and cancellations.
Read first
leave.balance.get
Governance
Read-only; ledger cannot be edited by normal users.
Safety
Ledger needs source and action request id retention.
List leave requests by employee, department, date, state, leave type, and manager.
Read first
leave.employees.list
Governance
Read-only; scoped to self, manager, or HR.
Safety
Sick-leave reasons and proof must not be exposed on team calendars.
Read request dates, units, reason, proof, balance impact, conflicts, approvals, and notifications.
Read first
leave.requests.list
Governance
Read-only; proof documents are permission-scoped to HR/manager.
Safety
Restricts visibility of sensitive documents such as sick-leave certificates.
leave.proof_documents.list
readList sick notes, proof documents, upload time, review state, and retention period.
Read first
leave.request.get
Governance
Read-only; limited to HR, manager, or submitter.
Safety
Documents should be encrypted, maskable, and access-audited.
leave.pending_approvals.list
readList requests pending approval, information, over-balance, or staffing-conflict handling.
Read first
leave.requests.list, leave.coverage_conflicts.list
Governance
Read-only; only returns items the approver can act on.
Safety
Must not expose other managers' pending approvals.
leave.approval_chain.get
readRead approvers, delegate approvers, escalation rules, state, and SLA for a request.
Read first
leave.request.get
Governance
Read-only; used to validate approval writes.
Safety
Approvers cannot self-edit the approval chain.
leave.team_calendar.get
readRead team leave calendar, approved/pending leave, public holidays, and staffing distribution.
Read first
leave.departments.list, leave.requests.list
Governance
Read-only; team calendar hides sensitive reasons.
Safety
Public views show availability only, not medical or personal reasons.
leave.coverage_conflicts.list
readCheck same-day overlaps, minimum-staffing shortfalls, key-role absence, and long-leave conflicts.
Read first
leave.team_calendar.get, leave.departments.list
Governance
Read-only; provides approval suggestions without automatic rejection.
Safety
AI suggestions cannot replace manager decisions.
leave.toil_records.list
readList TOIL records, source overtime, approvals, available balance, and expiry.
Read first
leave.employee.get
Governance
Read-only; TOIL source and approvals are retained.
Safety
Prevents unapproved overtime from directly increasing leave balances.
leave.payroll_exports.list
readList monthly payroll leave exports, state, creator, period, file version, and errors.
Read first
leave.config.get
Governance
Read-only; payroll files are HR/payroll-only.
Safety
Payroll exports may include sensitive absence data and need permission plus download audit.
leave.summary_report.get
readRead monthly/yearly requests, balances, expiry, absence rate, department usage, and leave liability summaries.
Read first
leave.requests.list, leave.balances.list
Governance
Read-only; can aggregate by permission scope.
Safety
Reports should avoid exposing individual sick-leave reasons.
leave.audit_logs.list
readList audit logs for requests, proof, approvals, balances, policies, carry-forward, payroll exports, and notifications.
Read first
leave.config.get
Governance
Read-only; audit logs cannot be edited by normal users.
Safety
Audit should be tamper-resistant and support labour-dispute tracing.
leave.request_check.preview
previewPreview leave days, balance deduction, proof requirements, public-holiday exclusion, conflicts, and staffing impact.
Read first
leave.balance.get, leave.public_holidays.list, leave.coverage_conflicts.list
Governance
Preview only; must be confirmed before submission or approval.
Safety
Prevents submitting requests with insufficient balance or wrong holiday calculations.
leave.approval_result.preview
previewPreview balance, calendar, staffing, notification, payroll, and audit impact of approval or rejection.
Read first
leave.request.get, leave.approval_chain.get
Governance
Must be confirmed by the designated approver before action.
Safety
AI must not approve leave by itself.
leave.balance_adjustment.preview
previewPreview manual balance adjustment reason, ledger, expiry, payroll impact, and notifications.
Read first
leave.balance.get, leave.balance_movements.list
Governance
Balance adjustments require HR/management approval.
Safety
Every adjustment needs reason, evidence, or action request.
leave.policy_change.preview
previewPreview how policy, leave type, accrual, or public-holiday changes affect balances and historical requests.
Read first
leave.policies.list, leave.accrual_rules.list
Governance
Policy changes require HR/management approval and versioning.
Safety
Prevents policy changes from corrupting closed or historical records.
leave.carry_forward_run.preview
previewPreview year-end carry-forward, reset, expiry, payout, and per-employee balance changes.
Read first
leave.balances.list, leave.accrual_rules.list
Governance
Execution requires HR/payroll approval.
Safety
Year-end runs must not execute twice and require idempotency.
leave.payroll_export.preview
previewPreview monthly payroll export for leave, absence, deductions, TOIL, and exceptions.
Read first
leave.requests.list, leave.summary_report.get
Governance
Official export requires HR/payroll confirmation.
Safety
Must flag pending requests and data gaps before export.
leave.request.create
writeCreate mobile leave requests with type, dates, unit, reason, proof requirements, and preview result.
Read first
leave.request_check.preview
Governance
Employee submission enters approval and does not immediately deduct actual balance.
Safety
Requires balance, proof, and day-count checks.
leave.request.update
writeUpdate draft or information-needed requests for dates, type, reason, proof, or units.
Read first
leave.request.get, leave.request_check.preview
Governance
Approved requests cannot be directly edited and need reschedule/cancel flow.
Safety
Prevents editing approved data without audit.
leave.request.withdraw
writeWithdraw draft, pending, or rule-eligible leave requests.
Read first
leave.request.get
Governance
Cancelling approved payroll-impacting requests requires manager/HR approval.
Safety
Cancellation must reverse balances, calendars, and notification state.
leave.proof_document.attach
writeUpload or replace sick notes and other proof documents linked to a leave request.
Read first
leave.request.get, leave.proof_documents.list
Governance
Submitter may upload proof; review is scoped to manager/HR permissions.
Safety
Files need malware scanning, encryption, and access audit.
leave.approval.approve
writeApprove leave, deduct balance, update team calendar, send notifications, and retain approval record.
Read first
leave.approval_result.preview
Governance
Must be executed by the designated approver in the approval chain.
Safety
AI cannot self-approve; human must confirm conflicts and staffing impact.
leave.approval.reject
writeReject leave, record reason, retain balance, and notify the employee.
Read first
leave.approval_result.preview
Governance
Must be done by designated approver with reason.
Safety
Rejection reasons should be professional and not expose other employees' privacy.
leave.approval.request_info
writeRequest more proof, date correction, or leave-reason details from employee.
Read first
leave.request.get
Governance
Issued by designated approver or HR.
Safety
Only request information necessary to process the leave.
leave.balance.adjust
writeManually adjust leave balance, expiry, or ledger with reason and evidence.
Read first
leave.balance_adjustment.preview
Governance
Requires HR/management approval.
Safety
All balance changes need ledger, reason, and audit.
leave.toil_record.create
writeCreate TOIL records linked to overtime source, available hours, and expiry.
Read first
leave.toil_records.list, leave.employee.get
Governance
Usually requires manager/HR approval before increasing balance.
Safety
Prevents unverified overtime from becoming leave balance.
leave.toil_record.approve
writeApprove TOIL records and add compensatory leave balance plus ledger movement.
Read first
leave.toil_records.list, leave.balance_adjustment.preview
Governance
Manager/HR approval only.
Safety
Must retain overtime source, approver, and expiry rules.
Create or update leave policies, carry-forward, payout, probation, proof, and approval rules.
Read first
leave.policy_change.preview
Governance
Policy changes require HR/management approval and versioning.
Safety
Must not overwrite effective historical policies without versioning.
leave.leave_type.upsert
writeCreate or update leave types, half-day/hour units, proof requirements, and payroll impact.
Read first
leave.leave_types.list, leave.policy_change.preview
Governance
Requires HR approval.
Safety
Avoid deleting types referenced by historical requests.
leave.accrual_rule.upsert
writeCreate or update accrual, start-date pro-rating, caps, carry-forward, and expiry rules.
Read first
leave.accrual_rules.list, leave.policy_change.preview
Governance
Requires HR/management approval; existing-balance impact needs preview.
Safety
Prevents company-wide balance miscalculation.
leave.public_holiday.upsert
writeCreate or update public, company, statutory/bank holiday calendars and applicable years.
Read first
leave.public_holidays.list, leave.policy_change.preview
Governance
Requires HR/admin approval, especially when submitted requests are affected.
Safety
Must avoid silently changing approved request day counts.
leave.carry_forward_run.execute
writeExecute year-end carry-forward, reset, expiry, or unused-leave payout and write ledger movements.
Read first
leave.carry_forward_run.preview
Governance
Official execution requires HR/payroll approval and idempotency key.
Safety
Must not run twice and needs complete before/after comparison.
leave.calendar_sync.push
writePush approved leave to company/team calendars while hiding sensitive reasons and updating availability.
Read first
leave.approval_result.preview, leave.team_calendar.get
Governance
Only syncs approved requests; failures can be retried.
Safety
Must not sync sick-leave reason or proof to public calendars.
leave.payroll_export.create
writeGenerate payroll leave/absence export files and exception lists for a period.
Read first
leave.payroll_export.preview
Governance
Requires HR/payroll approval; downloads need audit.
Safety
Payroll data is sensitive and export format/recipients must be restricted.
leave.notification.send
writeSend submission, info-needed, approval, rejection, balance-expiry, payroll-exception, and year-end reminders.
Read first
leave.request.get, leave.balance.get
Governance
Official messages need template and recipient preview; sensitive content must not be broadcast.
Safety
Avoid sending sick-leave, rejection reason, or payroll data to wrong recipients.
leave.action_request.status
statusCheck preview, approval, execution, failure, rollback, and audit state for leave management writes.
Read first
leave.audit_logs.list
Governance
Read-only status; cannot force approval through this endpoint.
Safety
Approval state must be traceable and cannot be self-edited by requesters.