This article is for workspace admins. It explains how to turn on Playable MCP for your team and choose what each role is allowed to do with it. Once you've done this, your colleagues can connect their AI tool.
Step 1: Get Playable MCP enabled for your workspace
Playable MCP is currently available on all Enterprise plans.
You can tell it's enabled when:
the OAuth sessions item appears in the menu under your user avatar, and
an MCP tools tab appears when you edit a role's permissions (see step 2).
Step 2: Review what each role can do
When Playable MCP is enabled, your roles already have access to all MCP tools, and new roles you create get it too. Review this to decide who should use it, and how:
Click your user avatar (top right) and open Account Overview.
Go to Roles and click Modify on the role you want to check.
In the Permissions section, open the MCP tools tab.
All (under All tools) allows every action. To limit a role, untick All and pick individual actions instead. They're grouped as Campaigns, Campaign pages, Campaign add-ons, Campaign form fields, Campaign design and Media library. To keep a role from using Playable MCP at all, untick everything.
Save the role.
Users who have individual permissions instead of a role don't get MCP access automatically. For them, tick the actions on the MCP tools tab of their user permissions.
How MCP permissions combine with other permissions
MCP tool permissions work on top of a role's normal Playable permissions. They can only narrow down what someone can do. They never add to it.
For example:
To edit pages through the assistant, a user needs both the MCP permission for that action and permission to edit the campaign layout in Playable.
To read statistics, a user needs the MCP permission and access to the campaign's statistics.
If a user is restricted to certain campaigns, the assistant is restricted to the same campaigns.
Actions a user isn't allowed to use are hidden from their AI assistant completely. It can't see them and can't call them.
Suggested setups
Who | What to tick | What they can do |
Analysts and stakeholders | Under Campaigns: List campaigns, List campaign types, Get campaign statistics | Find campaigns and ask questions about results. They can't change anything. |
Campaign builders | All | Everything Playable MCP offers, on draft campaigns they're allowed to edit |
Careful start | Everything except the Delete actions (Delete campaign page, Delete campaign page row, Delete campaign addon, Delete form field) | Build and edit, but not remove anything. Deletions are then done in the editor. |
Step 3: Check your AI tool's admin settings
If your company uses a business plan of an AI tool, its administrator may need to allow Playable first:
Claude Team and Enterprise: an owner adds Playable as a custom connector under Organization settings → Connectors. Members can then connect to it.
ChatGPT Business and Enterprise: an admin must allow developer mode and custom MCP connectors under Workspace settings → Permissions & roles.
The exact steps are in Connect your AI tool to Playable.
See who's connected
In Account Overview → Users, the MCP column shows each user's status. Hover over the icon to see what it means:
Active MCP connection: the user has an AI tool connected right now.
Has connected to MCP before, but has no active session: the user connected in the past, but the connection has ended or been revoked.
Remove someone's access
Change or remove their MCP tool permissions. This takes effect on the assistant's next request. The AI tool stays connected, but it can no longer use the actions you removed.
Deactivate the user when they leave your company. Their AI tool connections stop working.
Each user can disconnect their own AI tools under OAuth sessions. Admins can't currently disconnect another user's AI tool directly; use the permission options above instead.
For more on security, logging and data access, see Playable MCP security, access and control.
