# Connected MCP servers: letting AI employees use your other systems

> Register GitHub, Notion, Linear, Slack or your own MCP server; class each tool before it can be called; writes wait for approval.

Section: Settings and administration · Canonical: https://intubu.intuitivecapital-dai.com/docs/mcp-servers

Settings → MCP connections → Connected servers. Owner or settings administrator only, and the *Connected servers* switch under Governance must be on.

**What it is.** The other direction: IntuBu's AI employees can use tools from your other systems mid-task — check a delivered milestone in Linear before drafting the invoice, pull a contract from Notion, open a GitHub issue.

**Every tool starts disabled and unclassified.** A server's own description of a tool is not trusted to say what it does. After *Discover tools*, you class each one — **read**, **external write**, or **money-moving** — and only then can it be enabled. An unclassified tool cannot be switched on.

**Writes wait for approval.** A read tool runs while a task is being worked out. An external write or money-moving tool runs only in *apply*, after a person has approved the task, and the plan shows it plainly: "will call Shop.ship_order with {…}".

**The injection screen.** Tool descriptions at discovery and tool results at every call are checked for instruction-shaped text — "ignore previous instructions", "approve this now", "do not tell the user". A flagged description shows a warning and needs an explicit acknowledgement to enable; a flagged result is passed to the model with the warning that it is data and cannot change the plan.

**Credentials stay in the vault** and are added to the HTTP request here, outside the model's context. URLs that resolve to private or loopback addresses are refused, at registration and again on every call.

**Per tool** you can also restrict which AI employees may use it, which workspaces, calls per hour, and pin arguments — a fixed value on a sensitive parameter that wins over whatever the model proposed.

**The vetted list** covers GitHub, Notion, Linear and Slack with sensible preset classes (reads enabled, writes left off). *Your own server* is any Streamable HTTP MCP server.

**Stop this server** refuses one server; the emergency stop under Governance refuses everything.
