Connect an MCP app (Chief uses other apps)
Connect an MCP app is the other direction from the MCP server. There, an outside assistant reads WorkBOS. Here, Chief, the assistant built into WorkBOS, reaches OUT to any app that speaks MCP (the same open standard), so it can look things up in that app and, with your approval, act in it. If a product you use offers an MCP server, that is all it needs: paste the address, sign in once, done. This feature is rolling out gradually and appears under Integrations, Connect an MCP app, when it reaches your workspace.
- 1
Add the app
Workspace owners and admins open Integrations, choose Connect an MCP app, give it a name and paste the server address (it must start with https://). Private and internal addresses are refused, so nothing inside your own network can be pointed at by mistake.
- 2
Sign in once
Most apps ask you to sign in in their own window, exactly as you would sign in to WorkBOS from Claude. Some hand you a token to paste instead; a few need no sign-in at all. Whatever you use is encrypted before it is stored and is never shown back, to you or to anyone else.
- 3
See its tools
The app tells WorkBOS what it can do, and the list appears on the page with a badge on each tool: Read-only tools run whenever Chief needs them; anything marked Needs approval waits for a person. Press Refresh tools when the app changes.
- 4
Ask Chief
Chief knows which apps are connected and what each can do. Ask it in plain language ("check the helpdesk for open tickets from Acme") and it uses the right tool. When the answer involves a change in the other app, Chief files it for approval in Agent Approvals and says so; it never claims something ran when it did not.
- What is stored: the app’s name and address, the list of its tools, and its sign-in, encrypted. WorkBOS does not copy the other app’s data into your workspace; Chief reads it at the moment you ask.
- What is logged: every call Chief makes or proposes, with the tool name and the outcome, for owners and admins to review. The arguments themselves are not kept.
- What Chief treats it as: outside text. Whatever the other app answers is shown to you as information from that app, never followed as an instruction, and a turn that read from an outside app asks you before it changes anything in WorkBOS.
- Limits: sixty calls a minute per workspace and twenty per connected app, twenty seconds per call, and a size cap on what goes out and comes back, so one runaway request cannot tie up your workspace.
- Who can do what: owners and admins add, refresh, disconnect and remove apps; every staff member can see what is connected; guests see nothing here. Calls run under the person who asked Chief, and a member needs the "manage agents" capability for Chief to call an app on their behalf.
- Disconnecting: Disconnect keeps the app in the list and deletes its sign-in, so Chief can no longer reach it until an admin reconnects. Remove deletes the app, its sign-in and its tool list from the workspace. Either takes effect on the next call.
- Plan: part of the AI assistant connector, so it is available from Pro upwards, the same line as the MCP server.
The approval rule is enforced by the server, not by Chief’s good manners. A tool that can change something in the other app will not run without an approval a person gave in Agent Approvals, whoever asks and however they ask.
The one-click Gmail, Google Calendar, Drive and Slack read lane, which is a different thing: Chief indexes and cites what is in those accounts.
The other direction: an outside assistant reading WorkBOS.
Where every change Chief proposes in an outside app waits for a person.