Scoped to your workspace
A connection can only see the workspaces you grant. It can never reach another customer's data.
MCP · scopes
When you connect, you grant a clear set of permissions — nothing more. Each one is plain to read, scoped to your workspace, and revocable in one click.
/ what each permission means
See your modelsRead the models, assumptions, and results in workspaces you grant access to. Nothing outside them.
Build & edit modelsCreate and change model logic and assumptions — every change is versioned and reviewable.
Run modelsExecute models in the safe, isolated space. No access to your files or the open internet.
Use your dataRead the spreadsheets and files you attach, to query inside a model. Read-only on the source.
Read historyView past versions, runs, and results to compare or roll back.
Manage sharingCreate and revoke dashboard links and model access for your team.
/ how we handle access
A connection can only see the workspaces you grant. It can never reach another customer's data.
Disconnect any client from your dashboard and access ends immediately — no waiting, no support ticket.
Every action taken with these permissions lands in an append-only audit trail you can review anytime.
Grant only what you choose. Change your mind anytime.
Connect to ClaudeWant the full picture? Security overview →