MCP server
Privacy and redaction
What a tool result contains, what is held back by default, and what is recorded when an assistant asks for more.
Whatever a tool returns goes into your assistant's context, and from there to the model provider that assistant uses. That is outside Oleon. So the server returns what answers most questions, which is when something happened, which way it went and whether it worked, and holds back what most questions do not need.
What is redacted by default
| Data | What the assistant receives |
|---|---|
| Message text, captions, previews and snippets | [redacted] (42 chars), with the length kept |
| Phone numbers and WhatsApp IDs | The last four digits, as •••4821 |
| Email addresses | The first letter and the domain, as j•••••@example.com |
| Links to attachments and media | Removed entirely |
The length stays because it still answers useful questions, such as whether a customer sent a one-word reply or three paragraphs, without revealing the words. Attachment links are removed rather than masked because a working link is a credential: anyone holding it could download the file.
Everything else, such as timestamps, directions, delivery status, failure reasons, labels, assignees and order totals, is returned as it is.
Asking for message text
Two tools accept include_message_text:
When an assistant sets it to true, that one call returns the words themselves. Phone numbers and email addresses stay masked, and attachment links stay removed.
The result says which case applies in its _meta block, so neither you nor the assistant has to guess:
{
"data": { "…": "…" },
"_meta": { "message_text": "included and audited" }
}Assistants are told to ask for message text only when a question cannot be answered without it. You can also tell yours directly, for example: "Don't read message text unless I ask."
What is recorded
These events are written to Oleon's audit log under the MCP category, with the person, the time and the details:
| Event | Recorded detail |
|---|---|
| A tool call that includes message text | The tool, the project and the arguments it was called with |
A Bot Studio draft created with create_flow_version | The project, the flow type, the instance and the version number |
| A connection approved through OAuth | The app that asked, by the name it registered |
| A connector token created or revoked | The token's name |
Reads that do not include message text are not written to the audit log individually.
What Oleon does not do
- The MCP server does not send your data to a model. It has no model of its own; your assistant brings one.
- Tool results are not cached or stored. Each call reads your workspace as it is at that moment.
- Using the MCP server does not draw on your Oleon Support allowance. The model usage belongs to your assistant's provider.
The rest of it
This page covers what the MCP server does with your data. What Oleon Workspace as a whole collects, who it is handed to and how long it is kept is in the privacy policy, and how the product is built and operated is on the security page.
