Workspace369 publishes a remote MCP server. MCP, the Model Context Protocol, is the open standard AI apps use to connect to tools and data. Once your workspace is connected, you can ask an AI app in plain language to look up a client, draft an invoice, book a job, reply to a lead, or check which workflows will fire, and it happens in your workspace.
Every action runs as you. An AI app can never see or change more than you can in the app yourself.
What an AI app can do
Through the connection an AI app can:
- Look up clients, inbound requests, notes, projects, tasks, invoices, proposals, payments, time entries, calendar events, booking pages, and team availability.
- Create and update clients, notes, projects, tasks, boards, calendar events, reminders, time entries, catalog services, draft invoices, and draft proposals.
- Record invoice payments, invoice finished jobs, and record whether a proposal was accepted or declined.
- Send an invoice or a proposal to its client, reply to a lead, send an SMS or email from the inbox, or text up to 30 recipients at once.
- Search inbox messages, read task comments, review a workflow's definition and run history, and turn a workflow off.
Every tool, with the access it requires, is listed in the MCP tools reference.
What an AI app cannot do
Some actions are deliberately not available through MCP. They stay in the Workspace369 app:
- Delete clients, invoices, proposals, projects, tasks, or events. Cancelling an event and archiving a request are the strongest actions available.
- Invite, remove, or suspend team members, or change anyone's permissions.
- Turn a workflow on, create one, or edit one. Arming a workflow is itself a send, so it stays a human action.
- Create, edit, or publish intake forms, because their consent wording is a compliance record.
- Send marketing campaigns.
- Upload files. An app can attach files that already exist in workspace storage, and only through Ask AI today.
How access works
Four things decide what a connected app can do:
- A workspace admin has turned MCP on. MCP is off for every workspace until someone with the Manage MCP connections permission enables it. See Enable MCP and manage connected apps.
- Your own permissions. Each call is checked against the module permissions your role grants, and members limited to specific clients see only those clients. If you cannot view prices, amounts are hidden from the app too.
- The access you granted the app. When you connect, the app asks for scopes such as Clients or Invoices, each as view or view, create, and edit. You can uncheck any of them. An app never gets more than you approved.
- The workspace's Token balance. Every successful call is paid for in Tokens from the same balance as in-app AI. Refused and failed calls are free.
How MCP access is controlled and billed explains each check, the Token cost of each kind of call, and what the activity log records.
Which apps work
Any app that supports remote MCP servers over the Streamable HTTP transport can connect. Claude (web and desktop), ChatGPT, Cursor, Windsurf, and VS Code with Copilot are the common ones. Connecting uses your Workspace369 sign-in, so there is no API key to copy for these apps.
Scripts and headless agents that cannot open a sign-in page use a personal access token instead.
Where to find MCP in Workspace369
| You want to | Go to |
|---|---|
| Turn MCP on for a workspace, approve specific apps, see every member's connections, read analytics and the activity log | Settings, then AI, then AI Connections (MCP) |
| Connect your own AI app, see your own connections, create a personal access token | Account settings, then Connected AI apps |
MCP and Ask AI
Ask AI, the assistant built into Workspace369, uses the same tools with the same permission checks. The differences are where you use it and how sends are confirmed:
- Ask AI runs inside the app and always shows a confirmation card before it sends anything to a client, turns a workflow off, or changes a teammate's availability. Tool calls inside an Ask AI conversation are not charged separately; the conversation is.
- A connected AI app runs outside Workspace369, so Workspace369 cannot show a confirmation inside it. The app's own approval step applies, each tool call is charged in Tokens, and the scopes you granted limit what it can reach.
Next steps
- An admin enables MCP: Enable MCP and manage connected apps.
- Each member connects their app: Connect an AI app to your workspace.
- Try a read-only prompt first, such as "Which invoices are overdue?", before asking the app to create or send anything.