MCP permissions and security

Features3 views

MCP permissions and security

This article explains what a connected AI assistant can reach, who decides that, and how to take access away.

A connection belongs to one workspace

Every MCP connection is tied to one Conviro workspace. It is chosen when you authorize the connection, and it is shown to you on the consent screen before you approve anything.

A connection made for one workspace cannot reach another. The assistant does not get to pick, and neither does a prompt someone types into it. If you work across several workspaces, each one needs its own connection.

Permissions come from Conviro, not from the AI

This is the part worth understanding clearly.

The AI model does not decide what it may access. Permissions are approved in Conviro and enforced by Conviro on every single request. Asking an assistant nicely, or instructing it to ignore its limits, does not widen them -- the check does not happen inside the model.

A connection is also never broader than the person who created it. If you cannot see something in Conviro, a connection you authorize cannot see it either.

What permissions look like

Open Settings -> AI & MCP -> MCP -> Permissions to see exactly what is in use, grouped by what it means:

  • Conversations -- viewing conversations and messages
  • Knowledge -- viewing your knowledge sources
  • AI configuration -- viewing how your assistant is configured
  • Customer data -- contact and lead records

Writes are not currently available. A connected assistant cannot modify anything.

Sensitive information may be hidden

Depending on your workspace privacy settings, sensitive details can be redacted before an assistant ever sees them. Permissions and privacy settings work together: a permission says which records may be read, and privacy settings say how much of each record is revealed.

Disabled features are not offered at all

If a capability is switched off for your workspace or across the platform, it is not presented to the assistant as something it could try. There is no menu item for it, so there is nothing to talk it into.

Every request is recorded

Settings -> AI & MCP -> MCP -> Activity shows what connected assistants actually did: when, which client, who it acted as, which action, and how it ended.

Refusals are recorded too, and shown as refusals. If an assistant tried something it was not allowed to do, that appears in the list -- "nothing happened" is exactly the thing worth being able to look up.

Revoking access

Open Settings -> AI & MCP -> MCP -> Connections, find the connection, and choose Revoke.

Access ends on that connection's next request. It does not wait for a token to expire, and it does not require the assistant to cooperate. Reconnecting later means authorizing again from the beginning.

Revoke without hesitating if a connection is no longer needed, if you are unsure who set it up, or if the device or account behind it may be compromised.

Good practice

  • Connect only the assistants you actually use.
  • Review Connections periodically and revoke anything stale.
  • Check Activity after connecting something new, so you know what normal looks like.
  • Remember that a connection acts with the authorizing person's access -- so who creates it matters.
mcpsecuritypermissionsprivacyrevokeaudit

Was this article helpful?