Manage MCP access

Set the default access for connected MCP clients and review their activity.

Workspace admins control which MCP tools connected clients can use. Start with the least access that supports the workflow, then review grants and approvals regularly.

How to

  1. Open MCP settings

    If you are a workspace admin, open Settings, choose Integrations, then choose MCP. Non-admins can view MCP status but cannot change the policy.

  2. Set the workspace policy

    Choose Disabled, Read-only, or Read/write. Start with Read-only until the workspace has a reviewed reason to allow writes.

  3. Review clients and approvals

    Check connected clients, pending approvals, audit events, and usage. Revoke a client when it no longer needs access.

Choose the least access that works

Disabled blocks connected clients. Read-only lets them view workspace information without making changes. Read/write allows changes, while Robert still requires human confirmation before deleting workspace data.

Start read-only. Read-only access is the right default for discovery and research. Enable writes only for a workflow your workspace has reviewed.