What you control, and where
The control that matters most is the one you already use
Because a connection carries exactly the permissions of the person who made it, your existing roles and groups are the access control. You do not need a separate policy for AI assistants to decide who can see what. A rep who connects sees their own practice because that is what a rep sees. And for offboarding, the answer is the one you would do anyway: deactivate the person in Exec, or remove them from the workspace, and their connection stops working on its next request. Nobody has to go into their AI assistant. So the two things worth doing before a wide rollout are ordinary Exec hygiene:- Check your group structure. Group admins see their groups through the connection, so if groups are wrong, visibility is wrong.
- Check who has admin. Workspace admins see the whole workspace, including all analytics, through the connection.
Approving Exec once, for your organization
If your company is on a team or enterprise plan for your AI tool, connectors usually have to be approved centrally before anyone can use them. That approval is your main gate. An owner on that side adds Exec once, usinghttps://api.exec.com/mcp, after which each person connects their own account. Approving the connector does not grant anyone access to any data. See Connect your AI tool.
Turning that approval off later blocks new connections, and depending on the assistant may block existing ones too. Your assistant’s own documentation is the authority there.
What to tell your team when you roll this out
Three things are worth saying explicitly, because they are the ones that cause surprises:- Scenarios published through an assistant are shared with the whole workspace. See What the AI can see.
- It answers the question you asked. Point people at Prompts and reliable answers before they start quoting numbers in reviews.
- An assistant with several tools connected can carry Exec data into the others. If you have policies about where performance data may go, say that they cover AI assistants too.
FAQs
Can I see which of my people have connected?
Can I see which of my people have connected?
Not from Exec today. There is no MCP screen in the product. If your company approves connectors centrally in your AI tool, that side may show connection status.
Can I stop one person using it without deactivating their Exec account?
Can I stop one person using it without deactivating their Exec account?
Not from inside Exec. They can disconnect it themselves in their assistant, and an owner on your AI assistant’s organization can remove the connector for everyone. Deactivating the person in Exec cuts access immediately but also removes their access to Exec generally.
Can I turn MCP off for my whole workspace?
Can I turn MCP off for my whole workspace?
Not as an Exec setting. The effective control is to not approve Exec as a connector in your AI tool’s organization settings, which prevents your people from connecting it there.
Can I limit it to reading, with no scenario creation?
Can I limit it to reading, with no scenario creation?
Not per workspace. Creating a roleplay is the only change it can make, it always shows a draft for approval first, and it cannot delete or edit anything. Some assistants let an individual block specific capabilities on their own connection.
Is there an audit log of what people asked?
Is there an audit log of what people asked?
Not in Exec. Activity performed through the connection appears the way the same activity would if done in the product, so a scenario created this way is attributed to the person who created it.
Next
What the AI can see
The full permission model
Available tools
Everything it can do, listed