Skip to content

Enterprise AI

Governed connector actions

Control read, write and consequential MCP operations with policy and approvals.

Enterprise connectors expose bounded tools, not unrestricted access to a service. Effective permission is the intersection of the organization entitlement, Cortex role, connector configuration, provider identity, provider resource permission and the active workflow policy.

Class Examples Recommended control
Read Search issues, retrieve a document, inspect cloud metadata Minimum provider scopes and context limits
Draft Prepare a reply, issue update or code change without publishing it Human review before use
Write Create or update a supported record, message or work item Explicit tool enablement and an attributable identity
Consequential Change infrastructure, merge code, trigger delivery or affect an external audience Approval, exact target confirmation and retained evidence

An approval applies to the exact proposed action and current target. A changed record, revision, payload or destination requires a new decision.

Keep the acting identity, connector, operation, target, workflow run and result status. Use content-minimized request identifiers for support. If an action is blocked, do not widen scopes immediately: confirm the resource, role, provider permission and policy decision first.