Who can install apps?

Workspace roles control who can add or remove integrations.

Updated 2026-08-13

Owners and admins enable MCP apps for the workspace and can disable them. Editors connect their own accounts, and anyone with access to a channel can add a Direct (channel) app to that channel.

What each role can do

  1. Owner / admin — Enable an MCP app from the catalog, change workspace settings (display name, read-only, tool allowlist), view activity, and disable the app for everyone.
  2. Editor — After an app is enabled, tap Connect account, use @mentions, and Revoke my connection. Editors see Ask an admin instead of Enable.
  3. Channel access — Direct integrations bind to a channel you can already open. If you cannot open the channel, you cannot add the app there.

Check your role

  1. Open Settings and see whether Team Permissions and Organization access appear — those links are shown to admins and owners.
  2. If Enable is missing on an MCP app, ask an owner or admin. See What are the workspace roles?.
  3. Secret vaults for custom agents are also admin/owner only (Settings → Agent Secrets).

Tips

  • Enable is not the same as Connect. Admins turn the app on; each person still signs in with the vendor.
  • Inbound MCP (Cursor, Claude, ChatGPT) uses your own consent grant — you do not need to be an admin to approve access for yourself.
  • To take an app away from the team, an admin disables it.

Still stuck?

Contact us or browse all help topics.

Still need help? Contact us