pAInpoint.solutions
Documentation

08 of 13

Agent Access (MCP)

Agent Access lets you point an AI agent at your own AI Chat data. That agent can be Claude Desktop or any other MCP-compatible client. The agent can read and report on your knowledge base, conversation history, escalations, analytics, and settings. If you allow it, the agent can also help manage your agent by proposing changes you approve in chat. So you can ask things like "summarize this week's conversations" or "set my escalation contact to … " in plain language.

Access comes in three levels, and you choose. Read-only lets an agent look and report but change nothing. Read and manage lets it propose a change that you approve in chat before anything happens. And some things have no tool at all, listed below: an agent can never spend money, change your plan, delete your account, or change who has access.

It's free on every plan, and everything the agent sees is scoped to your own sites, so it can never reach another customer's data.

Read-only vs. read & manage

When you create a token you choose its access level:

  • Read-only (the default). The agent can read and report on your data, but can't change anything.
  • Read & manage. The agent can also propose changes: tune settings (tone, greeting, appearance, escalation contact), resolve escalations, add or edit pinned facts, refresh your knowledge by re-reading your site, and adjust which pages are skipped.

With a read & manage token, your agent can:

  • List your sites; search/list knowledge; read, list, and search conversations; view analytics; list escalations; read settings (read-only too)
  • Propose a settings change, an escalation resolution, or a pinned-fact add/edit
  • Propose a re-read (refresh knowledge from your live site) or a change to your excluded pages. These cost money or change what gets read, so they come with a clear cost/impact note, and re-reads stay within your monthly limit no matter how they're triggered

Changes never apply on their own

Every change is propose-then-confirm: the agent shows you exactly what it wants to change and gives you a confirmation step. Nothing is written until you confirm it in the chat. So even a "read & manage" agent can't quietly change your setup. You see and approve each change.

Deleting knowledge needs your approval in the dashboard. Because deleting a knowledge source is destructive, an agent can only request it. It can't delete anything itself, even from chat. When it requests a deletion you get a link to a one-click Approve button on the site's Knowledge page; the deletion happens only after you click it, signed in as the account owner.

And some things are never available to an agent, on any token: it can't spend money, buy or remove add-ons, delete your account, or change who has access. Those stay in the dashboard, done by a human.

How your agent's changes get approved

There are three levels, so nothing surprises you:

  • Applies immediately. Reading and reporting on your data. And, with a read & manage token, the green writes above once you confirm them in the chat (settings, escalation resolutions, pinned-fact edits).
  • Needs your approval in the dashboard. Deleting a knowledge source. The agent can only send you a one-click Approve link; the deletion happens after you click it, signed in as the owner.
  • The agent simply can't do it. There's no tool at all for re-reading (beyond the propose-then-confirm refresh), billing and add-ons, deleting your account, or changing access and credentials. For those, you use the dashboard yourself.

Pinned facts, not your whole knowledge base. "Add/edit pinned facts" manages the short, always-included facts your agent keeps top-of-mind (max 10 per site), not the pages read from your website. The agent can't rewrite the knowledge base built from your site.

Set it up

You connect with a token, a secret key the agent uses to authenticate as you.

  1. Go to Agent access (MCP) (in the sidebar, or from the Connect an AI agent card on your AI Chat overview).
  2. Click Create token, give it a name (e.g. Claude Desktop), choose all sites or specific sites, and pick the access level (read-only, or read & manage).
  3. When the token is created, you'll see a ready-to-paste connection config with the token already in place. Pick the tab for your client (Claude, OpenAI, or any other), and copy it right then. For your security the token is shown only once and can't be retrieved again; if you lose it, revoke it and create a new one.
  4. Paste the config into your MCP client and restart it. The token always rides an Authorization: Bearer header, never the URL.

That's it. Your agent can now work with your AI Chat data.

Which clients work today

Pasting a token in an Authorization header works in Claude Desktop and Claude Code right now (they let you configure the header). Claude on the web connects through its connector UI, which currently supports OAuth only and gives you no field to paste a token, so one-click web connect will arrive alongside our OAuth support. Until then, use Claude Desktop or Claude Code.

Tokens, scope, and security

  • Account owner only. Only the account owner can create or revoke tokens.
  • Per-site scope. A token can be limited to one site (or a set of sites), so you can hand an agent access to just one client without exposing the rest.
  • Access level you choose. Default read-only; "read & manage" is an explicit opt-in, and even then every change is confirmed by you in chat.
  • Revoke anytime. Revoking a token on the Agent access (MCP) page cuts off any agent or tool using it immediately.
  • Stored securely. We never store your token in a readable form, only a one-way hash, which is why we can show it just once.

A note on conversation search

When you ask your agent to find conversations about a topic, its search is keyword-based, not conceptual. The agent knows to try related words on your behalf (for "pricing" it will also look for "cost", "expensive", and so on), so just describe what you're after in plain language and let it do the expanding.