Connection is not authorization

Claude documentation includes MCP integrations. A connector simplifies access but does not decide which records an assistant should read or change. List required operations first and grant each only the access it needs.

Map trust boundaries

Identify who runs the connector, what data crosses it and how access is revoked. Retrieved documents are data, not instructions governing the agent. A paragraph in a file must not authorize sending records to a new destination.

Pilot read-only access

Start with non-sensitive read access for a small team. Test session expiry, revoked users and permission changes. Log operations without secrets, and introduce writes only after approval and recovery paths are understood.