MCP server
Access and permissions
A connection sees exactly what you see in Oleon Workspace, checked on every call.
A connection has no permissions of its own. It names you, and every tool call is checked against your memberships at the moment it runs, using the same rules the app uses when you open a page.
What you can reach
Your reach comes from where you are a member:
| Membership | What the connection can read |
|---|---|
| A project | That project |
| An organization with full access | Every project in the organization |
| An organization with partial access | Only the projects you have been given |
| An enterprise | The organizations and projects under it that your membership covers |
Ask your assistant to call whoami to see the result for your account. Each project is listed with its slug, the kind of access you have, and whether your role restricts it:
{
"user": { "id": "3f1c…", "email": "you@example.com" },
"counts": { "enterprises": 0, "organizations": 1, "projects": 2 },
"projects": [
{ "slug": "acme-store", "access_type": "full", "restricted_by_role": false },
{ "slug": "acme-support", "access_type": "partial", "restricted_by_role": true }
],
"organizations": ["acme"],
"enterprises": []
}Roles that restrict a project
When restricted_by_role is true, you are a member of the project but your role grants only some of it. A tool that reads a part your role does not include is refused for that project, even though other tools work.
This is expected, and it is the same answer the app would give you.
When a call is refused
A refusal comes back as a normal tool result that the assistant can read, not as a connection error:
You do not have access to "acme-support", or your role does not include this data. Call list_projects to see what you can read.The message is the same whether the project does not exist or you are not a member of it, so a connection cannot be used to discover projects in other accounts.
If your assistant reports "no access" for a project you can open in the app, ask it to call list_projects and check the slug. A project's slug is not always its display name.
When your access changes
Nothing is copied onto a connection when it is created. If someone adds you to a project, changes your role or removes you from an organization, every connection you have follows within seconds.
Removing a person from a workspace therefore removes what their connections can read, without anyone needing to find and revoke them.
