Glossary

MCP ConnectionCopy link to this section

An MCP connection is the thing a person creates when they connect an AI tool to a product, and the thing they revoke when they want it to stop. It is worth naming precisely, because the obvious alternatives are all wrong in ways that matter.

It is not a token. A connection outlives any individual token; tokens are minted and rotated under it, and revoking the connection kills all of them at once.

It is not an integration. An integration is usually something an organization installs once, for everybody. A connection belongs to one person: two colleagues connecting the same tool have two connections, with different access, revocable independently.

It is not a session. A session ends when the work does. A connection persists until somebody revokes it, which is precisely why it needs to be visible somewhere a person can find it.

The four things that define oneCopy link to this section

Who. A connection acts as one person. Anything it does is attributable to them, and its access is bounded by theirs.

What tool. Claude Code, Claude Desktop, ChatGPT, Cursor. Registered separately, so revoking one does not disturb the others.

Where. One organization, chosen when the connection is approved. Reaching a second organization means making a second connection — which sounds like friction and is actually the point: it makes "which company's data can this tool see" a question with a single answer.

What it may do. A fixed set of permissions, approved by a human on a consent screen, that can never exceed what that person could do themselves.

Why the scoping is worth the frictionCopy link to this section

The alternative — one connection reaching everything the person can reach — is easier to build and much harder to reason about. When something goes wrong, the question is always "what could this thing see?" A connection scoped to one organization with an explicit permission list answers it in one line.

The rule that access can never exceed the person's own role is what makes a connection safe to hand out. It cannot be used to escalate: if a Member cannot read conversation transcripts in the dashboard, a tool they connect cannot read them either. And because that check is re-run rather than baked into the token, demoting somebody takes effect on their connections too.

At FloeCopy link to this section

Floe lists a member's connections under Organization settings → Connected apps, with the access each holds and when it was last used. Revoking one stops it working within a minute.

See how Floe runs a live demo

Every inbound visitor gets a personalised, AI-led demo of your product. No form. No SE. No wait.

Talk to us