MCP Permissions and security
Permissions and Security using MCP Server
Who can connect an AI assistant to Spreo, what that assistant can reach, and how to control it.
What your assistant can access
When you connect an AI assistant to Spreo, it acts as you.
It sees exactly the boards and workspaces you see, and it can't reach anything you can't. It's bound to a single account: if you belong to more than one Spreo account you pick which one when you authorise, and the connection only covers that one. It gets no admin powers either, so connecting an assistant doesn't open up billing, member management or account settings.
If your access changes, your assistant's access changes with it. Remove someone from a workspace and their assistant loses that workspace too.
What you authorise
Spreo uses OAuth 2.0. You're never asked to paste a password or an API key into your AI tool.
When you connect, Spreo shows you what the assistant will be able to do:
Confirm who you are
See your profile: name, photo and email
See your workspaces and boards
Read, edit and create boards on your behalf
You authorise it once. Your AI tool holds a token from then on, and Spreo can revoke that token at any time.
Admin controls
Account owners control MCP for the whole account under Manage, then MCP.
Allow or block MCP
A single switch, Allow account members to connect AI tools via MCP, governs the entire account.
Turn it off and no member can connect an AI tool. Any existing connection stops working immediately. It applies to everyone in the account, owners included.
If your organisation isn't ready for AI tools to reach your boards, this is the control to use.
See who has connected
The Connected members table on the same page lists every member who has authorised an AI tool, showing the member, their email, which client they connected and when.
It's worth checking during the beta to see what's actually in use across your account.
Removing access
If you're a member, open your Spreo profile, go to Integrations, and remove the connection. Access stops straight away.
If you're an account owner, turn off the account switch under Manage, then MCP. That cuts off every connection at once.
Either way, remove the connector in your AI tool as well, or it'll sit there showing an error.
Where your board content goes
Two separate things happen when you use MCP, and they're worth keeping apart in your head.
Your board content goes to your AI provider. When your assistant reads a board, that content leaves Spreo and goes to whichever AI tool you connected, where it's handled under that provider's terms rather than ours. The same is true in reverse: whatever you paste into your assistant can end up on a Spreo board. Choose your AI tool the way you'd choose any other processor of your team's data, and check your organisation's position before you connect.
Spreo records MCP activity. We log which tools were called, and whether they worked, so we can support the beta, diagnose problems and understand what people are trying to do. When your assistant reads a board, the content it gets back isn't stored in that log. Content you send to build or change a board is.
Spreo doesn't use your data to train AI models. The AI Addendum has the detail.
Beta
Access is granted by request while MCP is in beta, and we set customers up individually. We want to know who's using it and hear directly from them while it takes shape.
For everything else about Spreo's security posture, see spreo.io/security.
Last updated

