Start with read-only access
Verify one reviewed read while keeping writes blocked.
Prepare a small pilot
Choose one provider and a small group of intended users.
- An administrator can configure the connection and policy.
- A member has the required team membership and provider access.
- A reviewed read tool targets a specific permitted resource.
Run the pilot
Keep the first test narrow enough to verify directly.
- Publish Deny all writes before making the connection available.
- Complete connection setup, review, testing, and activation.
- Have the member run the chosen read through their own MCP endpoint.
- Check the matching identity, connection, decision, and provider outcome in activity.
- Verify that a controlled identity outside the assigned team cannot use the scoped connection.
Troubleshooting
The reviewed read is denied
Check Default access, team scope, personal credentials, and the permitted resource. Broadening the write decision does not repair those conditions.
Frequently asked questions
When should I add more users or tools?
After the intended read and restriction both work. Add one member or reviewed read at a time and repeat the same checks.