Connector Access & Permissions
Once an MCP connector server is registered, you control who can use it — and which of its individual tools they can use — from the server’s Access and Tools tabs.
For registering, configuring, or connecting a server itself, see Connectors (MCP Servers).
Permissions
| Action | Permission required |
|---|---|
| View access settings | View MCP Servers |
| Change default access or manage access rules | Admin MCP Servers |
Open a server’s access settings
- On the Connectors server list, click a server’s access control (shield) icon to open its detail view.
- Select the Access tab (server-level access) or the Tools tab (per-tool access).
Note: The list’s auto-refresh pauses while a detail view is open and resumes when you return to the list.
Govern server-level access
On the Access tab, set Default access for the server:
| Option | Effect |
|---|---|
| All users | Everyone can use the server |
| Admins only | Restricted to administrators |
| Explicit only | No access except through an access rule |
This setting saves immediately on change.
Note: This Access tab setting is distinct from the free-text Default access field on the server’s Add/Edit form. The Access tab is the structured, enforced control; the form field does not replace it.
Add an access rule
- Click Add Rule.
- Choose a Rule type:
Role,Department, orUser. - Select the specific role, department, or user.
- For departments, choose whether to Include sub-departments (on by default).
- For users, search by name.
- Choose the Permission:
Full,Read only, orDenied. - Click Add Rule.
Delete a rule from the access-rules list to remove it.
Govern tool-level access
Open the Tools tab to view tools synced from the server (use Sync Tools on the server first if the list is empty — see Connectors (MCP Servers)). Each tool shows whether it currently inherits the server’s access rules or uses custom rules.
- Click a tool’s config (gear) icon.
- Choose Inherit from server or Custom rules.
- If Custom rules, build the rule list using the same steps as server-level access rules, then click Save.
Note: Switching a tool back to Inherit from server discards any custom rules previously configured for that tool.
Related
- Connectors (MCP Servers) — register, configure, and connect servers.
- Roles & Permissions — define the roles your access rules reference.
- Organization & Departments — manage the departments you can target with access rules.
- Managing Users — find and manage the users you grant access to.
- How Access & Permissions Work — understand the permission model behind this page.
- Control Hub Guide home