Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Approve your team's MCP servers

Make Stackyapper an organization-approved MCP connection, then restrict other MCP servers in your AI provider's admin settings. Use organization-approved to include vendor-hosted servers your organization has reviewed and enabled.
There are two separate controls:
  • Your AI provider controls which servers members can connect to.
  • Stackyapper controls which AI clients can connect to your workspace and which apps and tools each person can use through Stackyapper.
Stackyapper cannot block or audit a connection made directly to another MCP server. Configuring approved clients here does not change your AI provider's settings.

Provider controls

Checked against official documentation on September 13, 2026. These are documented capabilities, not tests performed in your organization's accounts. Plan, client version, and administrator permissions affect availability.

Claude Team and Enterprise

Only Owners and Primary Owners can add custom remote connectors for the organization. Add Stackyapper under Organization settings → Connectors; members then connect their own accounts. Review other enabled connectors. Claude remote connector setup.
Desktop needs a separate check. Team and Enterprise owners can enable a desktop extension allowlist, which is off by default. Enabling it removes existing extensions, so plan the rollout. It does not protect against users modifying local MCP files. Desktop extension allowlist.
For managed devices, review isLocalDevMcpEnabled and isDesktopExtensionEnabled in the Team/Enterprise system policies. Claude Code requires its own managed configuration review; do not treat the web connector list as a control over every Claude client. Claude Desktop device policies.

ChatGPT Business, Enterprise, and Edu

On Business, only admins/owners can use developer mode and deploy custom apps. Publish the approved Stackyapper app for members. Enterprise/Edu also let admins grant developer-mode access through roles; restrict that permission to trusted builders, since it permits private testing of unpublished apps. Only admins and owners publish workspace apps. OpenAI custom app controls.
Review enabled directory apps as well as custom apps. Approval of a custom app is not an organization-wide restriction on every way ChatGPT can access data.

Hatz

Under Integrations & Tools, turn off Allow MCP creation to prevent new personal registrations. Audit the MCP Inventory and disable unapproved existing servers; blocking creation alone leaves existing servers usable. Keep Allow MCP use enabled if Stackyapper is connected as a custom MCP server, because disabling it blocks all custom servers, including Stackyapper. Plan onboarding before freezing creation: new members may otherwise be unable to add their Stackyapper connection.
MSP-level restrictions apply across managed tenants. The documentation does not specify a subscription-tier requirement or organization-published custom MCP distribution, so confirm your deployment with Hatz rather than assuming a shared connector model. Hatz MCP policies.

Grok Business and Enterprise

Team admins provision catalog and custom MCP connectors in the cloud console before members can use them. Review the team's connector list and retain the approved servers. Adding or removing connectors requires Team Read-Write permissions. This is a Business/Enterprise control; an individual SuperGrok subscription is not equivalent. Grok connector management.

Microsoft Copilot Studio

Power Platform data policies can block connectors used by MCP tools. Configure the policy's environment scope and the connectors it permits. This is a Copilot Studio/Power Platform administration control, not a general Microsoft Copilot chat setting or a single “organization-published only” switch. Microsoft data policies.

Codex and other local clients

Codex documents admin-enforced requirements.toml policies that allow MCP servers by name and identity, including remote server URLs. Ordinary config files supply defaults and are not an enforced allowlist. Confirm supported versions and policy delivery for your deployment; ChatGPT Business app publishing alone does not establish this local control. Codex managed configuration.

Verify the rollout

Test as an ordinary member in the managed workspace:
  1. Connect to the approved Stackyapper endpoint and use a permitted read tool.
  2. Try adding an unapproved test MCP endpoint. Confirm the provider denies it.
  3. Check previously installed servers, desktop clients, and coding tools too.
  4. Confirm a tool the member cannot access remains denied through Stackyapper.
Workspace controls do not automatically cover personal accounts, unmanaged devices, direct API credentials, browser access, or other ways to reach business data. Review those paths separately before claiming all AI access is governed.