Workspace MCP roles, permissions, and security

Understand how Workspace MCP permissions work, which actions each Notiondesk role can access, and how OAuth keeps workspace access scoped to each teammate.

3 min read

Notiondesk Workspace MCP uses your existing workspace permissions to control what an AI assistant can access or change.

Connecting an AI assistant does not give your Notiondesk account additional permissions.

How Workspace MCP permissions work

Each teammate connects their own Notiondesk account. Workspace MCP then determines which information and actions are available based on:

  • The teammate's Notiondesk role
  • The help centers they can access
  • Whether Workspace MCP is enabled for those help centers

An AI assistant cannot access a help center or perform an action that the connected teammate is not allowed to access.

Permissions by Notiondesk role

Notiondesk roleWorkspace MCP access
ViewerRead help center information and insights
Billing ManagerRead help center information and insights
EditorRead information, update supported settings, and trigger supported actions such as syncs or translations
Admin or workspace ownerFull supported access, including restricted administrative actions

The exact tools available in your AI client can also depend on the MCP capabilities and restrictions of that client.

Workspace MCP follows each teammate's account

Permissions are not shared between teammates.

For example, if an Admin and a Viewer both connect Claude to the same Notiondesk workspace:

  • The Admin can access actions available to Admins
  • The Viewer only receives supported read-only access

Adding Workspace MCP to a shared Claude, Cursor, or VS Code environment does not share one person's Notiondesk permissions with everyone else.

Each teammate should complete their own OAuth authorization.

Access is scoped by help center

Workspace MCP is enabled separately for each help center.

An AI assistant can access a help center only when:

  1. Workspace MCP is enabled for that help center
  1. The connected Notiondesk teammate already has access to it

Enabling Workspace MCP for one help center does not automatically expose every help center in the workspace.

OAuth authentication

Workspace MCP uses OAuth rather than requiring you to copy Notiondesk credentials or API keys into your AI client.

During authorization, Notiondesk shows the workspace and permissions associated with the connection.

Before approving access:

  1. Confirm that the correct workspace is displayed
  1. Review the requested permissions
  1. Approve the connection only if the information is correct

Actions that change data

Editors, Admins, and workspace owners can perform supported actions according to their existing permissions.

Depending on the available Workspace MCP tools, this can include actions such as:

  • Triggering syncs
  • Starting translations
  • Updating supported help center settings
  • Managing AI Chatbot guidance
  • Managing redirects
  • Updating translation glossary entries
  • Managing changelog settings

Some actions may require confirmation in the AI client before they are performed.

Restricted deletion actions

Some destructive actions are limited to Admins.

These include supported deletion actions for:

  • Page redirects
  • Translation glossary entries
  • AI Chatbot guidance
  • Changelog subscriptions

Workspace MCP requires confirmation before performing these deletion actions.

Start with read-only requests

When connecting a new AI client, start by verifying access with a read-only request:

List the Notiondesk help centers I can access.

Then try:

Show the sync status for my main help center.

Once you have confirmed that the correct workspace and help centers are available, you can ask the assistant to perform supported actions.

Review changes before applying them

For workflows that modify your workspace, you can ask the assistant to explain or prepare changes first.

For example:

Review our recent chatbot conversations and suggest the guidance changes you recommend. Do not change anything yet.

Then, after reviewing the recommendations:

Apply the approved guidance changes.

This is useful for settings, translations, redirects, chatbot guidance, and other changes that affect your customer-facing help center.

What happens if you disable Workspace MCP?

Disabling Workspace MCP for a help center immediately blocks connected AI clients from accessing that help center.

Other help centers where Workspace MCP remains enabled are not affected.

Removing a connection from one AI client also does not revoke connections from other clients or teammates.

Security best practices

When using Workspace MCP:

  • Each teammate should connect their own Notiondesk account
  • Do not share sessions or credentials between teammates
  • Review the workspace and requested permissions before authorizing a connection
  • Give teammates the minimum Notiondesk role they need
  • Start with read-only requests when verifying a new connection
  • Review proposed changes before performing sensitive operations
  • Disable Workspace MCP for help centers that should no longer be accessible
  • Remove unused AI client connections

Related articles

Was this page helpful?