MCP Access is the Workspace-level setting that decides what AI assistants connected through the SmartSuite MCP Server can do in your Workspace. It applies to every connection, whether a Member connects from Claude, ChatGPT, or any other MCP-compatible tool.
Plan Availability | All Customers |
Permissions | Workspace Administrators |
Related Reading | SmartSuite MCP Server · Connect SmartSuite to Claude · Connect SmartSuite to ChatGPT · Connect SmartSuite to Other AI Tools · Roles and Permissions Overview |
Where to Find It
Open Workspace Administration.
Go to AI Control Center → MCP Access and click Edit.
Choose an option and click Save Configuration.
The current mode is shown on the MCP Access row. The default for every Workspace is Read-Only.
The Three Options
Option | What it allows |
Disabled | No MCP access to this Workspace. It won't appear in the list of Workspaces when a Member connects an assistant. |
Read-Only | Assistants can read anything the connected Member can see, including Records, documents, structure and settings, but can't create, change or delete anything. |
Read & Write | Assistants act as the Member who connected them and can change data and structure: Records, Fields, Tables, Views, Forms and Automations. They're limited by that Member's own Permissions. |
"Write" covers structure, not just Record values. In Read & Write, an assistant can create Fields, Tables, Views, Forms and Automations. Choose it deliberately.
Two Gates, and the Stricter One Wins
Each Member also chooses read-only or read & write when they connect. The Workspace setting is the ceiling; the Member's choice can only narrow it.
Workspace setting | Member granted read-only | Member granted read & write |
Disabled | No access | No access |
Read-Only | Read only | Read only |
Read & Write | Read only | Read & write, within that Member's own Permissions |
Setting the Workspace to Read & Write doesn't give write access to everyone; it permits it. Each Member still chooses it on their own connection and is still bound by their own Role and Permissions.
When Changes Take Effect
Lowering the setting to Read-Only or Disabled narrows every existing connection within about a minute. Nobody has to reconnect, and you don't need to ask Members to revoke anything.
Raising the setting to Read & Write doesn't upgrade existing read-only connections. A Member who wants write access reconnects and chooses it.
Recommended Setups
Build and sandbox Workspaces: Read & Write, so builders can scaffold Tables, Fields, Views and Automations with an assistant.
Production Workspaces: Read-Only, so Members can ask questions of live data without any risk of changes.
Workspaces you don't want any assistant to reach: Disabled.
Seeing What Assistants Did
Every change made through MCP is written to the Record's activity history under both the Member's name and the assistant's, so you can always tell what was done by a person and what was done through an assistant on their behalf.
Frequently Asked Questions
Does MCP Access apply to every AI platform? Yes. Claude, ChatGPT and every other tool connect through the same SmartSuite MCP Server, so one setting covers them all.
Can an assistant ever see more than the Member who connected it? No. It acts as that Member and is bound by their Role and Permissions.
A Member says a Workspace is missing when they connect. Why? MCP Access is set to Disabled for that Workspace.
A Member chose read & write but changes are refused. Why? MCP Access for that Workspace is Read-Only. The stricter setting wins.

