2 months free on every plan
Back
GuidesDiscoveryAI assistant

MCP: what your AI assistant can see

Équipe Flots4 min read

Plugging an AI into your own organization raises one question before all the others: what exactly does it see, and what can it do without asking me?

Here is the detailed answer, screen by screen, for an assistant connected to Flots through MCP.

The assistant works under your identity, never anyone else's

This is the foundation, and it does not depend on any setting of yours.

When you authorize a connection, Flots issues a token that designates you. Every request that arrives afterwards runs within the scope of that account. The assistant cannot tell the server which user it is working for: it is never asked the question.

Even with the broadest permissions, an assistant connected to your account only reaches what you reach yourself when you log in to Flots.

Permissions are chosen when you connect

At the moment you authorize, you grant permissions by type of action. The token is issued with exactly those, never with blanket access.

PermissionWhat it opens up
ReadConsult tasks, projects, milestones, document tree
WriteCreate and modify tasks, projects, notes, milestones
DeletePermanently remove items

The list of actions presented to the assistant is filtered according to what you granted. A read-only assistant cannot even see that a delete action exists. So it cannot attempt one, nor explain to you that it would rather like to.

That is fundamentally different from an instruction written in a prompt. An instruction can be worked around; a door closed on the server side cannot.

Some actions never go through silently

Ordinary writing happens directly: you ask for five tasks, the five tasks appear. Two families of actions escape that rule.

Irreversible actions first. Deleting a task, a note or a project is not carried out just because the assistant asks.

Then come the ones that land on someone else: assigning a task to a colleague steps outside your own scope and commits another person.

In both cases, the assistant has to show you the exact change, as it will be applied, and obtain your explicit agreement before going further. An agreement given covers that one change, not the ones after it.

The key point

An agreement only covers the action shown

Every deletion, every write on a colleague's side comes back to you. There is no blanket authorization.

Your note content is closed from the start

This is the most restrictive setting in Flots, and it is deliberately kept apart from the connection flow. It lives in Settings, under Note content reading.

  • Never, the starting level. The assistant creates and modifies notes, but never reads their text. It sees their titles.
  • Personal notes only. It reads the content of notes that you alone wrote.
  • All notes. It reads everything you can read, including notes shared in a project and written by others.

This caution concerns the whole industry, not just Flots. An assistant that reads a text can be swayed by instructions slipped into that text. A note written by someone else is therefore an attack surface, however discreet.

Flots flags that risk and limits it. We do not claim to have removed it, and that is precisely why the third level is not on by default: opening it up should stay a conscious decision, made with full knowledge of the facts.

You stay in control, at all times

The Connected applications (MCP) screen lists every authorized application, along with the date it was last used. An application that has never been used says so, and sorting things out takes a few seconds.

One button revokes access immediately. The application concerned can no longer reach anything, with no delay and no grace period.

That same screen hosts the full documentation of the available actions. It is generated from the server, so it describes what is actually deployed. For each action, it states whether it reads, writes or deletes, and whether it is irreversible.

What remains up to you

No technical safeguard replaces two or three simple habits.

Start in read-only mode, long enough to see what you actually ask for. Read back what you are shown before confirming a deletion, especially a batch one. Go through your connected applications from time to time, the way you would with passwords.

To understand the protocol itself and where it came from, see what MCP is. For the step-by-step instructions, connecting an AI assistant to Flots. And if the question of hosting and the legal framework interests you, it is covered in digital sovereignty and productivity tools.

Open up what you want, keep the rest closed.

The three note content reading levels in the Flots MCP settings
FAQ

Frequently asked questions

Still missing an answer?

Tell us about your setup and what is blocking you. We answer within 24 hours.