Skip to main content

What is AI assistant access?

AI assistant access lets a tool such as Claude query Nobly Insight directly, using the Model Context Protocol (MCP) — an open standard for connecting assistants to the systems they need to answer with. Instead of pasting documents into a chat, the assistant asks Insight and gets the answer from your own content. The assistant connects as you. It signs in with your account, and every request it makes carries your identity — so it sees exactly what you would see, and nothing more.
An assistant never gets its own account, and never sees more than the person using it. If you cannot open a document in Insight, neither can the assistant you are running.

What has to be true before an assistant sees anything

Three things stack, and all three must allow a request:
1

Available for your tenant

AI assistant access is provisioned per tenant. Confirm it is switched on for yours before you begin — if it is not, there is nothing to connect to.
2

Granted to the user's group

Availability alone exposes nothing. Each capability is a separate permission, granted per user group on the Permissions screen. Someone with no MCP permission connects successfully and finds no capabilities at all. See Granting access.
3

Allowed by the person's own document rights

The permissions decide which capabilities someone may use. Their existing document access rights still decide which documents they reach. A search through an assistant returns the same rows the same person would get from the search page — no more.

What each capability exposes

Grant these deliberately: they differ sharply in how much they reveal. Decide with the data in mind, not the feature name. Catalog is the mildest and is usually what makes the rest useful — an assistant cannot build a sensible search without knowing which document types and keyword types exist.

What is recorded

Assistant activity is not a side channel. It lands in the same places you already review:
  • Document retrieval is written to the document history, under the person whose account the assistant is using — the same record a download through the web client produces.
  • Searches are recorded in the search audit trail, marked as having come from an assistant, so you can tell them apart from searches run in the product.
Search auditing for assistants is always on. It does not follow the setting that controls auditing for the search page, so a tenant that has not switched that on still gets a record of what its assistants searched for.

What assistants cannot do

Access is read-only. An assistant can find, read, and summarise; it cannot create, edit, delete, or reindex anything, and there is no permission that lets it. Caseflow objects are not reachable either.

Granting access

The permissions that decide which capabilities a user group’s assistants may use, and how to grant them.

Connecting an assistant

The exact commands for Claude Code, Codex, and the hosted Claude connector.

Application permissions

The full catalogue of application permissions, grouped by area.