Data can leave your MindBridge environment
The assistant queries results directly from your environment. Retrieved data may include sensitive transaction, vendor, employee, customer, or journal information, depending on the analysis. After that data is returned, it is handled according to the assistant provider’s terms. That can include a different region, different retention, model training, or subprocessors. MindBridge’s data protections do not automatically extend to the external assistant. MindBridge does not operate or control third-party AI assistants. Before you allow a connection, ensure that the provider’s data retention, model training, processing locations, and sharing practices meet your organization’s requirements. Your organization’s approval to use an assistant is separate from the consent an individual grants when they connect.Access is read-only in MindBridge, not elsewhere
The connection cannot create, change, or delete MindBridge records, ingest data, run analyses, or perform Insights workflows. There is no write permission for this connection. Read-only access still allows the assistant to retrieve and reproduce data. If the same assistant can send email, create documents, or publish content, it may share retrieved information through those tools. Review the assistant’s other connections and do not pair MCP with tools that send or publish automatically unless your organization has approved that combination. Analysis field values are source data, not instructions. A transaction description or other retrieved text can contain wording that tries to redirect the assistant, for example by asking it to send data elsewhere. Treat that text as data. Do not treat it as permission to act.Who can connect, and what they can see
MCP is not enabled by default. An App Admin must enable the global toggle on the settings screen. Each user then authorizes their own connection with OAuth 2.1, using their normal sign-in and your organization’s existing identity controls. You do not need API keys, service accounts, or shared credentials. Every request runs with that user’s MindBridge permissions. The assistant can access only the analyses available to that user. Restricting or removing their MindBridge access also restricts the connection. Users choose which read-only permissions to grant:- Analysis metadata to find analyses, describe their structure, and explain control points.
- Analysis result data to query specific result rows or aggregates.
What MindBridge logs, and what it does not delete
MindBridge logging of MCP use is limited and depends on your contract. For customers on standard terms, MindBridge may retain anonymized tool call inputs for 30 days, such as analysis identifiers, keyword searches, and SQL generated by the assistant. If your organization has contracted out of section 5.2 of the standard terms, MindBridge logs tool names but not their inputs. See Data Processing and Retention. Do not assume MindBridge logging is a complete record of what an assistant retrieved, stored, or shared. Copies in conversations, generated files, and the provider’s systems are outside MindBridge. Revoking a connection in Admin → MCP stops further access through that application. It does not delete information already retrieved. Manage those copies through the AI provider’s controls and your organization’s procedures. See Manage or Revoke Access.Answers can be wrong or incomplete
An assistant may misinterpret a field, apply an incorrect filter, summarize only part of an analysis or generate conclusions that are not fully supported by the underlying analysis results. Before relying on an answer:- Confirm that it used the intended analysis, risk score, and filters.
- Check whether the result is a limited list or represents all relevant records.
- Verify important figures and explanations against the analysis in MindBridge.
- Review generated content before sharing it or using it in reports or audit documentation.

