MCP Server

MCP Server — Governed AI Agent Access to Your Workspace

Connect Claude, ChatGPT, and any MCP-compatible agent to your SmartSuite data through the Model Context Protocol—so agents can query Records, explore schemas, and take action inside the same guardrails that govern your teams.

What Is MCP Server?

The MCP Server is a SmartSuite capability that connects AI agents to your Workspace through the Model Context Protocol, the open standard for giving assistants like Claude and ChatGPT access to external tools and data. It lets MCP-compatible agents explore Solution schemas, query and update Records, and work with Automations and Dashboards—under access modes and audit logging you control. SmartSuite offers a Local MCP Server today, with a Hosted MCP Server on the way, extending the same governed data model behind the REST API to AI agents.

Agent Connectivity

Connect Claude, ChatGPT, and Any MCP-Compatible Agent

The MCP Server speaks the Model Context Protocol, so it works with the agents your teams already use—Claude Desktop, Claude Code, Cursor, and other MCP-compatible platforms. Ask a question in plain language and the agent reads your actual Solutions, Tables, and Records instead of guessing.

One connection gives an assistant durable, structured context about how your work is organized—no copy-pasting data into chat windows.

Workspace Actions

Query, Create, and Update Records From Your AI Agent

Connected agents do more than read. MCP Server tools cover schema discovery (list Solutions, describe Tables and Fields), Record operations (query, create, update), file uploads, comments, and SmartDoc content—plus building blocks like Automations, Forms, Dashboards, and Views.

An agent can inspect a Solution's structure, draft the missing Table, populate Records, and wire up the Automation—work that used to take a build session happens in a conversation.

Governed Access

Govern Every Agent Action With Access Modes and Audit Logs

AI access follows your rules, not the other way around. The MCP Server authenticates with a SmartSuite API key and Workspace ID, and administrators set the server's mode—read-only, read-write, or admin—so an agent can never exceed the access you granted. Allowlists narrow which applications an agent can touch, and destructive operations can require explicit confirmation.

Write operations are audit-logged, keeping agent activity as traceable as any Member's.

Local & Hosted

Run the MCP Server Locally Today—Hosted MCP Is on the Way

The Local MCP Server is open source and runs on your own machine: install it as a Claude Desktop extension or deploy it with npm or Docker, and your credentials never leave your environment. It's available on all current SmartSuite plans.

A Hosted MCP Server—managed by SmartSuite on a production-grade, governed track—is coming soon, bringing the same agent access without local setup.

Platform Context
How GRC Teams Use

MCP Server

AI agents are becoming coworkers in governed GRC operations. The MCP Server gives them structured, auditable access to the risk registers, control libraries, and evidence workflows your teams run in SmartSuite.

Conversational Control Queries

Ask Claude which controls are overdue for testing, which frameworks a control maps to, or where evidence is missing—the agent queries the live control register instead of a stale export.

Drafting Risk Register Updates

Have an agent read assessment Records, draft updated risk narratives into SmartDoc content, and stage register updates for a risk manager to review—inside read-write limits an admin set.

Audit Fieldwork Preparation

Let an agent query open evidence requests, summarize related Records and comments, and flag gaps before fieldwork begins. Reviewers get context in seconds, and every agent write lands in the audit log.

Scaffolding a Vendor Risk Register

Describe the third-party risk workflow you need and let an MCP-connected agent inspect existing schemas, create the Tables and Fields, and wire up Views—reviewed by a Solution Manager before rollout.

Agent Reads, API Syncs

Pair the MCP Server with the REST API: agents handle exploratory, conversational register work while scheduled API jobs handle high-volume compliance reporting sync—both against the same governed data model.

Works Better Together
Related Features

AI agents are becoming coworkers in governed GRC operations. The MCP Server gives them structured, auditable access to the risk registers, control libraries, and evidence workflows your teams run in SmartSuite.

Features FAQ’s
Frequently Asked Questions About
MCP Server
What is the SmartSuite MCP Server?

The MCP Server connects AI agents to SmartSuite through the Model Context Protocol, an open standard for giving assistants access to external tools and data. Connected agents can explore Solution schemas, query and update Records, and work with building blocks like Automations and Dashboards—governed by access modes you configure.

Which AI tools work with the SmartSuite MCP Server?

Any MCP-compatible client—including Claude Desktop, Claude Code, Cursor, and other agents that support the Model Context Protocol. Because MCP is an open standard, new compatible clients work without SmartSuite-specific development.

What is the difference between Local and Hosted MCP?

The Local MCP Server is open source and runs on your own machine—installed as a Claude Desktop extension or via npm or Docker—so credentials stay in your environment. The Hosted MCP Server, coming soon, will be managed by SmartSuite on a production-grade, governed track without local setup.

How does the MCP Server keep AI access governed?

Administrators set the server's access mode—read-only, read-write, or admin—and can restrict which applications an agent may touch with allowlists. Destructive operations can require confirmation, write operations are audit-logged, and the server authenticates with a SmartSuite API key, so an agent never has more access than that credential grants.

Can an AI agent modify or delete my SmartSuite data through MCP?

Only if you allow it. In read-only mode agents can query but never write; read-write mode enables Record changes; and delete operations can be gated behind explicit confirmation. Every write is captured in audit logs.

Which plans include the MCP Server?

The Local MCP Server is available on all current SmartSuite plans, per the pricing page. The Hosted MCP Server is listed as coming soon, also across all current plans.

Do I need the REST API to use the MCP Server?

No separate build is required—the MCP Server is a ready-made bridge, authenticated with a SmartSuite API key and Workspace ID. The REST API remains the right channel for custom, high-volume programmatic integrations; the MCP Server is purpose-built for conversational agent access.

Put AI Agents to Work—Without Losing Control

Connect Claude or any MCP-compatible agent to your Workspace and let it query, build, and update inside guardrails you set.