A little help.
A clear next step.
Start with a question, understand access, or get help from a person.
A good place to start.
Choose what you need help with. The question includes a connection guide. Copy it into the AI your company uses.
Included: product context, actions, setup, permissions and execution guidance.
Read the open guideThe question asks for guidance. It does not connect accounts or change permissions by itself.
Understand what you approve.
Can AI access more than I can?
OAuth means you approve access without giving Toolcape or your AI your password. You sign in with the provider, such as Microsoft or Google, and approve what the connection may do. Your organisation may need to approve it too.
- Your accountWhich files and actions you already have access to.
- The connectionThe access approved with the provider. It can be narrower than your own access.
- ToolcapeThe actions your organisation permits for you and your groups.
All three must allow the action. “All access” in Toolcape does not unlock files your account cannot access, or permissions the provider has not approved.
This applies when a connection acts on behalf of your own account. Shared accounts and application permissions can have different, broader rights and must be assessed separately. OAuth alone does not guarantee personal access limits.
MCP is how AI asks to use a tool. OAuth handles approved access. You can revoke the connection with the provider; this stops future access, but does not retract information already retrieved.
Read more: Microsoft · Google Drive
What are MCP, API and operations?
An operation is a task, such as finding a file. An API is the system’s technical interface. MCP gives AI a common way to ask for those tasks. None of these replaces permission checks.