Enterprise AI
Set up an enterprise connector
Authorize an MCP connector with the minimum identity, scope and write access.
Before you connect
Section titled “Before you connect”Confirm that the organization has enabled the connector and that the user or deployment identity has access to the intended resources. Decide whether the connection should use a personal identity or an organization-managed service identity. Do not reuse credentials across environments unless that is part of the approved access design.
Connect
Section titled “Connect”- Open the MCP or connector selector in an eligible Cortex client.
- Select the enterprise service.
- Complete the provider authorization flow and review the requested scopes.
- Return to Cortex and confirm that the service shows as connected.
- Test a narrow read operation against a known resource.
- Enable write tools only after approval and audit requirements are defined.
Selecting a service and connecting it are separate steps. A selected service can still require authentication, a plan entitlement or administrator approval.
Validate the connection
Section titled “Validate the connection”Ask Cortex to identify the connected account and retrieve a non-sensitive, known resource. Confirm the tenant, organization, repository, project, account, subscription or region before allowing broader work. Test writes in a non-production resource and review the resulting provider audit record.
Revoke or replace
Section titled “Revoke or replace”Revoke the provider authorization and remove the Cortex connection when it is no longer needed. Reconnect explicitly when changing identity. Cortex does not silently substitute a different connected account after revocation or expiry.

