Skip to main content
Use the Admin Console to control which Box MCP server tools are available across your enterprise. This helps you meet your organization’s security, compliance, and governance requirements.

How tool access works

Box MCP server tool access works at two levels: By default, every published integration follows your enterprise-wide configuration. That default stays in effect until you give the integration a Custom configuration on its Box MCP Server tab, which then takes precedence for that integration only. Box applies settings in this order:
  1. Custom configuration — When set on an integration, it applies to that integration only.
  2. Global configuration — Applies to any integration that doesn’t have its own custom configuration.
Because settings can differ from one integration to the next, the same Box MCP server can expose different tools depending on which AI platform is in use.

Enterprise-wide access

Enterprise-wide settings apply to every user and to any published integration that doesn’t have its own custom configuration. To open your enterprise-wide tool settings:
  1. Open the Admin Console.
  2. In the left sidebar, select Integrations.
  3. Select the Box MCP Server tab.
A table displays each tool category with its current access level and a Configure button. From here, you can manage access:
  • By tool category
  • By individual tool
  • Or both
Box MCP Server tab in the Admin Console showing tool categories, each with an Enablement dropdown and a Configure button.
Some categories, such as Box Hubs or Box AI & Agents, might not be available for every enterprise. Check your subscription for details.

Set category access

To set access for an entire category:
  1. In the Box MCP Server table, find the category you want to configure.
  2. Select its Enablement dropdown.
  3. Choose one of the following access levels:
    • Disable all tools — No tools in the category are available.
    • Enable read only tools — Only tools that read data are available.
    • Enable read & write tools — All tools in the category are available, including tools that create or modify data.
    • Custom configuration — You choose which individual tools in the category are available.
After that, category-level changes take effect immediately.

Set individual tool access

To control access of the specific tools within a category:
  1. In the Box MCP Server table, find the category you want to configure.
  2. Select Configure.
The configuration window lists the category’s tools under Read only MCP tools and Write MCP tools, each with its own toggle.
Category configuration window with individual tool toggles grouped under Read only MCP tools and Write MCP tools.
The Enablement selection and the individual toggles stay in sync:
  • Selecting an Enablement option updates every toggle in the category.
  • Changing an individual toggle updates the Enablement selection: enabling only read tools selects Enable read only tools; enabling all tools selects Enable read & write tools; disabling all tools selects Disable all tools; any other combination selects Custom configuration.
After you select Save, a confirmation message displays.
To find a specific tool without browsing categories, select the search bar at the top of any Admin Console page, enter a keyword, then select a result. The Admin Console opens the relevant category configuration.

Per-integration access

You can also set tool access for a specific published integration, overriding your enterprise-wide default for that integration only. This enables you to govern each third-party AI platform separately while keeping one enterprise-wide baseline for everything else.
Integration-level controls apply only to published integrations in the MCP category. Unpublished platform apps always follow your enterprise-wide configuration.

Open integration settings

  1. Open the Admin Console.
  2. In the left sidebar, select Integrations.
  3. Find the integration you want to configure. To narrow the list, filter it to the MCP category or search by name.
  4. Select Configure for that integration.
  5. In the window that opens, select the Box MCP Server tab.
Box MCP Server tab for the Claude integration with Custom configuration selected, showing the All, Read only, and Write only filters and the expanded Files and Folders category with individual tool toggles.
The Box MCP Server tab controls which tools an integration can use. To control whether managed users and groups can access the integration at all, use the Availability Status tab instead. Both tabs have a Custom configuration option, but they govern different things.

Choose a configuration

On the Box MCP Server tab, choose how the integration gets its tool access:
  • Global configuration — The integration inherits your enterprise-wide settings. This is the default for every integration.
  • Custom configuration — You set tool access for this integration only, overriding the enterprise-wide settings.
When you select Custom configuration, the tool categories display, and you can expand any category to configure its individual tools.
A custom configuration applies to every user who has access to the integration. Per-user and per-group controls aren’t supported.

Configure individual tools

  1. Select a category to expand it.
  2. Use each tool’s toggle to enable or disable it for this integration.
  3. Repeat for any other categories.
  4. Select Save.
To narrow the list to a specific scope, use the All, Read only, or Write only filter above the categories.

Revert to enterprise-wide

To stop using a custom configuration and return an integration to your enterprise-wide settings:
  1. Open the Box MCP Server tab for the integration.
  2. Select Global configuration.
  3. Select Save.
Box removes the integration’s custom configuration. The integration follows your enterprise-wide settings again, including any changes you make later.

When you disable a tool

When you disable a tool, either enterprise-wide or for a specific integration:
  • Box removes it from the tool list returned to the MCP client.
  • Agents can no longer discover or use it.
If you disable a tool after an agent has already discovered it:
  • Box enforces the change at runtime.
  • The MCP Server returns an error such as:
Tool has been disabled by the enterprise admin. Contact your enterprise admin for more information.
During an active session, the user might instead see a generic error, such as “tool not found.” The exact message depends on the MCP client.
Some MCP clients cache the tool list. After you enable or disable a tool, an agent might still reference a cached list, either trying to call a tool that’s no longer available or not yet seeing a newly enabled one. If this happens, close and reopen the MCP client so it fetches an updated tool list.

Audit tool changes

To review when and how tool settings changed, including changes to a specific integration:
  1. Open the Admin Console.
  2. In the left sidebar, select Reports.
  3. Select Create Report, then select Security Logs.
  4. Under Integrations, select Changed MCP Tools Enablement Status.
The report includes: For more information, see Security Logs Report.

Monitor usage

To review tool usage across your enterprise, use the MCP Server Activity report. This report shows which users and integrations are interacting with your MCP server within a given time period. For more information, see MCP Server Activity Report.
Last modified on July 24, 2026