Org-level MCP access control setting (allowlist by user or role).
Currently anyone in the company with shopify access from customer support to marketing, can connect claude desktop via the shopify app which is ‘available’ company wide in claude. I have no control over that as data controller/COO which is a lax security set up. I need explicit MCP/API permissioning for roles, not the hack of changing access to what is edit/read as this could affect their current role and workflow if go change 20 peoples permissions or restrict access.
I think this is a valid concern, especially for organizations where different teams have very different access requirements. As AI connectors become more capable, role-based access and granular permission controls become increasingly important. Ideally, administrators should be able to decide which users or groups can connect external AI tools and what data those tools are allowed to access, instead of relying only on broader Shopify permission settings.
A good balance would be workspace-level approval, scoped permissions, audit logs, and the ability to disable specific connectors for selected roles. That gives companies the flexibility to adopt AI while still meeting their security and governance requirements. As more businesses start using AI connectors in production, I think these kinds of controls will become essential rather than optional.