Permissions

Connector Access & Permissions

Once an MCP connector server is registered, you control who can use it — and which of its individual tools they can use — from the server’s Access and Tools tabs.

Grengin connectors access

For registering, configuring, or connecting a server itself, see Connectors (MCP Servers).

Permissions

ActionPermission required
View access settingsView MCP Servers
Change default access or manage access rulesAdmin MCP Servers

Open a server’s access settings

  1. On the Connectors server list, click a server’s access control (shield) icon to open its detail view.
  2. Select the Access tab (server-level access) or the Tools tab (per-tool access).

Note: The list’s auto-refresh pauses while a detail view is open and resumes when you return to the list.

Govern server-level access

On the Access tab, set Default access for the server:

OptionEffect
All usersEveryone can use the server
Admins onlyRestricted to administrators
Explicit onlyNo access except through an access rule

This setting saves immediately on change.

Note: This Access tab setting is distinct from the free-text Default access field on the server’s Add/Edit form. The Access tab is the structured, enforced control; the form field does not replace it.

Add an access rule

Grengin mcp add rule
  1. Click Add Rule.
  2. Choose a Rule type: Role, Department, or User.
  3. Select the specific role, department, or user.
    • For departments, choose whether to Include sub-departments (on by default).
    • For users, search by name.
  4. Choose the Permission: Full, Read only, or Denied.
  5. Click Add Rule.

Delete a rule from the access-rules list to remove it.

Govern tool-level access

Open the Tools tab to view tools synced from the server (use Sync Tools on the server first if the list is empty — see Connectors (MCP Servers)). Each tool shows whether it currently inherits the server’s access rules or uses custom rules.

Grengin mcp governance
  1. Click a tool’s config (gear) icon.
  2. Choose Inherit from server or Custom rules.
  3. If Custom rules, build the rule list using the same steps as server-level access rules, then click Save.

Note: Switching a tool back to Inherit from server discards any custom rules previously configured for that tool.