MCP.computer
DirectoryDocs
Sign in
DirectoryDocsSign in
DocumentationOpen workspace
Start hereWhat is MCP.computer?Get startedApps and downloads
CapabilitiesModelsTools and skillsGoogle Workspace setupCompany knowledge
Run itAccess and governanceConnections and reports
Loading documentation
MCP.computer

One governed connection for your company’s tools, models, and knowledge.

ExploreDirectoryPlatformCatalog updatesCompany brainDocumentationApps & downloads
WorkspaceOpen workspaceTalk to us
CompanyPrivacyTermsContact
© 2026 MCP.computer

Access and governance

Understand how workspace membership, company approval, user consent, connection policy, and runtime enforcement combine.

How access is evaluated

01Workspace membership02Company availability03Person consent04Connection policy05Runtime enforcement

Removing membership, a catalog item, a connector grant, or a tool approval changes the effective runtime policy. The next request is checked against current authority rather than relying only on what was true when the app first connected.

Workspace roles

Workspace roles
RoleAccess
OwnerManage resources, model policy, access, budgets, reviews, and administrators
AdminManage resources, model policy, access, budgets, and reviews
PublisherPublish catalog resources and contribute knowledge
MemberUse approved AI apps, tools, skills, and knowledge
ViewerView the company resources made available to the workspace

Membership and reusable groups

  • Owners and admins can invite people with an explicit role and revoke pending invitations.
  • Owners can change roles for other members; admins can manage publishers, members, and viewers.
  • Removing a member ends workspace access immediately while preserving account and activity history.
  • Groups can contain people and agent identities, then be reused as access targets across capabilities.
  • Members and viewers receive a focused home for AI apps, company tools, and knowledge instead of administrator controls.

Single sign-on is a labeled preview

Enterprise workspaces can preview a setup plan for Microsoft Entra ID, Okta, Google Workspace, or another SAML provider. The preview validates the proposed company domain, metadata address, and optional or required policy without contacting the provider or changing sign-in.

Production enforcement remains unavailable until provider provisioning, owner testing, recovery access, and release verification are complete.

Runtime enforcement

Runtime responsibilities
LayerResponsibility
Workspace configurationApproved resources, access, budgets, reconciliation state, and customer-visible history
Request enforcementCurrent model, connection, budget, MCP-server, tool, and parameter policy

Every request is checked against the workspace’s current effective policy.

Reconciliation status

  • Active: the desired revision is enforced.
  • Provisioning: reconciliation is still in progress.
  • Needs attention: the desired revision could not be applied.

Data handling

  • Prompts, responses, tool inputs, and tool results stay out of the workspace dashboard and activity history.
  • Reusable provider credentials are handled separately from workspace configuration and are never displayed after submission.
  • One-time connection secrets are shown once; durable records keep identifiers and hints.
  • Activity records contain metadata such as actor, app, action, decision, latency, and outcome, not prompts or tool bodies.
Company knowledgeConnections and reports