Skip to main content
Bridge Town

MCP · scopes

You decide what your assistant can touch.

When you connect, you grant a clear set of permissions — nothing more. Each one is plain to read, scoped to your workspace, and revocable in one click.

/ what each permission means

Six scopes, in plain English.

models:read

See your modelsRead the models, assumptions, and results in workspaces you grant access to. Nothing outside them.

models:write

Build & edit modelsCreate and change model logic and assumptions — every change is versioned and reviewable.

runs:execute

Run modelsExecute models in the safe, isolated space. No access to your files or the open internet.

data:connect

Use your dataRead the spreadsheets and files you attach, to query inside a model. Read-only on the source.

history:read

Read historyView past versions, runs, and results to compare or roll back.

sharing:manage

Manage sharingCreate and revoke dashboard links and model access for your team.

/ how we handle access

Least access, always revocable.

/ 01

Scoped to your workspace

A connection can only see the workspaces you grant. It can never reach another customer's data.

/ 02

Revoke in one click

Disconnect any client from your dashboard and access ends immediately — no waiting, no support ticket.

/ 03

Everything is logged

Every action taken with these permissions lands in an append-only audit trail you can review anytime.

Connect with confidence.

Grant only what you choose. Change your mind anytime.

Connect to Claude

Want the full picture? Security overview →