Enterprise AI
Governed connector actions
Control read, write and consequential MCP operations with policy and approvals.
Enterprise connectors expose bounded tools, not unrestricted access to a service. Effective permission is the intersection of the organization entitlement, Cortex role, connector configuration, provider identity, provider resource permission and the active workflow policy.
Action classes
Section titled “Action classes”| Class | Examples | Recommended control |
|---|---|---|
| Read | Search issues, retrieve a document, inspect cloud metadata | Minimum provider scopes and context limits |
| Draft | Prepare a reply, issue update or code change without publishing it | Human review before use |
| Write | Create or update a supported record, message or work item | Explicit tool enablement and an attributable identity |
| Consequential | Change infrastructure, merge code, trigger delivery or affect an external audience | Approval, exact target confirmation and retained evidence |
An approval applies to the exact proposed action and current target. A changed record, revision, payload or destination requires a new decision.
Audit and troubleshooting
Section titled “Audit and troubleshooting”Keep the acting identity, connector, operation, target, workflow run and result status. Use content-minimized request identifiers for support. If an action is blocked, do not widen scopes immediately: confirm the resource, role, provider permission and policy decision first.

