Connected MCP servers: letting AI employees use your other systems
Register GitHub, Notion, Linear, Slack or your own MCP server; class each tool before it can be called; writes wait for approval.
Settings → MCP connections → Connected servers. Owner or settings administrator only, and the Connected servers switch under Governance must be on.
What it is. The other direction: IntuBu's AI employees can use tools from your other systems mid-task — check a delivered milestone in Linear before drafting the invoice, pull a contract from Notion, open a GitHub issue.
Every tool starts disabled and unclassified. A server's own description of a tool is not trusted to say what it does. After Discover tools, you class each one — read, external write, or money-moving — and only then can it be enabled. An unclassified tool cannot be switched on.
Writes wait for approval. A read tool runs while a task is being worked out. An external write or money-moving tool runs only in apply, after a person has approved the task, and the plan shows it plainly: "will call Shop.ship_order with {…}".
The injection screen. Tool descriptions at discovery and tool results at every call are checked for instruction-shaped text — "ignore previous instructions", "approve this now", "do not tell the user". A flagged description shows a warning and needs an explicit acknowledgement to enable; a flagged result is passed to the model with the warning that it is data and cannot change the plan.
Credentials stay in the vault and are added to the HTTP request here, outside the model's context. URLs that resolve to private or loopback addresses are refused, at registration and again on every call.
Per tool you can also restrict which AI employees may use it, which workspaces, calls per hour, and pin arguments — a fixed value on a sensitive parameter that wins over whatever the model proposed.
The vetted list covers GitHub, Notion, Linear and Slack with sensible preset classes (reads enabled, writes left off). Your own server is any Streamable HTTP MCP server.
Stop this server refuses one server; the emergency stop under Governance refuses everything.