How tool access works
Box MCP server tool access works at two levels:
By default, every published integration follows your enterprise-wide configuration. That default stays in effect until you give the integration a Custom configuration on its Box MCP Server tab, which then takes precedence for that integration only.
Box applies settings in this order:
- Custom configuration — When set on an integration, it applies to that integration only.
- Global configuration — Applies to any integration that doesn’t have its own custom configuration.
Enterprise-wide access
Enterprise-wide settings apply to every user and to any published integration that doesn’t have its own custom configuration. To open your enterprise-wide tool settings:- Open the Admin Console.
- In the left sidebar, select Integrations.
- Select the Box MCP Server tab.
- By tool category
- By individual tool
- Or both

Some categories, such as Box Hubs or Box AI & Agents, might not be available for every enterprise. Check your subscription for details.
Set category access
To set access for an entire category:- In the Box MCP Server table, find the category you want to configure.
- Select its Enablement dropdown.
- Choose one of the following access levels:
- Disable all tools — No tools in the category are available.
- Enable read only tools — Only tools that read data are available.
- Enable read & write tools — All tools in the category are available, including tools that create or modify data.
- Custom configuration — You choose which individual tools in the category are available.
Set individual tool access
To control access of the specific tools within a category:- In the Box MCP Server table, find the category you want to configure.
- Select Configure.

- Selecting an Enablement option updates every toggle in the category.
- Changing an individual toggle updates the Enablement selection: enabling only read tools selects Enable read only tools; enabling all tools selects Enable read & write tools; disabling all tools selects Disable all tools; any other combination selects Custom configuration.
Per-integration access
You can also set tool access for a specific published integration, overriding your enterprise-wide default for that integration only. This enables you to govern each third-party AI platform separately while keeping one enterprise-wide baseline for everything else.Integration-level controls apply only to published integrations in the MCP category. Unpublished platform apps always follow your enterprise-wide configuration.
Open integration settings
- Open the Admin Console.
- In the left sidebar, select Integrations.
- Find the integration you want to configure. To narrow the list, filter it to the MCP category or search by name.
- Select Configure for that integration.
- In the window that opens, select the Box MCP Server tab.

The Box MCP Server tab controls which tools an integration can use. To control whether managed users and groups can access the integration at all, use the Availability Status tab instead. Both tabs have a Custom configuration option, but they govern different things.
Choose a configuration
On the Box MCP Server tab, choose how the integration gets its tool access:- Global configuration — The integration inherits your enterprise-wide settings. This is the default for every integration.
- Custom configuration — You set tool access for this integration only, overriding the enterprise-wide settings.
A custom configuration applies to every user who has access to the integration. Per-user and per-group controls aren’t supported.
Configure individual tools
- Select a category to expand it.
- Use each tool’s toggle to enable or disable it for this integration.
- Repeat for any other categories.
- Select Save.
Revert to enterprise-wide
To stop using a custom configuration and return an integration to your enterprise-wide settings:- Open the Box MCP Server tab for the integration.
- Select Global configuration.
- Select Save.
When you disable a tool
When you disable a tool, either enterprise-wide or for a specific integration:- Box removes it from the tool list returned to the MCP client.
- Agents can no longer discover or use it.
- Box enforces the change at runtime.
- The MCP Server returns an error such as:
Tool has been disabled by the enterprise admin. Contact your enterprise admin for more information.During an active session, the user might instead see a generic error, such as “tool not found.” The exact message depends on the MCP client.
Some MCP clients cache the tool list. After you enable or disable a tool, an agent might still reference a cached list, either trying to call a tool that’s no longer available or not yet seeing a newly enabled one. If this happens, close and reopen the MCP client so it fetches an updated tool list.
Audit tool changes
To review when and how tool settings changed, including changes to a specific integration:- Open the Admin Console.
- In the left sidebar, select Reports.
- Select Create Report, then select Security Logs.
- Under Integrations, select Changed MCP Tools Enablement Status.
For more information, see Security Logs Report.