Most MCP servers connect an assistant to a database or a pile of documents. This one connects it to a running business: 101 kinds of live record, through the same row-level security and role permissions the person holding the key has.
Included from Pro upwards · no per-request fee from us
There is no server for you to run and no connector to install on the assistant’s side.
Administration, API keys, Assistant access. A key is READ ONLY by default. You choose read-only or read-and-write when you create it, and you can change an existing key between the two later without reissuing it.
Add the WorkBOS MCP endpoint to Claude, ChatGPT, Cursor or any MCP client, with the key you just issued. Nothing to install and nothing to host.
The assistant can now read the workspace: invoices, deals, tasks, leave, attendance, the ledger, the audit trail. It sees exactly what the key’s holder is allowed to see and nothing else.
So the answer is not a policy. It is where the wall is.
Requests run through the same row-level security and role-based permissions a person gets. An assistant cannot read a record its key’s holder cannot read, whatever it is asked to do.
A new key cannot write. Turning writes on is a deliberate act, reversible at any time on the same key, so a reporting assistant keeps working while losing the ability to change anything.
A workspace-wide kill switch turns off assistant writes across every connected client at once, without revoking keys or breaking read access.
Keys are issued per use and revoked individually. They are stored encrypted server-side; the page shows status, never the value.
A key carries its own limit, so one assistant looping on a question cannot starve the workspace it is asking about.
Writes land in the same audit trail as everything else, naming what caused them. The trail does not say "someone".
Model Context Protocol is an open standard for connecting an AI assistant to a system it does not own. The assistant asks the server for data or actions; the server decides what it is allowed to have. WorkBOS implements the server side, so an assistant you already use can work with your business records instead of a copy of them.
Any MCP client. Claude, ChatGPT and Cursor are the ones people ask about most. There is nothing WorkBOS-specific to install on their side.
Whatever the key's holder can see, across 101 kinds of business record: money, customers, work, people, marketing and support. Not a document store and not an export. The live records, at the moment it asks.
Only if you turn writes on for that key, and only within what its holder is permitted to change: 18 kinds of record carry safe reversible fields. Money fields, deletions and approvals are not reachable this way at all.
No, and they are worth keeping apart. Chief is our own assistant, built into the workspace, with tools that go beyond reading. The MCP server is how an OUTSIDE assistant reaches the same data under the same rules. You can use either, both, or neither.
It is included from Pro upwards at no extra charge, and there is no per-request fee from us. Your assistant provider bills you for its own usage as normal.
Not by us. When you connect an outside assistant, that assistant’s provider handles the request under YOUR agreement with them, which is the agreement to read on this point. Our own AI providers are named on the subprocessor page and our privacy policy states we do not use workspace content to train third-party models.
Start free, get the workspace holding something worth asking about, then issue a read-only key and point your assistant at it.