Connecting a tool safely
Connect a business app or custom MCP server, grant employee access, test approval behavior and revoke access when work changes.
A tool gives an AI employee access to a system your company uses. Start with the responsibility, then connect the smallest useful capability.
Choose the connection
| Need | Connection path | What to verify |
|---|---|---|
| Supported business application | Tool access / app catalog | Connected account, workspace, provider consent and permitted data |
| Company or specialist MCP server | Tool access → Custom MCP | HTTPS endpoint, authentication, health and the actual tools it exposes |
| API.market or another paid API | Supported connector or custom MCP | Account, tool availability, service price and usage limits |
| Yodu from an external AI client | Yodu Platform MCP | Workspace-bound client authorization and allowed scopes |
A listed provider is not a guarantee that every action or customer plan is supported. We check the specific workflow during founding onboarding.
Connect a supported app
- Open Tool access and find the app.
- Connect the company account through the provider's authorization flow.
- Review provider consent and select the intended account or workspace.
- Check connection status and connected identity.
- Open employee access and enable the connection only for the intended employees.
- Set the employee to Draft only or Ask first for the first test.
- Ask it to retrieve a safe record and explain the evidence it used.
Provider permissions set the outer boundary. Employee tool switches control visibility. Employee autonomy and approval rules control how permitted actions execute. An instruction such as “never send emails” is not a substitute for restricting access.
Connect custom MCP
Use Custom MCP servers for the detailed flow. Add the remote HTTPS endpoint and authenticate with the supported OAuth flow or required request headers. Enter secrets in connection settings, never in chat. Re-test the server and inspect the exposed tools before enabling it for an employee.
Start with a harmless read. Then prepare a controlled write under Ask first, inspect the request, reject it with feedback and test the corrected request. Health means the server is reachable, not that every tool is safe or properly scoped.
Understand permission modes
- Draft only: research and prepare work without external changes.
- Ask first: request approval before external or irreversible actions.
- Auto: routine actions can execute directly; destructive actions still require review.
- Full autonomy: broader execution, including irreversible actions; avoid it for the first customer workflow.
Modes do not grant workspace membership or create missing provider permissions. The approval request should identify the proposed action and enough evidence for a human decision.
Slack
Where Slack is configured, verify the company Slack app, allowed channel, employee routing and a complete receive/respond cycle. A connected badge alone does not verify channel delivery. Start with a test channel. Connecting Slack as a tool and using Slack as an employee communication channel are distinct capabilities; confirm the one you need with your onboarding owner.
Disconnect and recover
Disable the connection for employees that no longer need it. Disconnect unused accounts and revoke access at the provider when necessary. Rotate exposed credentials. Pause affected schedules, repair access, re-test a safe read, then resume work. Inspect the task and activity records for the last successful and failed calls.
