Level 1: role in the organization
Every tool requires a minimum role. The order is Viewer < Member < Admin < Owner; owners meet every requirement. Distribution: 51 tools from Viewer, 43 from Member, 20 from Admin.
- Viewer
- May read and list, and use the read-only AI tools (similarity search, sprint suggestion, effort estimate, analytics).
- Member
- Additionally may create and change, and read some finance-related reports: budget forecast, expenses, accounting receipts and income. May delete draft invoices with the delete scope.
- Admin and Owner
- Additionally may use all delete tools, create, change, activate and delete budgets, delete expenses and set member rates. They also see monetary amounts in the budget reports.
Level 2: access level (scope) of the connection
A connection carries one of three cumulative levels. There are 55 tools with scope read, 42 with write and 17 with delete.
- read (Read only)
- Read and list.
- write (Read and write)
- Additionally allows all tools with scope write: create and update.
- delete (Full access)
- Additionally allows all delete tools. A higher level includes the lower ones.
Level 3: enabled modules
Most tools belong to a module and are available only if the module is enabled in the organization and assigned to you (organization-wide module choice, custom roles and per-member module assignments are respected). 20 tools have no module switch: list_organizations, get_organization, list_members, get_analytics, list_milestones, get_milestone, create_milestone, update_milestone, delete_milestone, list_network_contacts, get_network_contact, search_network_contacts, create_network_contact, update_network_contact, delete_network_contact, list_reviews, get_review, create_review, update_review, delete_review.
- Calendar
- 3 tools: list_calendar_events, create_calendar_event, find_team_free_slots
- Tasks
- 7 tools: list_tasks, get_task, create_task, update_task, delete_task, find_similar_tasks, estimate_task_effort
- Projects
- 5 tools: list_projects, get_project, create_project, update_project, delete_project
- Sprints
- 8 tools: list_sprints, get_sprint, create_sprint, update_sprint, delete_sprint, add_task_to_sprint, remove_task_from_sprint, suggest_sprint_plan
- Files
- 2 tools: list_files, list_file_folders
- Notes
- 5 tools: list_notes, get_note, create_note, update_note, delete_note
- Time tracking
- 6 tools: list_time_entries, get_running_timer, create_time_entry, stop_timer, update_time_entry, delete_time_entry
- Metrics
- 5 tools: list_metrics, get_metric, create_metric, update_metric, delete_metric
- Goals
- 5 tools: list_goals, get_goal, create_goal, update_goal, delete_goal
- Meetings
- 6 tools: list_meetings, get_meeting, create_meeting, update_meeting, delete_meeting, list_meeting_folders
- Knowledgebase
- 6 tools: list_kb_items, get_kb_item, search_kb, create_kb_item, update_kb_item, delete_kb_item
- CRM
- 11 tools: list_crm_leads, get_crm_lead, create_crm_lead, update_crm_lead, delete_crm_lead, create_crm_activity, get_crm_dashboard, get_crm_weekly_briefing, list_crm_email_drafts, create_crm_email_draft, update_crm_email_draft
- Budgeting
- 13 tools: list_budget_overview, get_project_budget, list_retainers, get_budget_forecast, list_expenses, list_member_rates, create_budget, update_budget, activate_budget, create_expense, set_member_rate, delete_budget, delete_expense
- Invoices
- 6 tools: list_invoices, get_invoice, create_invoice, update_invoice, delete_invoice, create_invoice_correction
- Accounting
- 4 tools: list_accounting_receipts, update_accounting_receipt, delete_accounting_receipt, list_accounting_income
- Planning
- 2 tools: get_planning_week, list_unscheduled_tasks
How missing permissions show up
For organization-bound connections the server filters the tool list: what you may not use does not appear. For account-wide connections without an organization header all tools are visible at first because the organization is only known at call time; there the server checks on call and answers missing permissions with "Insufficient permissions for this tool". The same applies to tools of a disabled module.
Data visibility for members
There is no restriction for owners and admins. For other roles some tools apply additional visibility rules that also hold in the web app.
- Invoices and accounting
- list_invoices, get_invoice, create_invoice, update_invoice, delete_invoice, create_invoice_correction, list_accounting_receipts, update_accounting_receipt, delete_accounting_receipt and list_accounting_income respect role-based project visibility. Items without a project stay visible.
- CRM drafts
- list_crm_email_drafts, create_crm_email_draft and update_crm_email_draft respect lead ownership: your own leads, leads of people reporting to you and unassigned leads.
- AI tools for tasks
- find_similar_tasks, estimate_task_effort and suggest_sprint_plan respect your task visibility (own tasks, tasks of people reporting to you, project grants of the role).
Monetary amounts for admins only
In the budget reports (list_budget_overview, get_project_budget, list_retainers, get_budget_forecast, list_member_rates) the server returns amounts, cost rates and revenue forecasts only to owners and admins. Other roles receive null but still see hours and percentages.
Traceability and safeguards
Sensitive actions follow additional rules regardless of role.
- Audit log
- Invoices (create, finalize, status change, correction) and receipt deletion are recorded with actor type "mcp".
- Legal hold
- A receipt with a document under legal hold cannot be deleted; the attempt is logged.
- Locked time entries
- Reserved or billed time entries can be neither changed nor deleted.
- Finalized invoices
- After finalization only the status can change; deleting is allowed for drafts only.
- No email sending
- Email drafts cannot be sent via MCP. Cold outbound leads need a documented legal basis (TKG § 174); recipients on the suppression list are rejected.
Common pitfalls
Scope and role are independent
An admin with a read-only connection cannot write, and a viewer with full access cannot delete. Both conditions must be met.
delete_invoice is special
It requires only the Member role but a connection with the delete scope. It deletes drafts only.
Tool missing despite the right role
Check whether the module is enabled in the organization and assigned to you (via role or member assignment).
