Skip to main content
This is where the real decision is made. Making AI assistant access available to your tenant exposes nothing on its own — until a group holds one of these permissions, an assistant that connects finds no capabilities at all.

Prerequisites

  • AI assistant access is provisioned for your tenant. See Introduction.
  • You hold Manage permissions, which is what the Permissions screen requires to make changes.

The permissions

You will find these under the MCP Access area on the Permissions screen, and in the wider permission catalogue. Each is independent: granting searches does not grant document content. Grant only what the group’s work actually needs.

Granting them

1

Open the Permissions screen

Go to Settings → Access → Permissions and find the user group you want to change.
2

Tick the capabilities under MCP Access

Start with MCP: View Catalog — an assistant is close to useless without it, and it exposes no customer data. Add searches, documents, and keywords as the group’s work requires.
3

Save

Changes are staged and take effect when you save, and the change is written to the audit trail like any other permission change.
MCP: View Documents gives an assistant the content of any document the person can already open, and MCP: Run Searches returns keyword values on every result row. Treat both as you would a bulk export permission — the assistant reads at machine speed and the data leaves the product in the conversation.

What the permission does not do

A permission never widens what someone can reach. It decides which capabilities their assistants may use; their own document access rights still decide which documents those capabilities return. Two people in the same group, both holding MCP: View Documents, will get different answers from the same question if their document rights differ — exactly as they would in the product.

Removing access

Revoke the permission and the capability disappears from the assistant on its next request on most setups — within a few minutes at most. Revoking every MCP permission from a group leaves its members able to connect, but with nothing to call. To cut access for the whole tenant rather than one group, ask for AI assistant access to be switched off; nothing MCP-related is reachable while it is off, regardless of who holds what.

Connecting an assistant

The exact commands for Claude Code, Codex, and the hosted Claude connector.

Managing permissions

How staged permission changes, saving, and the audit trail work on the Permissions screen.

Document access rights

The rights that decide which documents a person — and so their assistant — can reach.