Skip to main content

Manage AI connections

Control who in your nation can connect an AI client, see who already has, and revoke access when you need to.

When someone in your nation connects an AI client through NationBuilder's MCP server, that connection carries their control panel access into an application outside your nation. This article covers how to see those connections, revoke them, and control who can create them in the first place.

If you're looking to set up a connection of your own, see Getting started with AI Connections.

Configuring access

Access through AI Connections is governed at three levels: for the nation, for a permission set, and for an individual control panel user.

1. Access for your nation

Go to Settings > Nation defaults > Basics and find the "Enable AI connections" checkbox:

This is checked by default. Unchecking it immediately revokes every active connection in your nation and prevents anyone from creating a new one.

If connections already exist when you uncheck it, you'll be asked to confirm before the setting takes effect.

2. Access for a permission set

Within a specific permission set's configuration, under Settings › Permission sets, you can designate a control panel user's access to MCP functionality.

  1. AI connections > Access data: The user can connect an AI client and ask read-only questions. For example, "how many people in my database live in California?"

  2. AI connections > Change data: The user can make updates to profiles in your database. For example, "Move everyone on my 'Prospective donors' list to the first step of my 'Fundraising' path."

  3. Integrations > Manage AI connections: The user can see the "AI connections" tab under Settings > Integrations, and can revoke the connection of other individual control panel users.

An AI connection only allows an AI client to see and do what a person could see and do themselves in the control panel. These permissions only decide whether they can use an AI client to do it.

3. Access for an individual connection

When AI connections are enabled, an AI connections tab will be visible under Settings > Integrations to any control panel user with the "Manage AI connections" permission set. This is where you will find all active connections per control panel user along with the AI client they're using. You can also see when each connection was first authorized, and any recently revoked connections.

Revoke a connection

To revoke the connection of another control panel user, open the dropdown menu on the row you want to end and choose Revoke connection.

Revoking a connection will take place immediately. It will force that user to re-authenticate their AI client the next time they attempt to use the MCP. Connections that have been revoked for more than 1 week will disappear from the table. If you want to permanently revoke access for a control panel user, you will need to move them to a permission set without AI connection access.

For the full list of permissions, see Create, edit, or delete a permission set.

When to revoke

  • A device with an active AI client is lost or stolen.

    📌 Note: A control panel user who is no longer logged in may still have an active session in their AI client. Revoking their connection will force a reauthorization request.

  • You see a connection to an AI application that you don't recognize or hasn't been approved for use by your organization.

Did this answer your question?