Skip to content

Enterprise AI

Set up an enterprise connector

Authorize an MCP connector with the minimum identity, scope and write access.

Confirm that the organization has enabled the connector and that the user or deployment identity has access to the intended resources. Decide whether the connection should use a personal identity or an organization-managed service identity. Do not reuse credentials across environments unless that is part of the approved access design.

  1. Open the MCP or connector selector in an eligible Cortex client.
  2. Select the enterprise service.
  3. Complete the provider authorization flow and review the requested scopes.
  4. Return to Cortex and confirm that the service shows as connected.
  5. Test a narrow read operation against a known resource.
  6. Enable write tools only after approval and audit requirements are defined.

Selecting a service and connecting it are separate steps. A selected service can still require authentication, a plan entitlement or administrator approval.

Ask Cortex to identify the connected account and retrieve a non-sensitive, known resource. Confirm the tenant, organization, repository, project, account, subscription or region before allowing broader work. Test writes in a non-production resource and review the resulting provider audit record.

Revoke the provider authorization and remove the Cortex connection when it is no longer needed. Reconnect explicitly when changing identity. Cortex does not silently substitute a different connected account after revocation or expiry.