Connect & MCP
Connect & MCP

Approvals, permissions, and safety

Magister uses two layers of control: connector scopes decide which kinds of MCP tools are available, and the brand's Permissions policy decides which external actions must stop for review.

Baseline access — profile, plan, audit, AI-visibility, asset, social-analytics, and integration-discovery reads are available with the default scope. Built-in Magister research, audits, AI-visibility checks, plan recompiles, and media generation use that same baseline grant; metered calls remain bounded by the organization’s usage ledger and budget. External-account writes require their documented opt-in scope.

Immediate confirmation — publishing live content, sending email, spending money, deleting an asset, and other destructive actions require the relevant scope and an immediate user confirmation. The public catalog creates Meta and TikTok campaigns atomically paused; the full custom endpoint also supports LinkedIn, Pinterest, and X through immediate pause and readback, which can return an unresolved result that must be verified. Activating spend is a separate explicit action. Paid ads, live publishing, email send, and signed-in browser control remain separate permissions that even Full access does not silently include.

Permissions panel — open Permissions in the right-hand panel. Pending shows requests waiting for a decision; History shows allowed, denied, running, successful, failed, and expired actions from Connect, Agent, workflows, and Slack. Open a request to review the exact destination, content, schedule, campaign, repository, or other details.

Approve or deny — approve to let the displayed action run, or deny it. A denial can include optional feedback for the agent, and the note remains in permission history rather than being sent to the external service.

Returning to the assistant — a high-risk MCP tool can return an operation ID and Magister review link. After you decide, the assistant polls the approval status and receives a redacted result rather than the raw action token or sensitive arguments.

Standard permissions — every new brand starts on Standard: media generation and routine data edits inside connected tools can run without asking, while email, social/content publishing, paid ads, code and pull requests, and destructive actions ask first. The selection is saved for the brand, so each new chat keeps the latest setting chosen by a brand admin; workflows, Slack, and Connect use it too.

Ask-before categories — brand admins can choose Ask first, Standard, Allow all, or their own category mix. Turning a category off allows matching actions to run without asking. Allow all requires a strong confirmation; provider authorization, budgets, ownership checks, and other guardrails still apply. Paid spend and destructive approvals require a brand admin.