MCP access control for multi-client teams
Your clients’ data in the assistant. Their keys on nobody’s laptop.
Atrium runs the connectors — Google Analytics 4, Search Console, Postgres — on the server, and hands each person only the tools for the accounts they work on. One connection, scoped by role, credentials never in reach.
$ claude mcp add --transport http atrium \
https://atrium.savantly.cloud/api/mcp/{org-slug} \
--header "Authorization: Bearer sk_org_..."Twelve clients, three sources, six people
That is thirty-six credentials, and the usual answer is to spread them across laptops as service-account JSON and OAuth tokens. Then someone rolls off an account and the keys stay where they landed.
Connect once, centrally
Each client’s source is one row in your dashboard. Test the draft, publish it, and the secret is encrypted at rest from that moment on.
Entitle a role per client
A role names the connectors it can reach — whole server, or one named query at a time — and carries that client’s scope with it.
Assign and unassign
Staffing a consultant onto an account is one assignment. Off it is one removal, and there is nothing left on their machine to revoke.
Same endpoint. Different tools.
Everyone adds the same URL. What comes back is resolved per caller, per request, from the roles you assigned — not from what the caller asks for.
Dana
Acme only
acme_ga4_run_report
acme_gsc_search_analytics
acme_db_queryRae
Globex and Initech
globex_ga4_run_report
globex_gsc_search_analytics
initech_ga4_run_reportThe scope is bound, not asked for
A role can carry the property ID, the site URL, the tenant column. Those parameters are applied on the server and never appear in the tool’s input schema — so the model has no way to name another client’s account, whether it is confused or coaxed.
A shorter list is a sharper assistant
Tool definitions are context, and assistants get worse as the list grows. A gateway that unions every server your firm owns makes that worse. Atrium hands over one client’s tools, because that is all the caller is entitled to.
Connectors, ready to publish
Add the connection details once in the dashboard, test the draft, and publish. Everyone you grant access to picks up the tools on their next connect — nothing to install, and the credential never leaves the server.
- Google Analytics 45 tools
- Standard and realtime reports, metric/dimension metadata, property details, and account summaries — against the properties you grant, and no others.
- Google Search Console6 tools
- Search analytics, site and sitemap listings, and live URL inspection — for both domain and URL-prefix properties.
- Postgres3 tools
- Search tables, describe a table, run a read-only query — or withhold the generic query tool entirely and publish only the named queries you authored.
And the servers you don’t host
For the MCP servers your team installs themselves, Atrium replaces the internal wiki with a live, per-role list the assistant can actually read — ask it what you have access to and it hands back the right install artifact for the client in front of it, or files an approval request when the answer is no.
Atrium never proxies servers a client could reach on its own. It sits in the tool-call path for the sources you explicitly host, and nowhere else — so the blast radius stays the size of what you handed it.
list_available_servers
get_server_details
get_install_instructions
check_install_status
check_policy_status
request_approvalThe parts your client’s security review asks about
Deny by default
A principal sees the union of their roles’ entitlements and nothing else. A connector with no grant is invisible, not merely locked.
Credentials stay with you
Connection secrets are encrypted at rest, never rendered back into the dashboard, and scrubbed from logs and error messages.
Every org is a wall
Every row is scoped by organization on the only read path there is. There is no unscoped query for a caller to reach through.
Approvals in the flow
When someone asks for a server they can’t see, the assistant files a request that lands in your dashboard queue instead of dead-ending.
Policy-aware answers
Atrium reads the client’s managed MCP policy and tells the user “already approved — run this” rather than handing out a command that will be blocked.
Sign in the normal way
Desktop and web clients connect over OAuth with your existing identity provider. Server-to-server callers use a scoped organization API key.