workBOS MCP

Point your AI at the business, not at a folder

Most MCP servers connect an assistant to a database or a pile of documents. This one connects it to a running business: 101 kinds of live record, through the same row-level security and role permissions the person holding the key has.

Included from Pro upwards · no per-request fee from us

Three steps, nothing to host

There is no server for you to run and no connector to install on the assistant’s side.

  1. 1
    Issue a key

    Administration, API keys, Assistant access. A key is READ ONLY by default. You choose read-only or read-and-write when you create it, and you can change an existing key between the two later without reissuing it.

  2. 2
    Point the client at it

    Add the WorkBOS MCP endpoint to Claude, ChatGPT, Cursor or any MCP client, with the key you just issued. Nothing to install and nothing to host.

  3. 3
    Ask it about your business

    The assistant can now read the workspace: invoices, deals, tasks, leave, attendance, the ledger, the audit trail. It sees exactly what the key’s holder is allowed to see and nothing else.

Handing an assistant your books is a security decision

So the answer is not a policy. It is where the wall is.

The database is the wall, not the prompt

Requests run through the same row-level security and role-based permissions a person gets. An assistant cannot read a record its key’s holder cannot read, whatever it is asked to do.

Read-only by default

A new key cannot write. Turning writes on is a deliberate act, reversible at any time on the same key, so a reporting assistant keeps working while losing the ability to change anything.

One switch stops all writes

A workspace-wide kill switch turns off assistant writes across every connected client at once, without revoking keys or breaking read access.

Revoke a key without touching the others

Keys are issued per use and revoked individually. They are stored encrypted server-side; the page shows status, never the value.

Per-key rate limits

A key carries its own limit, so one assistant looping on a question cannot starve the workspace it is asking about.

Every action is on the record

Writes land in the same audit trail as everything else, naming what caused them. The trail does not say "someone".

What it will not do

  • It is not a sync. Records are read where they live, at the moment the assistant asks. Nothing is copied into the assistant and kept there by us.
  • It does not reach money fields, deletions or approvals, whatever the key’s permissions are. Those are unavailable over this interface by design.
  • It is not on the Free plan. The MCP server is included from Pro upwards.
  • We do not control what your assistant’s provider does with a request once it leaves. That is between you and them, which is why the key is read-only until you decide otherwise.

Questions, answered

What is an MCP server?+

Model Context Protocol is an open standard for connecting an AI assistant to a system it does not own. The assistant asks the server for data or actions; the server decides what it is allowed to have. WorkBOS implements the server side, so an assistant you already use can work with your business records instead of a copy of them.

Which assistants work with it?+

Any MCP client. Claude, ChatGPT and Cursor are the ones people ask about most. There is nothing WorkBOS-specific to install on their side.

What can the assistant actually see?+

Whatever the key's holder can see, across 101 kinds of business record: money, customers, work, people, marketing and support. Not a document store and not an export. The live records, at the moment it asks.

Can it change things?+

Only if you turn writes on for that key, and only within what its holder is permitted to change: 18 kinds of record carry safe reversible fields. Money fields, deletions and approvals are not reachable this way at all.

Is this the same as the AI inside WorkBOS?+

No, and they are worth keeping apart. Chief is our own assistant, built into the workspace, with tools that go beyond reading. The MCP server is how an OUTSIDE assistant reaches the same data under the same rules. You can use either, both, or neither.

What does it cost?+

It is included from Pro upwards at no extra charge, and there is no per-request fee from us. Your assistant provider bills you for its own usage as normal.

Is my data used to train a model?+

Not by us. When you connect an outside assistant, that assistant’s provider handles the request under YOUR agreement with them, which is the agreement to read on this point. Our own AI providers are named on the subprocessor page and our privacy policy states we do not use workspace content to train third-party models.

Connect an assistant this afternoon

Start free, get the workspace holding something worth asking about, then issue a read-only key and point your assistant at it.