All documentation

Documentation Settings: Account

Governance: tools and connections

Every line in the Tools & connections card: MCP servers, private hosts, registries, hooks, tool families, apps, origins and environment variables.

Tools & connections

The third card of part 2. It decides which MCP servers, hooks, tool families, apps and web origins the room may use. Whatever you allow here, every MCP server's tools are pinned when someone first approves it, so a server cannot quietly change what a tool does afterwards.

Where to find it. Mac: Settings → Account → Governance → 2 · Tools & Execution. Web: Settings → Governance (part 2). iPhone: Settings → Governance → Rules → 2 of 3. Owner or admin edits.

The policies, top to bottom

PolicyDefaultWhat it doesWhen to turn it on
MCP servers members may runanyPatterns, one per line, matched against a URL server's host, a command server's whole command, or "pkg:" and a package name. Never against the name a member gave a server.When only reviewed servers should run.
Private hosts members' Macs may reachnoneExact hostnames or IPv4 addresses on your own network. A Mac otherwise refuses an MCP server, an external agent or a sandboxed connection on a private address. Cloud metadata addresses stay refused.When your MCP servers live inside the company network.
Or a registry file the team servesnoneAn https address of a file in the MCP registry format. Its servers become the allowlist, fetched at start and daily; a server no longer listed is stopped.When you already keep an MCP registry.
A skills registry the team servesnoneAn https address of a JSON list of skills with a sha256 of each. Members install them with a click under Skills; an entry whose hash does not match is never installed.When the team shares vetted skills.
Members may add hooks of their ownonOff, only the team's hooks run on members' Macs.When hooks must be reviewed like code.
Hooks every member's Mac runsnoneOne per line: the event, an optional match on tool names, optionally "closed", then a command or "prompt:" and a sentence. A closed hook that cannot run refuses the action. Events: beforeTool, afterTool, afterWrite, sessionStart, sessionEnd, beforeAsk, beforeApproval, beforeStop.When a secret scanner should run before every tool.
Tool familieseach onOne select each for Browser, Computer use, Image generation, Publishing, Phone files and Delegation: on, ask or off. Off is not offered to any seat; ask makes every use ask the person.When a family is out of scope for your team.
Apps the computer-use tools may driveanyApp names or bundle ids, one per line.When computer use should stay inside Xcode and a browser.
Origins the browser tools may act onanyOrigins, one per line.When the browser should only touch staging.
Environment variables unset for commandstoken-shaped namesExtra variable names removed from every command's environment. Names that look like tokens are always removed in the sandbox.When a database address sits in everyone's shell.
Settings → Account → Governance → Tools & Execution on the Mac: the Tools & connections card with the tool family selects
Settings → Account → Governance → Tools & Execution on the Mac: the Tools & connections card with the tool family selects

When not to use it. An empty allowlist allows any server. A list with one wrong pattern stops every member's MCP server at once, so test the pattern against one Mac before you save.

Further reading. Model Context Protocol specification, MCP project. OWASP LLM01 Prompt Injection, OWASP GenAI Security Project.

See also

Not what you were looking for? The help centre answers one question at a time, and the support page says how to reach a person.