<img alt="" src="https://secure.mean8sigh.com/214862.png" style="display:none;">
Skip to content
English
  • There are no suggestions because the search field is empty.

Control Access to AI Chat, AI Actions and AI Assistant (MCP)

Content

  • Overview
  • Pre-conditions
  • Steps to Control Access
    • AI Chat
    • AI Action
    • AI Assistant
  • Supplementary Information
  • Notes

Overview

Use Platform Configuration to enable AI Chat, AI Actions and AI Assistant (MCP) separately and restrict each capability to selected people.

Enabling one does not enable either of the others.

These controls narrow access; they do not grant document or system permissions.

 

Separate Capability Behaviour

Capability When access is available When disabled or access is removed
AI Chat Selected users can ask questions against accessible published Portal documents. The Chat route is unavailable; the next request in an existing session redirects to Policy Portal Documents.
AI Actions Selected users with the required automation permissions can add AI steps to automation rules. New AI steps are not offered; existing steps remain visible but are disabled.
AI Assistant (MCP) Selected approved users or current members of selected approved groups can connect within permitted scopes and existing permissions. The next MCP call is refused, including from existing connections.

 

AI Assistant (MCP)

Layer Access Model

The 4 layers that ultimately determine what an AI Assistant's permissions are (listed in order):

  • Client-Level: Whether AI functionalities are enabled or disabled on the client level (view the upcoming pre-conditions section for more guidance)
  • Admin-Level: Whether that Clausematch user is added either individually or through a group, and if so with what scopes granted (see MCP Scopes section further below).
  • Connection-Level: Which tools (permissions) are consented by the end user to to be usable by their AI assistant.
  • Clausematch-User-Level: Which system and document permissions does the Clausematch user has.

 

MCP Scopes

New MCP users start with documents:read.

At connection time, documents:read is preselected and write scopes are opt-in. The user authorises scopes before a token is issued and can refuse write access while keeping read access.

Area Available scopes
Documents documents:read , documents:write

Configuration

configuration:read , configuration:write
Users users:read , users:write
Policy Portal portal:read
  • Permissions that are effectively available for the AI assistant are determined by the Clausematch user's permissions (system and documents).
  • A Portal-only user receives the Portal search and filter-list tools, not management or configuration tools. The beta catalogue contains 55 tools, but a connected user sees only the permitted subset. Use the live catalogue rather than assuming that names or counts are fixed.

 

Confirmation and Destructive Actions

Assistants are instructed to restate each proposed write and ask for approval. Approval of one write is not approval of another. However, those instructions are not platform-enforced gates for all actions.

Metadata-field deletion is the only operation with a confirmation gate enforced in code. The first request returns an impact assessment; deletion requires a repeated request with an explicit acknowledgement. The assessment identifies coverage gaps, including chart usage, custom reports and document values that cannot be fully inspected through available read endpoints. Existing platform blocks, such as chart use or a lock held by another user, produce readable explanations.

Other destructive operations - including deletion of metadata screens or stage prototypes, replacement of a document type, archiving a connection link and bulk user disabling - are marked as destructive but are not equivalently blocked in code. Documents are archived and users disabled; metadata screens and stage prototypes can be permanently deleted.

 

Pre-conditions

  • System Permission: 'System Administration'
  • All three capabilities are disabled by default and, when enabled, are available in non-PROD environments only.
    • Enable Request is to be submitted to either your Customer Success Manager or the Support Team.

Steps

  1. Navigate to the Admin Panel module and head over to the Platform Configuration tab.
  2. Identify the capability you intend to configure:
    1. AI Chat
    2. AI Actions
    3. AI Assistant (MCP)
  3. Enable that capability.
  4. Search for the users and groups who should have access and add them.
    1. For MCP, also set their high-level tools (permissions) on a read/write basis.
  5. Save changes.

Supplementary Information

Audit

MCP calls are recorded in the User Activity log with user, connected client, tool, sanitised arguments, result summary, duration and outcome.

Sensitive or large payloads are identified as present, not reproduced.

Document edits also appear in document activity under the acting user's name.

Notes

Cached Tools

  • An MCP client of a granted user may continue displaying cached tools (granted permissions) until fully restarted.

    • So if their Clausematch user has had their AI assistant permissions changed, then until a full restart of their assistant or signing out and connecting again is needed for its tool list to be updated.

    • Note that this lag only affects what is displayed on their assistant's tool list, it doesn't affect how quickly AI permission changes are made - they're made instantly.
    • This is an open issue across MCP hosts, not something specific to the Clausematch platform.
      • For example: Cursor's reload control does not pick up changes and Cursor staff are tracking the regression with no fixed date. Claude Code, GitHub Copilot in VS Code, and OpenAI Codex all have open reports of ignoring the standard notifications/tools/list_changed signal, so a stale list can survive until the client is restarted.

        References: Cursor forum thread, Claude Code issue.

General

  • A tool denylist, write-policy tiers and tenant plain-language guardrails are not delivered controls.
  • Environments enforcing MFA cannot use MCP; SSO and username/password sign-in are supported.
  • MCP restrictions apply to assistants connected as individuals. Existing service-account API integrations retain their established behaviour.

Data Processing

  • Built-in AI Chat and AI Actions process data within the dedicated Clausematch hosting environment. External MCP assistants receive authorised content and handle it under your organisation's provider agreement; do not extend the built-in hosting assurances to them.