MCP permissions and scopes
Use scoped permissions so each AI client can access only the workflows it needs.
Prism MCP should be treated as a sensitive data access surface because it connects external AI tools to the user's authorized Libraries.
Workflow
Primary steps
- 1Start with canonical read-only knowledge access.
- 2Add write scopes only for trusted workflows and only when the deployment exposes them.
- 3Revoke or edit clients from the Prism MCP dashboard.
Default posture
Start with canonical knowledge:read for Library search, source retrieval, artifacts, profiles, and recent activity. research:read remains an accepted legacy alias and grants no extra access. Privacy-sensitive memory:read is excluded from defaults and must be explicitly selected or re-consented.
Write scopes are hidden unless the server-side PRISM_MCP_WRITE_TOOLS_ENABLED flag is enabled and the user explicitly authorizes the scope.
For new or re-consented connections, a selected folder grant includes that folder's current and future descendants. Existing connections keep legacy exact-folder grants until they are edited or re-consented.
Publishing boundary
MCP write tools can support private draft, library, graph, portfolio, thesis proposal, and explicit workspace-memory workflows when enabled. memory:write can remember, correct, or forget a specific authorized workspace memory; forgetting purges memory content and derived data while retaining a non-content audit marker and never deleting canonical sources. It cannot silently infer durable preferences. MCP cannot publish, schedule, delete, send subscriber emails, or place trades.