9. Connecting your LLM agent (MCP)#

Workforce → Connect your agent — every member can do this for themselves:

  1. Create agent token: choose Read only, Read + remember, or Read + author, name it (e.g. "Claude Desktop — laptop"). The secret is shown once.
  2. Copy the ready-made config into your agent (Claude Desktop/Code use the mcp-remote snippet shown; anything else can use the curl/API example).
  3. Your agent now has tools including search_knowledge, read_concept, browse_index, and get_onboarding (§9b) — and answers with your permissions: content in groups you can't see doesn't exist as far as your agent is concerned. Permissions are live: lose a group and your agent loses it on its next call.

Trust floors over MCP: search_knowledge and search_skills accept an optional min_trust argument (unverified < machine-confirmed < human-reviewed, §4a) — set it when your agent should only act on knowledge a person has signed off on.

Remember (write-back): with a "Read + remember" token, tell your agent things like "remember this for the team: …". The fact lands in the Workspace under Agent memories with a "from agent" pill (who/when), is immediately searchable within your group visibility, and waits for human curation before it can ever become authoritative. Re-remembering the same statement updates it. A remember-token can only add reviewable notes — it can never delete, crawl, or edit.

Author (trusted write-back): with a "Read + author" token, your agent's author_concept tool writes a first-class concept immediately — authoritative, shared with the whole team and admins, and cited to you by name in the concept's # Citations. There's no review hop: this is the trusted "query prior solutions, write back new ones" loop — an agent fixing something, then writing the fix back so nobody on the team repeats the mistake and everyone's very next search_knowledge finds it. Contrast with remember, which drafts a note for a human to check first; use author only for things you already trust. Re-authoring the same title updates that concept in place rather than duplicating it.

Tokens expire after 90 days, can be revoked anytime (admins see all workspace tokens), and every mint/revoke/deposit is audited.