Workspace MCP tools
Connect exposes OAuth-authenticated workspace MCP tools. A grant is bound to one workspace and one selected business. Read tools cover profile, readiness, follow-ups, memory and business-scoped customer-operations records; configuration tools update supported Business Setup, channels, autonomy, runtime and memory under explicit write authority.
Read surface#
- Business profile, operational readiness and runtime state.
- Follow-ups and central business memory.
- Business-bound searches for people, companies, leads, prospects, opportunities, conversations, calls, cases, onboarding and Knowledge.
- The sheet and business for domain searches are fixed server-side; neither is an arbitrary caller-controlled query target.
Write surface#
- Update supported Business Setup profile fields.
- Set Email, Phone, SMS or WhatsApp requirement state.
- Assign supported business channel endpoints.
- Set autonomy policy within the workspace ceiling.
- Start or pause runtime only when Owner/workspace-admin authorization permits it.
- Add or archive central business memory.
Identity and sibling-business protection#
A workspace can contain several businesses and can also know one human across more than one of them. The normal product has human workflows that can deliberately share or adopt that relationship. A single-business MCP grant is narrower. If a supplied email or phone already resolves to a Person outside the authorized business, the create-person tool refuses instead of attaching that Person to the current business. A legacy email Contact outside the business is refused for the same reason.
What success evidence looks like#
Configuration writes already use a persist, read-back, compare sequence and return audit evidence. Customer-operation writes return the row after the canonical Data Workspace has re-read it inside the same business reach. A client should report a held, refused, conflict or verification failure exactly as returned. Retrying a failed state transition as though transport had failed can turn an explicit safety decision into repeated pressure on the same boundary.
- Use read tools first when the requested write depends on current state.
- Use the smallest matching tool instead of reconstructing a generic data editor.
- Keep the business implicit in authorization; never ask a model to copy an internal id between businesses.
- Treat missing records as absent within this business, not as evidence that they do not exist anywhere in the workspace.
Questions#
Can the model pass another business id?
No. Protected tools derive it from authorization.
Are MCP test tools available in production?
No. Diagnostics require an explicitly non-production deployment and explicit opt-in.
Can MCP bypass Connect's normal domain rules?
No. The MCP facade uses canonical services and Data Workspace reach rules.