MCP access levels control how much an AI agent can do in Fullcast when a user connects it through the model context protocol (MCP). Each user has their own level, and it works as a ceiling: it can limit what the agent does, but it never gives the agent more access than the user already has in Fullcast.
An AI agent works much faster than a person and can be misled by instructions hidden in the data it reads. The access level lets you keep someone's full access in the app while giving their agent a tighter limit.
Access levels
Level | What the agent can do | Good fit for |
|---|---|---|
Read-only tools | Look up, report on, and analyze data. It cannot change anything. | New MCP users, executives, analysts, and anyone who only needs answers |
Standard writes (default) | Everything in Read-only, plus focused changes such as moving accounts between territories or creating a coverage assignment. | Most users |
Include heavy operations | Everything in Standard writes, plus high-impact changes: committing proposed changes, rerunning territory rules, editing targets, changing a person's role, and committing commission ledger entries. Some of these cannot be undone. | Experienced admins running planning or commission cycles through an agent |
Full (role-based, no cap) | Every tool the user's Fullcast permissions allow, with no MCP limit. For administrators, this includes admin tools. | Administrators who want the agent to match their in-app access |
How the level combines with permissions:
The agent gets whichever is lower: the MCP access level or the user's Fullcast permissions. A user with read-only permissions stays read-only at every level.
The level applies to everyone, including Tenant Admins and Sys Admins.
The level applies to every AI client the user connects.
Change a user's MCP access level
Before you begin
You need Tenant Admin or Sys Admin permissions.
Go to Settings > Users > User Management.
Find the user you want to update.
Click the menu ⋮ and select Edit.
From the MCP Access (AI agent) dropdown, select a level.
Click Save.
Note
Recommended: Start new MCP users on Read-only tools. Raise the level once they've seen how their agent handles your data.
When an agent asks for more than its level allows
If you ask an agent to do something above your level, the agent tells you the action isn't available at your current MCP access level. It does not look for a workaround. To raise your level, ask a Fullcast administrator.