Access & Permissions

How organization opt-in, member permissions, tool tiers, and security boundaries govern access to the Pliant MCP.

The Pliant MCP uses a layered permission model. Organization admins control whether members can connect to the Pliant MCP at all. What AI agents can then access is governed by each member's existing Pliant role, and by their configuration of their AI client.

For Admins

Enabling MCP Access

MCP access is off by default. An admin must enable it before any member in the organization can connect an AI client.

To enable MCP access:

  1. Go to Settings → Modules in Pliant.
  2. Find the Pliant MCP tile and activate it.

Disabling MCP Access

Admins can disable MCP access for the entire organization by deactivating the same module. This immediately revokes access for everyone in the organization, across every connected AI tool. It does not delete conversation history already in your AI client.

For Members

Member Permission Model

The MCP server makes no authorization decisions of its own. Every tool call is authorized the same way a regular Pliant API call is: against the connected member's existing role and permissions.

  • A member can read and act on the data their role already lets them see in the Pliant product.
  • An agent cannot access data the connecting member cannot see in Pliant.
  • An empty result usually means the data is outside your permissions, not that it doesn't exist.

Members can configure which tools require approval within their AI client. Write tools that require approval will prompt the member to confirm the intended change before it executes.

Revoking Your Access

Members can disconnect their own AI client's MCP access at any time. See Disconnect Pliant MCP for the steps.

Rate Limits

Tool calls are rate-limited per connected member to protect the underlying services. Write actions carry a tighter, additional limit on top of the general one.

Security Boundaries

  • No payment actions. The MCP does not support top-ups, card issuance, or any autonomous payment decision.
  • No permission elevation. An agent cannot access data or take actions beyond the connected member's existing Pliant permissions.
  • No sensitive card data. Full card numbers, CVVs, or PINs are never returned by any tool.

What Comes Next?

Related Reading


Did this page help you?