Skip to main content

Server access

Choose which AI agents, smart groups and people can use one MCP server. Everyone else is denied access before any tool is listed or called.

Configure it on the server​

Go toQuilrAI consoleSettingsAI GatewayMCP Gatewayserver cardConfigureGeneral

Scroll to the Access control card.

SettingWhat it does
Allowed agentsAI clients that may connect to this server, matched by their User-Agent keyword. Built-in agents and any custom agent from Allowed Agents are listed.
Allowed smart groupsWhen set, only members of these smart groups may use the server. Leave empty to allow every group.
Denied smart groupsMembers of these smart groups are denied access, unless they are listed in Allowed users.
Allowed usersEmail addresses that are allowed access even if one of their smart groups is denied. This list does not restrict anyone by itself.
Denied usersEmail addresses that are always denied access.

Adding a group or person to one side removes it from the opposite list. Click Save settings in the footer to apply your changes.

To manage agents across every server at once, use the Allowed Agents button in the MCP Gateway header. It edits the same agent list. See Allowed Agents.

Precedence​

The card reads: "Denied users take precedence. An explicitly allowed user can override a denied smart group; user rules are matched case-insensitively."

The gateway checks each person in this order and stops at the first match:

OrderIf the person is...Result
1In Denied usersDenied
2In Allowed usersAllowed
3In a Denied smart groupDenied
4Not in any Allowed smart group (when that list is set)Denied
5Anyone elseAllowed

Emails match regardless of case, so Jane@Example.com and jane@example.com match the same email address.

Allowed agents is checked separately. A request from a client whose User-Agent matches no allowed agent is denied regardless of the user.

The User-Agent identifies a client but does not authenticate it, so treat Allowed agents as steering, and rely on the user and group lists for access decisions. See Allowed Agents.

Gateway traffic only

These rules apply to calls that go through the MCP Gateway. They do not stop someone from connecting to an MCP server directly from their own client. To find and close those paths, see An MCP server outside the gateway.

Example​

SettingValue
Denied smart groupsContractors
Allowed userslead@example.com
Denied usersformer.admin@example.com
  • A contractor is denied access.
  • lead@example.com is allowed even though they are in Contractors.
  • former.admin@example.com is denied access even if they are in an allowed group.

How it relates to other settings​

FeatureScopeUse it to
Access control (this page)One serverDecide who and which agents may use this server at all.
Allowed AgentsEvery server, per agentSee and change which servers each agent gets.
Group and user rulesOne server, per group or userConfigure what authorized users can access: tools, guardrails, token saving and confirmation.

Going further with the Policy Engine​

The same decision lives on the MCP Server Access card (stage 1, Session) in Govern > Policy Engine > MCP Gateway. Its effect is MCP access: allow or deny. Because it runs at session, a denied caller never sees the server's tools. Deny wins over allow, and a server that is not registered is denied by default. Edits join a shared draft and apply once you publish a revision.

A rule can match on far more than the Access control card offers:

  • Block servers by name for everyone. Match MCP name against a list, for example unapproved or legacy servers, and deny access across the tenant in one rule.
  • Gate by identity source or network. Match the caller's identity provider or client IP, so a server is only reachable from accounts signed in through your corporate IdP or from known networks.
  • Gate by agent or route. Match agent name, agent classification or route kind (direct, onemcp, workflow), for example allow a server through OneMCP but not as a direct connection.
  • Gate by server attributes. Match MCP tags, transport or auth type instead of naming each server.
block_unapproved_serverssession

runs on sessionpriority 900

WhenMCP nameis any ofUnapproved NotesLegacy CRM
Then
MCP accessdeny

The OneMCP Features card sits in the same Session stage. It turns OneMCP dynamic tools and memory on or off per caller. See OneMCP.