Who can install apps?
Workspace roles control who can add or remove integrations.
Updated 2026-08-13
Owners and admins enable MCP apps for the workspace and can disable them. Editors connect their own accounts, and anyone with access to a channel can add a Direct (channel) app to that channel.
What each role can do
- Owner / admin — Enable an MCP app from the catalogue, change workspace settings (display name, read-only, tool allowlist), view activity, and disable the app for everyone.
- Editor — After an app is enabled, tap Connect account, use @mentions, and Revoke my connection. Editors see Ask an admin instead of Enable.
- Channel access — Direct integrations bind to a channel you can already open. If you cannot open the channel, you cannot add the app there.
Check your role
- Open Settings and see whether Team Permissions and Organisation access appear — those links are shown to admins and owners.
- If Enable is missing on an MCP app, ask an owner or admin. See What are the workspace roles?.
- Secret vaults for custom agents are also admin/owner only (Settings → Agent Secrets).
Tips
- Enable is not the same as Connect. Admins turn the app on; each person still signs in with the vendor.
- Inbound MCP (Cursor, Claude, ChatGPT) uses your own consent grant — you do not need to be an admin to approve access for yourself.
- To take an app away from the team, an admin disables it.
Related
- What are the workspace roles?
- How do I install a channel app?
- How do I set up an MCP app?
- Apps & Integrations
Still stuck?
Contact us or browse all help topics.