[{"data":1,"prerenderedAt":690},["ShallowReactive",2],{"doc:\u002Fv\u002F2026.3\u002Fai-connections\u002Fmcp-permissions-tokens-and-audit":3},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"section":10,"version":11,"lastUpdated":12,"body":13,"_type":684,"_id":685,"_source":686,"_file":687,"_stem":688,"_extension":689},"\u002Fv\u002F2026.3\u002Fai-connections\u002Fmcp-permissions-tokens-and-audit","ai-connections",false,"","How MCP access is controlled and billed","Understand the checks every MCP call passes, why an AI app can never exceed your permissions, how Tokens are charged per call, and what the audit trail records.","AI connections","2026.3","2026-09-07",{"type":14,"children":15,"toc":672},"root",[16,24,31,36,121,126,132,137,142,148,167,388,393,399,404,410,415,443,449,454,535,540,558,563,568,574,579,585,610,616,635,658,663],{"type":17,"tag":18,"props":19,"children":20},"element","p",{},[21],{"type":22,"value":23},"text","An MCP connection is an external door into your workspace, so every call passes the same checks the app applies, plus a few that only make sense for a connected app. This article explains those checks in the order they run, the Token cost of each kind of call, and what is recorded.",{"type":17,"tag":25,"props":26,"children":28},"h2",{"id":27},"every-call-is-checked-every-time",[29],{"type":22,"value":30},"Every call is checked, every time",{"type":17,"tag":18,"props":32,"children":33},{},[34],{"type":22,"value":35},"A tool call is refused at the first check it fails. Nothing is charged for a refused call.",{"type":17,"tag":37,"props":38,"children":39},"ol",{},[40,52,71,81,91,101,111],{"type":17,"tag":41,"props":42,"children":43},"li",{},[44,50],{"type":17,"tag":45,"props":46,"children":47},"strong",{},[48],{"type":22,"value":49},"The tool is available.",{"type":22,"value":51}," Workspace369 can switch individual tools off platform-wide during an incident.",{"type":17,"tag":41,"props":53,"children":54},{},[55,60,62,69],{"type":17,"tag":45,"props":56,"children":57},{},[58],{"type":22,"value":59},"MCP is on for the workspace.",{"type":22,"value":61}," Off is the default. See ",{"type":17,"tag":63,"props":64,"children":66},"a",{"href":65},"\u002Fv\u002F2026.3\u002Fai-connections\u002Fenable-mcp-and-manage-connected-apps\u002F",[67],{"type":22,"value":68},"Enable MCP and manage connected apps",{"type":22,"value":70},".",{"type":17,"tag":41,"props":72,"children":73},{},[74,79],{"type":17,"tag":45,"props":75,"children":76},{},[77],{"type":22,"value":78},"The app is approved",{"type":22,"value":80},", when the workspace has an approved-apps list.",{"type":17,"tag":41,"props":82,"children":83},{},[84,89],{"type":17,"tag":45,"props":85,"children":86},{},[87],{"type":22,"value":88},"The connection carries the scope",{"type":22,"value":90}," the tool needs, such as Invoices with view, create, and edit.",{"type":17,"tag":41,"props":92,"children":93},{},[94,99],{"type":17,"tag":45,"props":95,"children":96},{},[97],{"type":22,"value":98},"You have the permission",{"type":22,"value":100}," the tool needs, and you are still a member of the workspace. Both are read live from your team settings, not from the connection.",{"type":17,"tag":41,"props":102,"children":103},{},[104,109],{"type":17,"tag":45,"props":105,"children":106},{},[107],{"type":22,"value":108},"The client is in your book.",{"type":22,"value":110}," Members limited to specific clients get results filtered to those clients, and a record outside their book reads as not found.",{"type":17,"tag":41,"props":112,"children":113},{},[114,119],{"type":17,"tag":45,"props":115,"children":116},{},[117],{"type":22,"value":118},"The workspace can pay.",{"type":22,"value":120}," The balance must cover the call before it runs.",{"type":17,"tag":18,"props":122,"children":123},{},[124],{"type":22,"value":125},"Then the tool runs, the Tokens are charged, and the call is written to the activity log.",{"type":17,"tag":25,"props":127,"children":129},{"id":128},"an-app-acts-as-you",[130],{"type":22,"value":131},"An app acts as you",{"type":17,"tag":18,"props":133,"children":134},{},[135],{"type":22,"value":136},"Every call runs under your identity with your permissions. An app connected by a member with view-only access to invoices can read invoices and nothing more, even if the member approved every scope. Amounts are hidden from an app when you cannot view prices.",{"type":17,"tag":18,"props":138,"children":139},{},[140],{"type":22,"value":141},"Records an AI app creates or changes are attributed to you in the workspace activity trail, marked as coming through the connected app.",{"type":17,"tag":25,"props":143,"children":145},{"id":144},"scopes-and-permissions-are-different-limits",[146],{"type":22,"value":147},"Scopes and permissions are different limits",{"type":17,"tag":18,"props":149,"children":150},{},[151,153,158,160,165],{"type":22,"value":152},"A ",{"type":17,"tag":45,"props":154,"children":155},{},[156],{"type":22,"value":157},"scope",{"type":22,"value":159}," is what you granted the app at sign-in. A ",{"type":17,"tag":45,"props":161,"children":162},{},[163],{"type":22,"value":164},"permission",{"type":22,"value":166}," is what your role allows. A call needs both. Scopes let you give an app less than you have, for example view-only access to invoices while you can edit them yourself. Scopes can never give an app more than you have.",{"type":17,"tag":168,"props":169,"children":170},"table",{},[171,190],{"type":17,"tag":172,"props":173,"children":174},"thead",{},[175],{"type":17,"tag":176,"props":177,"children":178},"tr",{},[179,185],{"type":17,"tag":180,"props":181,"children":182},"th",{},[183],{"type":22,"value":184},"Scope on the sign-in page",{"type":17,"tag":180,"props":186,"children":187},{},[188],{"type":22,"value":189},"Unlocks",{"type":17,"tag":191,"props":192,"children":193},"tbody",{},[194,208,221,234,247,260,273,285,298,311,323,336,349,362,375],{"type":17,"tag":176,"props":195,"children":196},{},[197,203],{"type":17,"tag":198,"props":199,"children":200},"td",{},[201],{"type":22,"value":202},"Workspace details",{"type":17,"tag":198,"props":204,"children":205},{},[206],{"type":22,"value":207},"Workspace summary and context, and running several calls as a batch",{"type":17,"tag":176,"props":209,"children":210},{},[211,216],{"type":17,"tag":198,"props":212,"children":213},{},[214],{"type":22,"value":215},"Clients",{"type":17,"tag":198,"props":217,"children":218},{},[219],{"type":22,"value":220},"Clients and lead sources",{"type":17,"tag":176,"props":222,"children":223},{},[224,229],{"type":17,"tag":198,"props":225,"children":226},{},[227],{"type":22,"value":228},"Requests",{"type":17,"tag":198,"props":230,"children":231},{},[232],{"type":22,"value":233},"Inbound requests and intake forms",{"type":17,"tag":176,"props":235,"children":236},{},[237,242],{"type":17,"tag":198,"props":238,"children":239},{},[240],{"type":22,"value":241},"Notes",{"type":17,"tag":198,"props":243,"children":244},{},[245],{"type":22,"value":246},"Workspace and personal notes",{"type":17,"tag":176,"props":248,"children":249},{},[250,255],{"type":17,"tag":198,"props":251,"children":252},{},[253],{"type":22,"value":254},"Invoices",{"type":17,"tag":198,"props":256,"children":257},{},[258],{"type":22,"value":259},"Invoices, payments, and invoicing scheduled jobs",{"type":17,"tag":176,"props":261,"children":262},{},[263,268],{"type":17,"tag":198,"props":264,"children":265},{},[266],{"type":22,"value":267},"Proposals",{"type":17,"tag":198,"props":269,"children":270},{},[271],{"type":22,"value":272},"Proposals and estimates",{"type":17,"tag":176,"props":274,"children":275},{},[276,281],{"type":17,"tag":198,"props":277,"children":278},{},[279],{"type":22,"value":280},"Projects",{"type":17,"tag":198,"props":282,"children":283},{},[284],{"type":22,"value":280},{"type":17,"tag":176,"props":286,"children":287},{},[288,293],{"type":17,"tag":198,"props":289,"children":290},{},[291],{"type":22,"value":292},"Tasks",{"type":17,"tag":198,"props":294,"children":295},{},[296],{"type":22,"value":297},"Boards, tasks, subtasks, and comments",{"type":17,"tag":176,"props":299,"children":300},{},[301,306],{"type":17,"tag":198,"props":302,"children":303},{},[304],{"type":22,"value":305},"Calendar",{"type":17,"tag":198,"props":307,"children":308},{},[309],{"type":22,"value":310},"Events, categories, availability checks, and booking pages",{"type":17,"tag":176,"props":312,"children":313},{},[314,319],{"type":17,"tag":198,"props":315,"children":316},{},[317],{"type":22,"value":318},"Reminders",{"type":17,"tag":198,"props":320,"children":321},{},[322],{"type":22,"value":318},{"type":17,"tag":176,"props":324,"children":325},{},[326,331],{"type":17,"tag":198,"props":327,"children":328},{},[329],{"type":22,"value":330},"Time entries",{"type":17,"tag":198,"props":332,"children":333},{},[334],{"type":22,"value":335},"Time entries and timesheets",{"type":17,"tag":176,"props":337,"children":338},{},[339,344],{"type":17,"tag":198,"props":340,"children":341},{},[342],{"type":22,"value":343},"Products and services",{"type":17,"tag":198,"props":345,"children":346},{},[347],{"type":22,"value":348},"The catalog",{"type":17,"tag":176,"props":350,"children":351},{},[352,357],{"type":17,"tag":198,"props":353,"children":354},{},[355],{"type":22,"value":356},"Team members",{"type":17,"tag":198,"props":358,"children":359},{},[360],{"type":22,"value":361},"The roster, availability, and member activity",{"type":17,"tag":176,"props":363,"children":364},{},[365,370],{"type":17,"tag":198,"props":366,"children":367},{},[368],{"type":22,"value":369},"Inbox",{"type":17,"tag":198,"props":371,"children":372},{},[373],{"type":22,"value":374},"Searching messages, and separately, sending messages on your behalf",{"type":17,"tag":176,"props":376,"children":377},{},[378,383],{"type":17,"tag":198,"props":379,"children":380},{},[381],{"type":22,"value":382},"Workflows",{"type":17,"tag":198,"props":384,"children":385},{},[386],{"type":22,"value":387},"Reading workflows and their runs, and turning one off",{"type":17,"tag":18,"props":389,"children":390},{},[391],{"type":22,"value":392},"Each scope offers view or view, create, and edit. Inbox offers view and send on your behalf. Sending an invoice or proposal needs that module's create-and-edit scope; replying to a lead needs the inbox send scope.",{"type":17,"tag":25,"props":394,"children":396},{"id":395},"client-opt-outs-are-honored",[397],{"type":22,"value":398},"Client opt-outs are honored",{"type":17,"tag":18,"props":400,"children":401},{},[402],{"type":22,"value":403},"A client who has opted out of email or text messages cannot be messaged through MCP, the same as in the app. Sending an invoice or proposal to an opted-out client is refused and the reason names the client. A bulk text reports opted-out recipients as suppressed rather than sending to them.",{"type":17,"tag":25,"props":405,"children":407},{"id":406},"sends-and-confirmation",[408],{"type":22,"value":409},"Sends and confirmation",{"type":17,"tag":18,"props":411,"children":412},{},[413],{"type":22,"value":414},"Ten tools send something to a person or change something a person relies on: sending an invoice or proposal, replying to a lead, sending an inbox message or a bulk text, invoicing a range of jobs with notifications, converting a request to a client, turning a workflow off, and setting a teammate's availability.",{"type":17,"tag":416,"props":417,"children":418},"ul",{},[419,431],{"type":17,"tag":41,"props":420,"children":421},{},[422,424,429],{"type":22,"value":423},"In ",{"type":17,"tag":45,"props":425,"children":426},{},[427],{"type":22,"value":428},"Ask AI",{"type":22,"value":430},", these tools always show a confirmation card first, even in a workspace that has turned on auto-approval for ordinary changes.",{"type":17,"tag":41,"props":432,"children":433},{},[434,436,441],{"type":22,"value":435},"In a ",{"type":17,"tag":45,"props":437,"children":438},{},[439],{"type":22,"value":440},"connected AI app",{"type":22,"value":442},", Workspace369 cannot show a confirmation. The app's own approval step is the safeguard, together with the scopes you granted. If you do not want an app sending on your behalf, do not grant it the send scope.",{"type":17,"tag":25,"props":444,"children":446},{"id":445},"what-each-call-costs",[447],{"type":22,"value":448},"What each call costs",{"type":17,"tag":18,"props":450,"children":451},{},[452],{"type":22,"value":453},"Every successful call is paid from the workspace's Token balance, the same balance used by Ask AI and messaging. Calls are priced by what they do:",{"type":17,"tag":168,"props":455,"children":456},{},[457,478],{"type":17,"tag":172,"props":458,"children":459},{},[460],{"type":17,"tag":176,"props":461,"children":462},{},[463,468,473],{"type":17,"tag":180,"props":464,"children":465},{},[466],{"type":22,"value":467},"Kind of call",{"type":17,"tag":180,"props":469,"children":470},{},[471],{"type":22,"value":472},"Examples",{"type":17,"tag":180,"props":474,"children":475},{},[476],{"type":22,"value":477},"Default cost",{"type":17,"tag":191,"props":479,"children":480},{},[481,499,517],{"type":17,"tag":176,"props":482,"children":483},{},[484,489,494],{"type":17,"tag":198,"props":485,"children":486},{},[487],{"type":22,"value":488},"Read",{"type":17,"tag":198,"props":490,"children":491},{},[492],{"type":22,"value":493},"Search clients, get an invoice, list events",{"type":17,"tag":198,"props":495,"children":496},{},[497],{"type":22,"value":498},"1 Token",{"type":17,"tag":176,"props":500,"children":501},{},[502,507,512],{"type":17,"tag":198,"props":503,"children":504},{},[505],{"type":22,"value":506},"Write",{"type":17,"tag":198,"props":508,"children":509},{},[510],{"type":22,"value":511},"Create a task, update a client, record a payment",{"type":17,"tag":198,"props":513,"children":514},{},[515],{"type":22,"value":516},"5 Tokens",{"type":17,"tag":176,"props":518,"children":519},{},[520,525,530],{"type":17,"tag":198,"props":521,"children":522},{},[523],{"type":22,"value":524},"Send",{"type":17,"tag":198,"props":526,"children":527},{},[528],{"type":22,"value":529},"Send an invoice, reply to a lead, bulk text",{"type":17,"tag":198,"props":531,"children":532},{},[533],{"type":22,"value":534},"10 Tokens",{"type":17,"tag":18,"props":536,"children":537},{},[538],{"type":22,"value":539},"The current rates are listed in the Token charging guide in the app under the MCP heading. Three rules apply:",{"type":17,"tag":416,"props":541,"children":542},{},[543,548,553],{"type":17,"tag":41,"props":544,"children":545},{},[546],{"type":22,"value":547},"A refused or failed call is free.",{"type":17,"tag":41,"props":549,"children":550},{},[551],{"type":22,"value":552},"A send also pays the normal cost of the email or text it triggers.",{"type":17,"tag":41,"props":554,"children":555},{},[556],{"type":22,"value":557},"Retrying an identical call within the same minute after a network error is not charged twice.",{"type":17,"tag":18,"props":559,"children":560},{},[561],{"type":22,"value":562},"When the balance cannot cover a call, the app receives a message saying the workspace is out of Tokens and asking for a top-up.",{"type":17,"tag":18,"props":564,"children":565},{},[566],{"type":22,"value":567},"Tool calls made inside an Ask AI conversation are not charged individually; the conversation is charged for its AI usage instead.",{"type":17,"tag":25,"props":569,"children":571},{"id":570},"rate-limits",[572],{"type":22,"value":573},"Rate limits",{"type":17,"tag":18,"props":575,"children":576},{},[577],{"type":22,"value":578},"One connection may make 120 calls per minute, and a workspace as a whole 600 calls per minute. A call over the limit is refused with the time until the limit resets, and does not count against the next minute.",{"type":17,"tag":25,"props":580,"children":582},{"id":581},"how-long-a-connection-lasts",[583],{"type":22,"value":584},"How long a connection lasts",{"type":17,"tag":416,"props":586,"children":587},{},[588,593,605],{"type":17,"tag":41,"props":589,"children":590},{},[591],{"type":22,"value":592},"An interactive connection keeps working for up to 90 days without signing in again, as long as MCP stays on, the app stays approved, and you stay a member. Disconnecting ends it immediately.",{"type":17,"tag":41,"props":594,"children":595},{},[596,598,604],{"type":22,"value":597},"A personal access token lasts until its expiry or until it is revoked. See ",{"type":17,"tag":63,"props":599,"children":601},{"href":600},"\u002Fv\u002F2026.3\u002Fai-connections\u002Fpersonal-access-tokens\u002F",[602],{"type":22,"value":603},"Personal access tokens for scripts and agents",{"type":22,"value":70},{"type":17,"tag":41,"props":606,"children":607},{},[608],{"type":22,"value":609},"Removing a member from the workspace ends all of their connections and tokens immediately.",{"type":17,"tag":25,"props":611,"children":613},{"id":612},"what-the-activity-log-records",[614],{"type":22,"value":615},"What the activity log records",{"type":17,"tag":18,"props":617,"children":618},{},[619,621,626,628,633],{"type":22,"value":620},"Every call, successful or refused, is written to the ",{"type":17,"tag":45,"props":622,"children":623},{},[624],{"type":22,"value":625},"Activity Log",{"type":22,"value":627}," on the ",{"type":17,"tag":45,"props":629,"children":630},{},[631],{"type":22,"value":632},"AI Connections (MCP)",{"type":22,"value":634}," screen with:",{"type":17,"tag":416,"props":636,"children":637},{},[638,643,648,653],{"type":17,"tag":41,"props":639,"children":640},{},[641],{"type":22,"value":642},"The app and the member whose authorization it used.",{"type":17,"tag":41,"props":644,"children":645},{},[646],{"type":22,"value":647},"The tool, the scope it required, and the outcome, including the refusal reason.",{"type":17,"tag":41,"props":649,"children":650},{},[651],{"type":22,"value":652},"Latency and the Tokens charged.",{"type":17,"tag":41,"props":654,"children":655},{},[656],{"type":22,"value":657},"Which argument fields were passed and their types. Values such as names, amounts, or message text are never stored in the log, and neither is any credential.",{"type":17,"tag":18,"props":659,"children":660},{},[661],{"type":22,"value":662},"Entries are kept indefinitely. Owners and admins with the Manage MCP connections permission can read the log and the usage analytics built from it.",{"type":17,"tag":664,"props":665,"children":666},"blockquote",{},[667],{"type":17,"tag":18,"props":668,"children":669},{},[670],{"type":22,"value":671},"For a security review, the short version is: a connected app runs as the member who connected it, under that member's live permissions, limited further by the scopes they approved, in one workspace, with every call recorded.",{"title":7,"searchDepth":673,"depth":673,"links":674},2,[675,676,677,678,679,680,681,682,683],{"id":27,"depth":673,"text":30},{"id":128,"depth":673,"text":131},{"id":144,"depth":673,"text":147},{"id":395,"depth":673,"text":398},{"id":406,"depth":673,"text":409},{"id":445,"depth":673,"text":448},{"id":570,"depth":673,"text":573},{"id":581,"depth":673,"text":584},{"id":612,"depth":673,"text":615},"markdown","content:v:2026.3:ai-connections:mcp-permissions-tokens-and-audit.md","content","v\u002F2026.3\u002Fai-connections\u002Fmcp-permissions-tokens-and-audit.md","v\u002F2026.3\u002Fai-connections\u002Fmcp-permissions-tokens-and-audit","md",1788830656120]