Backport of 'Pre-approve Orbit MCP tools in tool_access_policies claim'
What does this MR do and why?
Backport of !247570 (merged). Orbit MCP tools prompt for approval on every call in web Duo Chat because the tool_access_policies claim cannot express them. Cherry-pick of 3dedb179 minus the ask_tools hunk in ResolutionService, which depends on the Permissions-constant refactor absent from 19.2 and has no consumer there.
Related to !247570 (merged)
MR acceptance checklist
This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.
- This MR is backporting a bug fix, documentation update, or spec fix, previously merged in the default branch.
- The MR that fixed the bug on the default branch has been deployed to GitLab.com (not applicable for documentation or spec changes).
- The MR title is descriptive (e.g. "Backport of 'title of default branch MR'"). This is important, since the title will be copied to the patch blog post.
- Required labels have been applied to this merge request
- severity label and bug subtype labels (if applicable)
- If this MR fixes a bug that affects customers, the customer label has been applied.
- This MR has been approved by a maintainer (only one approval is required).
- Ensure the
e2e:test-on-omnibus-eejob has succeeded, or if it has failed, investigate the failures. If you determine the failures are unrelated, you may proceed. If you need assistance investigating, request help in the #s_developer_experience Slack channel to confirm the failures are unrelated to the merge request.