StackYapper separates an MSP's own workspace from each customer workspace.
Credentials, MCP sessions, access policy, and audit history are scoped to the
selected workspace.
Permission layers
Access is evaluated through the workspace's policy:
The app must be available to the workspace.
The app and its tools must be enabled by an administrator.
Group grants establish the normal access for a team.
User-specific policy can further constrain or grant approved access.
The operation's risk class determines whether runtime confirmation is
required.
Connecting provider credentials does not bypass these controls.
Customer workspaces
MSP staff can operate across approved customer workspaces according to their
role. Customer users remain inside their customer workspace and cannot see
another customer's apps, credentials, sessions, or audit events.
Always check the active workspace before connecting an app or authorizing an
AI client.