MCP permissions and security
This article explains what a connected AI assistant can reach, who decides that, and how to take access away.
A connection belongs to one workspace
Every MCP connection is tied to one Conviro workspace. It is chosen when you authorize the connection, and it is shown to you on the consent screen before you approve anything.
A connection made for one workspace cannot reach another. The assistant does not get to pick, and neither does a prompt someone types into it. If you work across several workspaces, each one needs its own connection.
Permissions come from Conviro, not from the AI
This is the part worth understanding clearly.
The AI model does not decide what it may access. Permissions are approved in Conviro and enforced by Conviro on every single request. Asking an assistant nicely, or instructing it to ignore its limits, does not widen them -- the check does not happen inside the model.
A connection is also never broader than the person who created it. If you cannot see something in Conviro, a connection you authorize cannot see it either.
What permissions look like
Open Settings -> AI & MCP -> MCP -> Permissions to see exactly what is in use, grouped by what it means:
- Conversations -- viewing conversations and messages
- Knowledge -- viewing your knowledge sources
- AI configuration -- viewing how your assistant is configured
- Customer data -- contact and lead records
Writes are not currently available. A connected assistant cannot modify anything.
Sensitive information may be hidden
Depending on your workspace privacy settings, sensitive details can be redacted before an assistant ever sees them. Permissions and privacy settings work together: a permission says which records may be read, and privacy settings say how much of each record is revealed.
Disabled features are not offered at all
If a capability is switched off for your workspace or across the platform, it is not presented to the assistant as something it could try. There is no menu item for it, so there is nothing to talk it into.
Every request is recorded
Settings -> AI & MCP -> MCP -> Activity shows what connected assistants actually did: when, which client, who it acted as, which action, and how it ended.
Refusals are recorded too, and shown as refusals. If an assistant tried something it was not allowed to do, that appears in the list -- "nothing happened" is exactly the thing worth being able to look up.
Revoking access
Open Settings -> AI & MCP -> MCP -> Connections, find the connection, and choose Revoke.
Access ends on that connection's next request. It does not wait for a token to expire, and it does not require the assistant to cooperate. Reconnecting later means authorizing again from the beginning.
Revoke without hesitating if a connection is no longer needed, if you are unsure who set it up, or if the device or account behind it may be compromised.
Good practice
- Connect only the assistants you actually use.
- Review Connections periodically and revoke anything stale.
- Check Activity after connecting something new, so you know what normal looks like.
- Remember that a connection acts with the authorizing person's access -- so who creates it matters.