MCP access control
MCP (Model Context Protocol) lets AI assistants connect to Kissflow and act on behalf of your users. An assistant connects for a person and acts within that person's permissions. To open MCP access control, click your profile picture > Account governance > MCP access control.

Note:
Only a Super Admin or an IAM Admin can open and change these settings.
Turning account-wide MCP access on and off
The Account-wide MCP access switch controls whether assistants can reach your account.
Turning it off stops every connected assistant immediately, for everyone in the account. Your flow and people selections are kept, so turning it back on restores them.
Caution:
Turning this off does not disconnect anything under My settings > Security settings > Assistants and apps. Existing connections remain listed, and they start working again as soon as you turn access back on.
Choosing which flows assistants can work in
Flows are processes and boards, in or outside apps. Select one of three options:
| Option | What it means |
| All flows | Every process and board. |
| Selected flows | Only the ones you select. |
| All except selected | Everything except the ones you select. |
Selected flows and All except selected each open a search field where you select the flows.
Note:
Under Selected flows, a flow created later is not included until you add it. Under All except selected, a flow created later is available to assistants unless you exclude it.
Choosing who assistants can work for
Select one of two options:
| Option | What it means |
| Everyone | Every user, including super admins. |
| Selected people or groups | Only the people and groups you select. |
Everyone includes super admins and IAM admins. An assistant working for an admin acts with that admin's permissions. To keep admins out, use Selected people or groups and leave them unselected.
You can select users and groups only. Portal users cannot be selected, so under Selected people or groups an assistant can never work for one.
Under Everyone and All except selected, an assistant can work for a portal user. Portal users have no page on which to see or end a connection, so only the person who set it up can disconnect it, from the assistant. Use Selected people or groups if you need every connection to be one a user can end themselves.
Seeing what an assistant did
In the audit log, an assistant's actions are recorded under the person it worked for: the assistant appears under Acted by, below the person's name. To see only what was done through an assistant, add the Acted through filter.
Note:
These records name any connected application, not only AI assistants. An assistant is one kind.
What this page does not cover
This page controls the MCP connection only. Anyone who can create an access key under My settings > API authentication can still reach Kissflow through the API with their own access.
Learn more about connecting AI assistants.
