Manage MCP access
Set the default access for connected MCP clients and review their activity.
Workspace admins control which MCP tools connected clients can use. Start with the least access that supports the workflow, then review grants and approvals regularly.
How to
Open MCP settings
If you are a workspace admin, open Settings, choose Integrations, then choose MCP. Non-admins can view MCP status but cannot change the policy.
Set the workspace policy
Choose Disabled, Read-only, or Read/write. Start with Read-only until the workspace has a reviewed reason to allow writes.
Review clients and approvals
Check connected clients, pending approvals, audit events, and usage. Revoke a client when it no longer needs access.
Choose the least access that works
Disabled blocks connected clients. Read-only lets them view workspace information without making changes. Read/write allows changes, while Robert still requires human confirmation before deleting workspace data.
Start read-only. Read-only access is the right default for discovery and research. Enable writes only for a workflow your workspace has reviewed.