Skip to main content
Use the Admin Console to control which Box MCP server tools are available across your enterprise. This helps you meet your organization’s security, compliance, and governance requirements.

How tool access works

Box MCP server tool access works at two levels: enterprise-wide, and for an individual integration or platform app. By default, every published integration and unpublished platform app follows your enterprise-wide configuration. That default stays in effect until you set a Custom configuration on the Box MCP Server tab of an individual integration or app, which then takes precedence for that integration or app only. Box applies settings in this order:
  1. Custom configuration — When set on an integration or platform app, it applies to that integration or app only.
  2. Global configuration — Applies to any integration or platform app that doesn’t have its own custom configuration.
Because settings can differ from one integration or app to the next, the same Box MCP server can expose different tools depending on which AI platform is in use.

Enterprise-wide access

Global configuration applies to every user, and to any integration or platform app that doesn’t have its own custom configuration. To open your enterprise-wide tool settings:
  1. Open the Admin Console.
  2. In the left sidebar, select Integrations.
  3. Select the Box MCP Server tab.
A table displays each tool category with its current access level and a Configure button. From here, you can manage access:
  • By tool category
  • By individual tool
  • Or both
Box MCP Server tab in the Admin Console showing tool categories, each with an Enablement dropdown and a Configure button.
Some categories, such as Box Hubs or Box AI & Agents, might not be available for every enterprise. Check your subscription for details.

Set category access

To set access for an entire category:
  1. In the Box MCP Server table, find the category you want to configure.
  2. Select its Enablement dropdown.
  3. Choose one of the following access levels:
    • Disable all tools — No tools in the category are available.
    • Enable read only tools — Only tools that read data are available.
    • Enable read & write tools — All tools in the category are available, including tools that create or modify data.
    • Custom configuration — You choose which individual tools in the category are available.
After that, category-level changes take effect immediately.

Set individual tool access

To control access of the specific tools within a category:
  1. In the Box MCP Server table, find the category you want to configure.
  2. Select Configure.
The configuration window lists the category’s tools under Read only MCP tools and Write MCP tools, each with its own toggle.
Category configuration window with individual tool toggles grouped under Read only MCP tools and Write MCP tools.
The Enablement selection and the individual toggles stay in sync:
  • Selecting an Enablement option updates every toggle in the category.
  • Changing an individual toggle updates the Enablement selection: enabling only read tools selects Enable read only tools; enabling all tools selects Enable read & write tools; disabling all tools selects Disable all tools; any other combination selects Custom configuration.
After you select Save, a confirmation message displays.
To find a specific tool without browsing categories, select the search bar at the top of any Admin Console page, enter a keyword, then select a result. The Admin Console opens the relevant category configuration.

Access for one integration or app

You can also set tool access for a specific integration or platform app, overriding your enterprise-wide default for that integration or app only. This enables you to govern each AI platform separately while keeping one enterprise-wide baseline for everything else. Every integration and platform app has its own Box MCP Server tab, where you choose how it gets its tool access:
  • Global configuration — It inherits your enterprise-wide settings. This is the default.
  • Custom configuration — You set tool access for this integration or app only, overriding the enterprise-wide settings.
When you select Custom configuration, the tool categories display, and you can expand any category to enable or disable its individual tools.
A custom configuration applies to every user who has access to the integration or app. Per-user and per-group controls aren’t supported.
Where you find the tab, and how your changes take effect, depends on the type of app.

Set tool access for an integration

  1. Open the Admin Console.
  2. In the left sidebar, select Integrations.
  3. Find the integration you want to configure. To narrow the list, filter it to the MCP category or search by name.
  4. Select Configure for that integration.
  5. In the window that opens, select the Box MCP Server tab.
  6. Select Custom configuration.
  7. Select a category to expand it, then use each tool’s toggle to enable or disable it. To narrow the list to a specific scope, select the All, Read only, or Write only filter above the categories.
  8. Select Save.
Box MCP Server tab for the Claude integration with Custom configuration selected, showing the All, Read only, and Write only filters and the expanded Files and Folders category with individual tool toggles.
To return the integration to your enterprise-wide settings, select Global configuration, then select Save.
The Box MCP Server tab controls which tools an integration can use. To control whether managed users and groups can access the integration at all, use the Availability Status tab instead. Both tabs have a Custom configuration option, but they govern different things.

Set tool access for a platform app

  1. Open the Admin Console.
  2. In the left sidebar, select Platform.
  3. From the top of the window, select the Platform Apps tab.
  4. Find the app you want to configure, then select its name.
  5. On the app details page, select the Box MCP Server tab.
  6. Select Custom configuration.
  7. Select a category to expand it, then use each tool’s toggle to enable or disable it. Your changes apply immediately.
To return the app to your enterprise-wide settings, select Global configuration. Box removes the custom configuration. The integration or app follows your enterprise-wide settings again, including any changes you make later.

When you disable a tool

When you disable a tool, either enterprise-wide or for a specific integration or platform app:
  • Box removes it from the tool list returned to the MCP client.
  • Agents can no longer discover or use it.
If you disable a tool after an agent has already discovered it:
  • Box enforces the change at runtime.
  • The MCP Server returns an error such as:
Tool has been disabled by the enterprise admin. Contact your enterprise admin for more information.
During an active session, the user might instead see a generic error, such as “tool not found.” The exact message depends on the MCP client.
Some MCP clients cache the tool list. After you enable or disable a tool, an agent might still reference a cached list, either trying to call a tool that’s no longer available or not yet seeing a newly enabled one. If this happens, close and reopen the MCP client so it fetches an updated tool list.

Audit tool changes

To review when and how tool settings changed, including changes to a specific integration or platform app:
  1. Open the Admin Console.
  2. In the left sidebar, select Reports.
  3. Select Create Report, then select Security Logs.
  4. Under Integrations, select Changed MCP Tools Enablement Status.
The report includes: For more information, see Security Logs Report.

Monitor usage

To review tool usage across your enterprise, use the MCP Server Activity report. This report shows which users and integrations are interacting with your MCP server within a given time period. For more information, see MCP Server Activity Report.
Last modified on September 3, 2026