MCP: roles, permissions and modules – who may use which tools

Whether a tool is available is decided by three levels together: your role in the organization, the access level (scope) of the connection and the enabled modules. Only when all three match does the tool appear in the list and can it be called.

Prerequisites
  • You know your role in the organization (Owner, Admin, Member or Viewer).
  • You know which access level the MCP connection was created with (Account → Integrations).

Level 1: role in the organization

Every tool requires a minimum role. The order is Viewer < Member < Admin < Owner; owners meet every requirement. Distribution: 51 tools from Viewer, 43 from Member, 20 from Admin.

Viewer
May read and list, and use the read-only AI tools (similarity search, sprint suggestion, effort estimate, analytics).
Member
Additionally may create and change, and read some finance-related reports: budget forecast, expenses, accounting receipts and income. May delete draft invoices with the delete scope.
Admin and Owner
Additionally may use all delete tools, create, change, activate and delete budgets, delete expenses and set member rates. They also see monetary amounts in the budget reports.

Level 2: access level (scope) of the connection

A connection carries one of three cumulative levels. There are 55 tools with scope read, 42 with write and 17 with delete.

read (Read only)
Read and list.
write (Read and write)
Additionally allows all tools with scope write: create and update.
delete (Full access)
Additionally allows all delete tools. A higher level includes the lower ones.

Level 3: enabled modules

Most tools belong to a module and are available only if the module is enabled in the organization and assigned to you (organization-wide module choice, custom roles and per-member module assignments are respected). 20 tools have no module switch: list_organizations, get_organization, list_members, get_analytics, list_milestones, get_milestone, create_milestone, update_milestone, delete_milestone, list_network_contacts, get_network_contact, search_network_contacts, create_network_contact, update_network_contact, delete_network_contact, list_reviews, get_review, create_review, update_review, delete_review.

Calendar
3 tools: list_calendar_events, create_calendar_event, find_team_free_slots
Tasks
7 tools: list_tasks, get_task, create_task, update_task, delete_task, find_similar_tasks, estimate_task_effort
Projects
5 tools: list_projects, get_project, create_project, update_project, delete_project
Sprints
8 tools: list_sprints, get_sprint, create_sprint, update_sprint, delete_sprint, add_task_to_sprint, remove_task_from_sprint, suggest_sprint_plan
Files
2 tools: list_files, list_file_folders
Notes
5 tools: list_notes, get_note, create_note, update_note, delete_note
Time tracking
6 tools: list_time_entries, get_running_timer, create_time_entry, stop_timer, update_time_entry, delete_time_entry
Metrics
5 tools: list_metrics, get_metric, create_metric, update_metric, delete_metric
Goals
5 tools: list_goals, get_goal, create_goal, update_goal, delete_goal
Meetings
6 tools: list_meetings, get_meeting, create_meeting, update_meeting, delete_meeting, list_meeting_folders
Knowledgebase
6 tools: list_kb_items, get_kb_item, search_kb, create_kb_item, update_kb_item, delete_kb_item
CRM
11 tools: list_crm_leads, get_crm_lead, create_crm_lead, update_crm_lead, delete_crm_lead, create_crm_activity, get_crm_dashboard, get_crm_weekly_briefing, list_crm_email_drafts, create_crm_email_draft, update_crm_email_draft
Budgeting
13 tools: list_budget_overview, get_project_budget, list_retainers, get_budget_forecast, list_expenses, list_member_rates, create_budget, update_budget, activate_budget, create_expense, set_member_rate, delete_budget, delete_expense
Invoices
6 tools: list_invoices, get_invoice, create_invoice, update_invoice, delete_invoice, create_invoice_correction
Accounting
4 tools: list_accounting_receipts, update_accounting_receipt, delete_accounting_receipt, list_accounting_income
Planning
2 tools: get_planning_week, list_unscheduled_tasks

How missing permissions show up

For organization-bound connections the server filters the tool list: what you may not use does not appear. For account-wide connections without an organization header all tools are visible at first because the organization is only known at call time; there the server checks on call and answers missing permissions with "Insufficient permissions for this tool". The same applies to tools of a disabled module.

Data visibility for members

There is no restriction for owners and admins. For other roles some tools apply additional visibility rules that also hold in the web app.

Invoices and accounting
list_invoices, get_invoice, create_invoice, update_invoice, delete_invoice, create_invoice_correction, list_accounting_receipts, update_accounting_receipt, delete_accounting_receipt and list_accounting_income respect role-based project visibility. Items without a project stay visible.
CRM drafts
list_crm_email_drafts, create_crm_email_draft and update_crm_email_draft respect lead ownership: your own leads, leads of people reporting to you and unassigned leads.
AI tools for tasks
find_similar_tasks, estimate_task_effort and suggest_sprint_plan respect your task visibility (own tasks, tasks of people reporting to you, project grants of the role).

Monetary amounts for admins only

In the budget reports (list_budget_overview, get_project_budget, list_retainers, get_budget_forecast, list_member_rates) the server returns amounts, cost rates and revenue forecasts only to owners and admins. Other roles receive null but still see hours and percentages.

Traceability and safeguards

Sensitive actions follow additional rules regardless of role.

Audit log
Invoices (create, finalize, status change, correction) and receipt deletion are recorded with actor type "mcp".
Legal hold
A receipt with a document under legal hold cannot be deleted; the attempt is logged.
Locked time entries
Reserved or billed time entries can be neither changed nor deleted.
Finalized invoices
After finalization only the status can change; deleting is allowed for drafts only.
No email sending
Email drafts cannot be sent via MCP. Cold outbound leads need a documented legal basis (TKG § 174); recipients on the suppression list are rejected.

Common pitfalls

  • Scope and role are independent

    An admin with a read-only connection cannot write, and a viewer with full access cannot delete. Both conditions must be met.

  • delete_invoice is special

    It requires only the Member role but a connection with the delete scope. It deletes drafts only.

  • Tool missing despite the right role

    Check whether the module is enabled in the organization and assigned to you (via role or member assignment).

Keep reading

Still have a question or a problem?

Visit support

Last reviewed on 2026-09-26