Skip to main content
MCP gives a compatible AI assistant read-only access to completed analyses the signed-in user can already see in MindBridge. The main risk is not that the assistant can change MindBridge records. It is that analysis data can leave your MindBridge environment and then be processed, stored, or shared in ways MindBridge does not control. Use of MCP remains subject to your organization’s applicable agreement with MindBridge, including the Terms of Use and related service documentation. By enabling MCP access, you acknowledge that you have reviewed the considerations described on this page and are authorized by your organization to enable the connection. Use this page for a security or acceptable-use review. Connection steps are in Get Started. Retention and regional processing are in Data Processing and Retention.

Data can leave your MindBridge environment

The assistant queries results directly from your environment. Retrieved data may include sensitive transaction, vendor, employee, customer, or journal information, depending on the analysis. After that data is returned, it is handled according to the assistant provider’s terms. That can include a different region, different retention, model training, or subprocessors. MindBridge’s data protections do not automatically extend to the external assistant. MindBridge does not operate or control third-party AI assistants. Before you allow a connection, ensure that the provider’s data retention, model training, processing locations, and sharing practices meet your organization’s requirements. Your organization’s approval to use an assistant is separate from the consent an individual grants when they connect.

Access is read-only in MindBridge, not elsewhere

The connection cannot create, change, or delete MindBridge records, ingest data, run analyses, or perform Insights workflows. There is no write permission for this connection. Read-only access still allows the assistant to retrieve and reproduce data. If the same assistant can send email, create documents, or publish content, it may share retrieved information through those tools. Review the assistant’s other connections and do not pair MCP with tools that send or publish automatically unless your organization has approved that combination. Analysis field values are source data, not instructions. A transaction description or other retrieved text can contain wording that tries to redirect the assistant, for example by asking it to send data elsewhere. Treat that text as data. Do not treat it as permission to act.

Who can connect, and what they can see

MCP is not enabled by default. An App Admin must enable the global toggle on the settings screen. Each user then authorizes their own connection with OAuth 2.1, using their normal sign-in and your organization’s existing identity controls. You do not need API keys, service accounts, or shared credentials. Every request runs with that user’s MindBridge permissions. The assistant can access only the analyses available to that user. Restricting or removing their MindBridge access also restricts the connection. Users choose which read-only permissions to grant:
  • Analysis metadata to find analyses, describe their structure, and explain control points.
  • Analysis result data to query specific result rows or aggregates.
Granting only metadata access limits the assistant to structure and explanations. It cannot retrieve underlying result rows.

What MindBridge logs, and what it does not delete

MindBridge logging of MCP use is limited and depends on your contract. For customers on standard terms, MindBridge may retain anonymized tool call inputs for 30 days, such as analysis identifiers, keyword searches, and SQL generated by the assistant. If your organization has contracted out of section 5.2 of the standard terms, MindBridge logs tool names but not their inputs. See Data Processing and Retention. Do not assume MindBridge logging is a complete record of what an assistant retrieved, stored, or shared. Copies in conversations, generated files, and the provider’s systems are outside MindBridge. Revoking a connection in Admin → MCP stops further access through that application. It does not delete information already retrieved. Manage those copies through the AI provider’s controls and your organization’s procedures. See Manage or Revoke Access.

Answers can be wrong or incomplete

An assistant may misinterpret a field, apply an incorrect filter, summarize only part of an analysis or generate conclusions that are not fully supported by the underlying analysis results. Before relying on an answer:
  • Confirm that it used the intended analysis, risk score, and filters.
  • Check whether the result is a limited list or represents all relevant records.
  • Verify important figures and explanations against the analysis in MindBridge.
  • Review generated content before sharing it or using it in reports or audit documentation.
A high-risk score alone is not evidence of fraud, error or non-compliance. Use MindBridge results alongside the analysis context and your professional judgment. MindBridge is responsible for operating the MCP Server and enforcing access controls within MindBridge. Customers are responsible for selecting and governing their AI assistant and reviewing AI-generated responses for their intended use.