Organization Access
Authorize an MCP client, choose an organization, and revoke access.
MCP access is scoped to the signed-in user and selected organization. This keeps plans, runs, environments, and evidence separated between teams and deployment tiers.
Authorization flow
When the MCP client connects, Autonomy opens a browser authorization flow. Sign in, choose the organization, then approve the client connection.
Organization selection
The selected organization scopes the plans, runs, traces, and environments available to the MCP client. If the wrong organization appears, sign out in the browser and authorize again with the correct account.
Permissions
The client can only access resources your account is allowed to see. Organization admins can restrict access by role and revoke client authorization when a user or agent no longer needs it.
Revocation
Revoke MCP access from account or organization settings. After revocation, the MCP client must repeat the browser authorization flow.
Common mistakes
- Authorizing with a personal account that is not a member of the target organization.
- Using a production MCP URL while expecting staging plans.
- Leaving an old browser session signed in to the wrong account.