Skip to main content

Guide to MCP Tool Permissions

Admin users decide which actions AI clients are allowed to perform for your business via MCP. Actions that can lead to money moving are switched off by default, so you have to deliberately turn them on.

Who can do this

  • Only Admin users can access "Manage tool permissions".

  • Settings apply to the whole business, not to individual users.

  • If you are not an Admin, contact your admin to request a change.

Default settings

Tools fall into three groups.

Tool type

What it covers

Default

Read-only

Viewing balances, transactions, cards, budgets and similar

Enabled

Write, no money impact

Actions that change records without leading to money moving

Enabled

Write, money impact

Actions that can lead to money moving later, such as approving a bill or claim, or creating and approving a card

Disabled

Notes:

  • No tool can send a transfer or make a payment. Payment execution always stays in Aspire and requires human action.

  • Enabling a tool does not override role permissions. A user can only use a tool if their Aspire role already allows that action.

How to change tool permissions

  1. On your Aspire dashboard, click "Settings" in the top navigation bar (web app)

  2. Click "MCP" -> "Manage tool permissions".

  3. Find the tool you want to change. Tools are grouped by type.

  4. Switch the tool on or off.

  5. If you are enabling a tool with a money impact, read the confirmation and confirm.

Notes:

  • Turning a tool off removes it from what AI clients can do for your business straight away. Permissions are checked on every request.

  • You can disable read-only tools too, not just write tools.

What to do if a tool is not working

  • Your AI client says it cannot perform an action. Check the tool is switched on in "Manage tool permissions".

  • The tool is on but one person still cannot use it. Their Aspire role does not permit that action. Tool permissions do not grant role permissions.

  • The whole section has disappeared. MCP has been disabled for your business. Re-enable it from the banner in "Settings" then "MCP".

Which tools are on by default?

Read-only tools and write tools with no money impact are on. Tools that can lead to money moving, such as approving a bill or claim or creating a card, are off.

Can the AI send a transfer or make a payment?

No. No tool can execute a payment. Payment execution always stays in Aspire and requires human action.

Why did I get a confirmation when switching on a tool?

That tool can lead to money moving later. Tick "Don't show this again" in the confirmation if you do not want the prompt for other tools in that group.

Do tool permissions apply per user?

No. They apply to the whole business.

If I enable a tool, can everyone use it?

No. Users can only use a tool their Aspire role already allows. Enabling a tool does not grant role permissions.

Can I switch off read-only tools too?

Yes. You can enable or disable any tool.

How quickly does a change take effect?

Immediately. Permissions are checked on every request.

Did this answer your question?