Bounding the agent by the permissions of whoever connected it is a sensible default. Can it get less than that, say one board in read-only, so a teammate can let Claude groom the backlog without it touching the roadmap?
Hello Anton. Thank you for your review!
Setting more granular permissions for mcp clients is not possible yet, but we have it in our backlog. We will need to design it carefully though, to not overcomplicate it. Our main goal is to build a powerful tool, that does not require complex configuration to be used.
Because of that we have decided to launch with mcp clients having the same permissions as the account to which they belong. We were already using it internally for several months and we have observed no issues with Claude doing anything it was not supposed to do. Additionally to that in the activity log on cards and epics it can be easily checked whether an action was performed through user interface or mcp. So in such case, there is an audit trail.